{"resultsPerPage":1444,"startIndex":0,"totalResults":1444,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-15T10:01:37.837","vulnerabilities":[{"cve":{"id":"CVE-2013-7316","sourceIdentifier":"cve@mitre.org","published":"2014-01-24T15:08:00.777","lastModified":"2026-06-17T00:01:44.507","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in GitLab 6.0 and other versions before 6.5.0 allows remote attackers to inject arbitrary web script or HTML via a crafted HTML file, as demonstrated by README.html."},{"lang":"es","value":"Vulnerabilidad de XSS en GitLab 6.0 y otras versiones anteriores a 6.5.0 permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarias a través de un archivo HTML manipulado, como es demostrado por README.html."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:6.0.0:*:*:*:*:*:*:*","matchCriteriaId":"E82B301E-25BD-4438-9696-DF3E290F32B7"}]}]}],"references":[{"url":"http://www.exploit-db.com/exploits/30329","source":"cve@mitre.org"},{"url":"http://www.securityfocus.com/bid/64490","source":"cve@mitre.org"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/89932","source":"cve@mitre.org"},{"url":"https://www.gitlab.com/2014/01/30/xss-vulnerability-in-gitlab/","source":"cve@mitre.org"},{"url":"http://www.exploit-db.com/exploits/30329","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.securityfocus.com/bid/64490","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/89932","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.gitlab.com/2014/01/30/xss-vulnerability-in-gitlab/","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2013-4580","sourceIdentifier":"secalert@redhat.com","published":"2014-05-12T14:55:05.210","lastModified":"2026-06-16T23:57:29.480","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab before 5.4.2, Community Edition before 6.2.4, and Enterprise Edition before 6.2.1, when using a MySQL backend, allows remote attackers to impersonate arbitrary users and bypass authentication via unspecified API calls."},{"lang":"es","value":"GitLab en versiones anteriores a 5.4.2, Community Edition en versiones anteriores a 6.2.4 y Enterprise Edition en versiones anteriores a 6.2.1, cuando se utiliza un backend MySQL, permite a atacantes remotos hacerse pasar por usuarios arbitrarios y eludir la autenticación a través de llamadas API no especificadas."}],"affected":[{"source":"secalert@redhat.com","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-287"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionEndIncluding":"5.4.1","matchCriteriaId":"F1A9AAEC-EF1A-41E6-ADCE-C6143D05F37B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:0.8.0:*:*:*:*:*:*:*","matchCriteriaId":"444637C6-564C-41DF-B6BE-4FA01E6B77A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:0.9.1:*:*:*:*:*:*:*","matchCriteriaId":"0362CC4F-BABB-4276-B64E-A17646A49A23"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:0.9.4:*:*:*:*:*:*:*","matchCriteriaId":"CB51B25E-B875-45AB-94BF-D5EC2FA8AFFA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:0.9.6:*:*:*:*:*:*:*","matchCriteriaId":"320D195E-8E65-47E8-9CF8-BDF360CD74E2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:1.0.0:*:*:*:*:*:*:*","matchCriteriaId":"84FC408D-2CD9-419B-A4B2-14D45BD74760"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:1.0.1:*:*:*:*:*:*:*","matchCriteriaId":"A41C4622-FB3A-4C8C-B2C9-805C3F6E6602"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:1.0.2:*:*:*:*:*:*:*","matchCriteriaId":"2A787059-D8E4-4083-9E36-CD8B8BEF5B7E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:1.1.0:*:*:*:*:*:*:*","matchCriteriaId":"797F2359-FFB4-400D-A93E-5A7061D71124"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:1.2.0:*:*:*:*:*:*:*","matchCriteriaId":"C4C8EC5B-A4EC-46CA-BD3B-B78FB1306DEE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:1.2.1:*:*:*:*:*:*:*","matchCriteriaId":"1A052F51-6C2E-4DD2-B609-66A7C9797270"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:1.2.2:*:*:*:*:*:*:*","matchCriteriaId":"C9FEE30F-6C1A-4FC3-A173-D698875C4453"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.0.0:*:*:*:*:*:*:*","matchCriteriaId":"787590AA-85EC-437D-978D-236AAB6D2794"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.1.0:*:*:*:*:*:*:*","matchCriteriaId":"EECCB6CE-7D05-4851-A44E-045AA8A7AA81"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.2.0:*:*:*:*:*:*:*","matchCriteriaId":"09A85D72-EA22-4C3D-854A-53B09960B21A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.3.0:*:*:*:*:*:*:*","matchCriteriaId":"17657E91-9536-41E3-ACC1-56ED4404BE55"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.3.1:*:*:*:*:*:*:*","matchCriteriaId":"47A880E9-1BCE-4C4C-8E57-848A33521BF5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.4.0:*:*:*:*:*:*:*","matchCriteriaId":"9BCCA4F3-A1B2-46F1-B5E8-E5A6F969DE08"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.5.0:*:*:*:*:*:*:*","matchCriteriaId":"D2ED75C5-C4BC-47CF-8DEF-DB3ECE9DC7AA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.6.0:*:*:*:*:*:*:*","matchCriteriaId":"ACAF546C-9340-416D-9FBB-3B94E7B707BC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.7.0:*:*:*:*:*:*:*","matchCriteriaId":"969B6390-5341-433B-A651-90D9DBF324EC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.8.0:*:*:*:*:*:*:*","matchCriteriaId":"1D627C22-D607-4CC1-AD07-B0EC2C2FFB57"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.8.1:*:*:*:*:*:*:*","matchCriteriaId":"2311FF2C-96A3-42CE-AE2B-54F1D1C0BA3C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.9.0:*:*:*:*:*:*:*","matchCriteriaId":"2724D97F-A516-43CC-AD08-1CBF2BF1C568"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.9.1:*:*:*:*:*:*:*","matchCriteriaId":"04333737-F1BE-4BD3-BD6D-CB43A6C8900D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:3.0.0:*:*:*:*:*:*:*","matchCriteriaId":"B77D14F9-EED1-48E5-8CF3-65C6D993A672"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:3.0.1:*:*:*:*:*:*:*","matchCriteriaId":"76E37021-52C3-4E30-8B2D-7D777FE31D2A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:3.0.2:*:*:*:*:*:*:*","matchCriteriaId":"93144929-0112-4A56-94D4-3C8670F4B029"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:3.0.3:*:*:*:*:*:*:*","matchCriteriaId":"C12A2C84-3810-4CF4-A8CD-4DAD60445BA0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:3.1.0:*:*:*:*:*:*:*","matchCriteriaId":"C9EA82AE-0A37-4D4D-92CD-C030F8E9D620"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:4.0.0:*:*:*:*:*:*:*","matchCriteriaId":"9A6F5AED-8917-4E0B-9B75-DF582B0C8143"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:4.1.0:*:*:*:*:*:*:*","matchCriteriaId":"5E3A7947-B050-4AF7-B520-7D7B27A15B1D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:4.2.0:*:*:*:*:*:*:*","matchCriteriaId":"5D8CB468-670E-4B29-AB93-7964BC796735"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.0.0:*:*:*:*:*:*:*","matchCriteriaId":"4DA23AF5-81E7-4D04-A224-DF823772EC06"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.0.1:*:*:*:*:*:*:*","matchCriteriaId":"5A780E86-D049-4C46-8481-2E55E974649C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.1.0:*:*:*:*:*:*:*","matchCriteriaId":"960E66D9-2E5B-460A-A262-88FF1CE60750"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.2.0:*:*:*:*:*:*:*","matchCriteriaId":"2D61A37D-1A91-4C85-9737-E54670401FC6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.3.0:*:*:*:*:*:*:*","matchCriteriaId":"81CB5B34-09DE-4589-824C-97A6D696BD43"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.4.0:*:*:*:*:*:*:*","matchCriteriaId":"C9C5A188-6B92-46A2-9345-386F90BE362C"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndIncluding":"6.2.3","matchCriteriaId":"B2E382BE-FA4E-4CC8-AC24-DDA7BDE41C8E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:0.8.0:*:*:*:community:*:*:*","matchCriteriaId":"CE0DFA2C-41DA-4E36-8CA9-0C4B8D8C90C3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:0.9.1:*:*:*:community:*:*:*","matchCriteriaId":"AC092D59-F723-45C0-AF20-64777AE5684F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:0.9.4:*:*:*:community:*:*:*","matchCriteriaId":"1950E027-EA2C-4904-9195-CBF722B33DDB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:0.9.6:*:*:*:community:*:*:*","matchCriteriaId":"86EAAB74-39E2-4C9E-B4F2-BCDFF312CAC7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:1.0.0:*:*:*:community:*:*:*","matchCriteriaId":"C41C6495-EABB-402E-9FE4-CAEE68501445"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:1.0.1:*:*:*:community:*:*:*","matchCriteriaId":"F1101DBF-2066-40C7-9B37-5C8DE7511139"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:1.0.2:*:*:*:community:*:*:*","matchCriteriaId":"E7BB90B0-C20A-4227-B96C-4508761D3379"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:1.1.0:*:*:*:community:*:*:*","matchCriteriaId":"84E14E95-80B3-4529-BF3C-13091745AEEE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:1.2.0:*:*:*:community:*:*:*","matchCriteriaId":"DAC793E9-4E50-4F33-AFAB-087ECF86E145"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:1.2.1:*:*:*:community:*:*:*","matchCriteriaId":"3F75A45E-14B1-4422-A855-C6E6AC4B722C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:1.2.2:*:*:*:community:*:*:*","matchCriteriaId":"94D30489-151E-4B3B-9909-7299DD54F1AE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.0.0:*:*:*:community:*:*:*","matchCriteriaId":"355E9233-2B1E-44C8-BA51-E4CB07B37D22"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.1.0:*:*:*:community:*:*:*","matchCriteriaId":"BB939572-4A05-4621-AC42-838301DF5129"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.2.0:*:*:*:community:*:*:*","matchCriteriaId":"FE2EEB8B-E46A-495E-B1E7-68647A737F86"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.3.0:*:*:*:community:*:*:*","matchCriteriaId":"1D4CCBEB-E02A-4488-827F-D312465BBD62"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.3.1:*:*:*:community:*:*:*","matchCriteriaId":"7CDE0745-1E53-41FA-97C3-CDB0C34C26C3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.4.0:*:*:*:community:*:*:*","matchCriteriaId":"A085524A-A0BA-4FB7-AF39-A3E5CB4981B4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.5.0:*:*:*:community:*:*:*","matchCriteriaId":"DB844D02-E1C4-426C-81A5-6788DE1B55C5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.6.0:*:*:*:community:*:*:*","matchCriteriaId":"271BB4F1-DA7A-472F-9BE9-AC84F5A03ADC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.7.0:*:*:*:community:*:*:*","matchCriteriaId":"CA3CC2D4-4FFC-4336-8A75-D57FC720AB91"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.8.0:*:*:*:community:*:*:*","matchCriteriaId":"05826240-4551-4962-82C0-0202BF94CB80"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.8.1:*:*:*:community:*:*:*","matchCriteriaId":"0B66E8D3-A1EB-44CA-8ECB-C30B3E33D479"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.9.0:*:*:*:community:*:*:*","matchCriteriaId":"79EB6A9E-C843-467C-8C99-362731631C07"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.9.1:*:*:*:community:*:*:*","matchCriteriaId":"17E4F7A7-C306-4E31-857A-6B6377254E7C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:3.0.0:*:*:*:community:*:*:*","matchCriteriaId":"879EE5F3-9C51-45DA-947C-DB0800A24959"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:3.0.1:*:*:*:community:*:*:*","matchCriteriaId":"5C38D689-3A30-4246-85A6-715C5D3F3B51"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:3.0.2:*:*:*:community:*:*:*","matchCriteriaId":"F3662FD6-3ED2-4109-916C-C9F971845AAE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:3.0.3:*:*:*:community:*:*:*","matchCriteriaId":"1BE9E979-D1D4-45F3-947D-050723CF08E0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:3.1.0:*:*:*:community:*:*:*","matchCriteriaId":"59661D3D-6229-4468-8E84-3B626DCC53FA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:4.0.0:*:*:*:community:*:*:*","matchCriteriaId":"D05A7568-2C2F-4F75-8195-23D56E834E14"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:4.1.0:*:*:*:community:*:*:*","matchCriteriaId":"35EE78CC-9CB5-470C-BB32-C2DC73C947B0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:4.2.0:*:*:*:community:*:*:*","matchCriteriaId":"6E6ABD26-09D5-449F-ACB1-52B55254BA97"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.0.0:*:*:*:community:*:*:*","matchCriteriaId":"C6BC4C79-77B9-44EC-AF94-6E876EA51471"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.0.1:*:*:*:community:*:*:*","matchCriteriaId":"3C2193F3-6CE9-4C34-84E5-083D81F933D0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.1.0:*:*:*:community:*:*:*","matchCriteriaId":"D90ACB08-B9D9-4C4F-B8D1-DA9BC1F544FD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.2.0:*:*:*:community:*:*:*","matchCriteriaId":"499FDD67-9859-4724-8BB3-DA5B6FEAF4C2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.3.0:*:*:*:community:*:*:*","matchCriteriaId":"D8D25320-F483-4845-B901-EC1AD92C9B19"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.4.0:*:*:*:community:*:*:*","matchCriteriaId":"6E94F3C6-D4FD-4C9D-B30E-A20DCB56409A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.4.1:*:*:*:community:*:*:*","matchCriteriaId":"A468410B-4ABC-4A4C-A02E-DC30B3DB26C7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.4.2:*:*:*:community:*:*:*","matchCriteriaId":"F1325ED2-89B2-4134-8EBD-8D7B989B28BD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:6.0.0:*:*:*:community:*:*:*","matchCriteriaId":"7ED08516-18CD-4638-87E5-7E5823AEDD58"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:6.1.0:*:*:*:community:*:*:*","matchCriteriaId":"E2171EB2-9EA1-4972-B268-C702A68772DB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:6.2.0:*:*:*:community:*:*:*","matchCriteriaId":"FCF4A772-ED0F-43E0-9CE4-9B483F20755F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:6.2.1:*:*:*:community:*:*:*","matchCriteriaId":"65701BE8-9223-45CF-87CD-0CFC5EA34DB1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:6.2.2:*:*:*:community:*:*:*","matchCriteriaId":"AD6656F9-BF5A-4F54-8A77-785BF67BFF79"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndIncluding":"6.2.0","matchCriteriaId":"5E462374-C134-446E-9836-E9D7777EA2ED"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:0.8.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"1436C749-3454-40C5-9D50-4A853A5CB54E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:0.9.1:*:*:*:enterprise:*:*:*","matchCriteriaId":"991F0C7A-AFF4-4623-8571-322A7B805985"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:0.9.4:*:*:*:enterprise:*:*:*","matchCriteriaId":"729924F8-5E0E-4F56-B266-328E0C918AB4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:0.9.6:*:*:*:enterprise:*:*:*","matchCriteriaId":"3E950DE0-7F8C-4D1C-BFB0-BEF85D8049D1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:1.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"3C040C0E-9DE2-4F31-AAAE-502A4A3E48A2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:1.0.1:*:*:*:enterprise:*:*:*","matchCriteriaId":"32D736D0-E8EC-4EFF-B798-035DC1B7655C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:1.0.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"DB8CA49D-3F07-4E20-9E45-C82D7012A814"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:1.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"037E5B38-4DB2-456B-BF81-5B15B20B6AF3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:1.2.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"884AC03F-625A-43BF-81BD-E3ACF0E83FF1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:1.2.1:*:*:*:enterprise:*:*:*","matchCriteriaId":"04144524-638B-41AE-8FA0-3CCAE2B503C5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:1.2.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"F5347E8C-BF9E-4495-B291-31CEC8BB4BFB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"DCB993B5-3A7C-4C7A-B70A-CE41173A98D0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"1065C127-72C5-48F4-876E-1E1F1B60DB2A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.2.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"6E994A08-F74C-4F37-900E-493AAA414255"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.3.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"D9FABE06-CA7D-4B77-A944-24C165719811"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.3.1:*:*:*:enterprise:*:*:*","matchCriteriaId":"217AF163-703B-435E-98DD-BA071FFDD5AC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.4.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"8A1FDC7B-126A-49EF-8C7E-03C4D08C4355"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.5.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"500AD829-098B-4E6F-955D-1CB024130DFD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.6.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"BDF97947-68FE-4B2E-A747-6D880DBED590"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.7.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"B687AA58-E0A6-48FC-9F17-AACE9235B104"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.8.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"B954A9D1-2AB2-43D2-B406-009A57390B0F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.8.1:*:*:*:enterprise:*:*:*","matchCriteriaId":"4F01FB9C-4706-4939-B094-F41727EF3C0D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.9.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"F0E8A8DC-38C6-4B30-B5D9-C0D387D2990A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.9.1:*:*:*:enterprise:*:*:*","matchCriteriaId":"D19921EF-92DF-4828-97DB-9F468A8BC17F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:3.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"F374EC1C-6BE6-4BD6-88FB-58FCA908EDE1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:3.0.1:*:*:*:enterprise:*:*:*","matchCriteriaId":"5263CB34-1B3D-42ED-8172-CCCB4D81221C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:3.0.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"C2F05FB7-75FE-423B-9535-B901825AA767"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:3.0.3:*:*:*:enterprise:*:*:*","matchCriteriaId":"B26074A4-9DB4-4628-98C1-24E096FF8F13"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:3.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"9F5F8DF2-EDF2-4DF2-BAA0-E0A1D4E99E38"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:4.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"331FB92E-66E1-48F6-9B60-6598692DB899"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:4.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"E6C230E7-6A64-4D1D-8CAA-613BFA9817B1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:4.2.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"E86E2191-6E7E-4F6B-B578-2CBB461A1835"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"77D5DFE4-7AD3-47EB-A53D-78057CBC2B74"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.0.1:*:*:*:enterprise:*:*:*","matchCriteriaId":"0CE62CA8-6140-4C91-ACE2-4A35D48B4AD0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"D3F1C8DC-895F-4203-92CD-80A512C0B3FA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.2.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"1867B5F2-6B02-4CBE-8082-151BC9595A02"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.3.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"78E19895-D307-4237-A8C3-2F2DA9253CFE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.4.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"999B4B61-3F53-4810-9A2E-6526E479B8BD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.4.1:*:*:*:enterprise:*:*:*","matchCriteriaId":"602715E3-A0E7-4990-8FD2-6020FB7FA28E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.4.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"9BFD668F-303C-490C-AD56-6D780E112039"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:6.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"0CB85A2B-4621-473B-AF14-D2C555F2ED58"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:6.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"CAE3803B-C3BF-4B2F-8D3A-94936CB37D07"}]}]}],"references":[{"url":"http://www.openwall.com/lists/oss-security/2013/11/15/4","source":"secalert@redhat.com"},{"url":"https://www.gitlab.com/2013/11/14/multiple-critical-vulnerabilities-in-gitlab/","source":"secalert@redhat.com","tags":["Patch","Vendor Advisory"]},{"url":"http://www.openwall.com/lists/oss-security/2013/11/15/4","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.gitlab.com/2013/11/14/multiple-critical-vulnerabilities-in-gitlab/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2013-4581","sourceIdentifier":"secalert@redhat.com","published":"2014-05-12T14:55:05.290","lastModified":"2026-06-16T23:57:29.600","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote attackers to execute arbitrary code via a crafted change using SSH."},{"lang":"es","value":"GitLab 5.0 anterior a 5.4.2, Community Edition anterior a 6.2.4, Enterprise Edition anterior a 6.2.1 y gitlab-shell anterior a 1.7.8 permite a atacantes remotos ejecutar código arbitrario a través de un cambio manipulado que utiliza SSH."}],"affected":[{"source":"secalert@redhat.com","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-94"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndIncluding":"6.2.3","matchCriteriaId":"B2E382BE-FA4E-4CC8-AC24-DDA7BDE41C8E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:0.8.0:*:*:*:community:*:*:*","matchCriteriaId":"CE0DFA2C-41DA-4E36-8CA9-0C4B8D8C90C3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:0.9.1:*:*:*:community:*:*:*","matchCriteriaId":"AC092D59-F723-45C0-AF20-64777AE5684F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:0.9.4:*:*:*:community:*:*:*","matchCriteriaId":"1950E027-EA2C-4904-9195-CBF722B33DDB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:0.9.6:*:*:*:community:*:*:*","matchCriteriaId":"86EAAB74-39E2-4C9E-B4F2-BCDFF312CAC7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:1.0.0:*:*:*:community:*:*:*","matchCriteriaId":"C41C6495-EABB-402E-9FE4-CAEE68501445"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:1.0.1:*:*:*:community:*:*:*","matchCriteriaId":"F1101DBF-2066-40C7-9B37-5C8DE7511139"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:1.0.2:*:*:*:community:*:*:*","matchCriteriaId":"E7BB90B0-C20A-4227-B96C-4508761D3379"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:1.1.0:*:*:*:community:*:*:*","matchCriteriaId":"84E14E95-80B3-4529-BF3C-13091745AEEE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:1.2.0:*:*:*:community:*:*:*","matchCriteriaId":"DAC793E9-4E50-4F33-AFAB-087ECF86E145"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:1.2.1:*:*:*:community:*:*:*","matchCriteriaId":"3F75A45E-14B1-4422-A855-C6E6AC4B722C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:1.2.2:*:*:*:community:*:*:*","matchCriteriaId":"94D30489-151E-4B3B-9909-7299DD54F1AE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.0.0:*:*:*:community:*:*:*","matchCriteriaId":"355E9233-2B1E-44C8-BA51-E4CB07B37D22"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.1.0:*:*:*:community:*:*:*","matchCriteriaId":"BB939572-4A05-4621-AC42-838301DF5129"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.2.0:*:*:*:community:*:*:*","matchCriteriaId":"FE2EEB8B-E46A-495E-B1E7-68647A737F86"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.3.0:*:*:*:community:*:*:*","matchCriteriaId":"1D4CCBEB-E02A-4488-827F-D312465BBD62"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.3.1:*:*:*:community:*:*:*","matchCriteriaId":"7CDE0745-1E53-41FA-97C3-CDB0C34C26C3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.4.0:*:*:*:community:*:*:*","matchCriteriaId":"A085524A-A0BA-4FB7-AF39-A3E5CB4981B4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.5.0:*:*:*:community:*:*:*","matchCriteriaId":"DB844D02-E1C4-426C-81A5-6788DE1B55C5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.6.0:*:*:*:community:*:*:*","matchCriteriaId":"271BB4F1-DA7A-472F-9BE9-AC84F5A03ADC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.7.0:*:*:*:community:*:*:*","matchCriteriaId":"CA3CC2D4-4FFC-4336-8A75-D57FC720AB91"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.8.0:*:*:*:community:*:*:*","matchCriteriaId":"05826240-4551-4962-82C0-0202BF94CB80"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.8.1:*:*:*:community:*:*:*","matchCriteriaId":"0B66E8D3-A1EB-44CA-8ECB-C30B3E33D479"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.9.0:*:*:*:community:*:*:*","matchCriteriaId":"79EB6A9E-C843-467C-8C99-362731631C07"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.9.1:*:*:*:community:*:*:*","matchCriteriaId":"17E4F7A7-C306-4E31-857A-6B6377254E7C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:3.0.0:*:*:*:community:*:*:*","matchCriteriaId":"879EE5F3-9C51-45DA-947C-DB0800A24959"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:3.0.1:*:*:*:community:*:*:*","matchCriteriaId":"5C38D689-3A30-4246-85A6-715C5D3F3B51"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:3.0.2:*:*:*:community:*:*:*","matchCriteriaId":"F3662FD6-3ED2-4109-916C-C9F971845AAE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:3.0.3:*:*:*:community:*:*:*","matchCriteriaId":"1BE9E979-D1D4-45F3-947D-050723CF08E0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:3.1.0:*:*:*:community:*:*:*","matchCriteriaId":"59661D3D-6229-4468-8E84-3B626DCC53FA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:4.0.0:*:*:*:community:*:*:*","matchCriteriaId":"D05A7568-2C2F-4F75-8195-23D56E834E14"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:4.1.0:*:*:*:community:*:*:*","matchCriteriaId":"35EE78CC-9CB5-470C-BB32-C2DC73C947B0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:4.2.0:*:*:*:community:*:*:*","matchCriteriaId":"6E6ABD26-09D5-449F-ACB1-52B55254BA97"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.0.0:*:*:*:community:*:*:*","matchCriteriaId":"C6BC4C79-77B9-44EC-AF94-6E876EA51471"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.0.1:*:*:*:community:*:*:*","matchCriteriaId":"3C2193F3-6CE9-4C34-84E5-083D81F933D0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.1.0:*:*:*:community:*:*:*","matchCriteriaId":"D90ACB08-B9D9-4C4F-B8D1-DA9BC1F544FD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.2.0:*:*:*:community:*:*:*","matchCriteriaId":"499FDD67-9859-4724-8BB3-DA5B6FEAF4C2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.3.0:*:*:*:community:*:*:*","matchCriteriaId":"D8D25320-F483-4845-B901-EC1AD92C9B19"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.4.0:*:*:*:community:*:*:*","matchCriteriaId":"6E94F3C6-D4FD-4C9D-B30E-A20DCB56409A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.4.1:*:*:*:community:*:*:*","matchCriteriaId":"A468410B-4ABC-4A4C-A02E-DC30B3DB26C7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.4.2:*:*:*:community:*:*:*","matchCriteriaId":"F1325ED2-89B2-4134-8EBD-8D7B989B28BD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:6.0.0:*:*:*:community:*:*:*","matchCriteriaId":"7ED08516-18CD-4638-87E5-7E5823AEDD58"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:6.1.0:*:*:*:community:*:*:*","matchCriteriaId":"E2171EB2-9EA1-4972-B268-C702A68772DB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:6.2.0:*:*:*:community:*:*:*","matchCriteriaId":"FCF4A772-ED0F-43E0-9CE4-9B483F20755F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:6.2.1:*:*:*:community:*:*:*","matchCriteriaId":"65701BE8-9223-45CF-87CD-0CFC5EA34DB1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:6.2.2:*:*:*:community:*:*:*","matchCriteriaId":"AD6656F9-BF5A-4F54-8A77-785BF67BFF79"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndIncluding":"6.2.0","matchCriteriaId":"5E462374-C134-446E-9836-E9D7777EA2ED"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:0.8.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"1436C749-3454-40C5-9D50-4A853A5CB54E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:0.9.1:*:*:*:enterprise:*:*:*","matchCriteriaId":"991F0C7A-AFF4-4623-8571-322A7B805985"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:0.9.4:*:*:*:enterprise:*:*:*","matchCriteriaId":"729924F8-5E0E-4F56-B266-328E0C918AB4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:0.9.6:*:*:*:enterprise:*:*:*","matchCriteriaId":"3E950DE0-7F8C-4D1C-BFB0-BEF85D8049D1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:1.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"3C040C0E-9DE2-4F31-AAAE-502A4A3E48A2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:1.0.1:*:*:*:enterprise:*:*:*","matchCriteriaId":"32D736D0-E8EC-4EFF-B798-035DC1B7655C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:1.0.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"DB8CA49D-3F07-4E20-9E45-C82D7012A814"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:1.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"037E5B38-4DB2-456B-BF81-5B15B20B6AF3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:1.2.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"884AC03F-625A-43BF-81BD-E3ACF0E83FF1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:1.2.1:*:*:*:enterprise:*:*:*","matchCriteriaId":"04144524-638B-41AE-8FA0-3CCAE2B503C5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:1.2.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"F5347E8C-BF9E-4495-B291-31CEC8BB4BFB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"DCB993B5-3A7C-4C7A-B70A-CE41173A98D0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"1065C127-72C5-48F4-876E-1E1F1B60DB2A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.2.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"6E994A08-F74C-4F37-900E-493AAA414255"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.3.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"D9FABE06-CA7D-4B77-A944-24C165719811"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.3.1:*:*:*:enterprise:*:*:*","matchCriteriaId":"217AF163-703B-435E-98DD-BA071FFDD5AC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.4.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"8A1FDC7B-126A-49EF-8C7E-03C4D08C4355"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.5.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"500AD829-098B-4E6F-955D-1CB024130DFD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.6.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"BDF97947-68FE-4B2E-A747-6D880DBED590"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.7.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"B687AA58-E0A6-48FC-9F17-AACE9235B104"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.8.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"B954A9D1-2AB2-43D2-B406-009A57390B0F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.8.1:*:*:*:enterprise:*:*:*","matchCriteriaId":"4F01FB9C-4706-4939-B094-F41727EF3C0D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.9.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"F0E8A8DC-38C6-4B30-B5D9-C0D387D2990A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:2.9.1:*:*:*:enterprise:*:*:*","matchCriteriaId":"D19921EF-92DF-4828-97DB-9F468A8BC17F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:3.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"F374EC1C-6BE6-4BD6-88FB-58FCA908EDE1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:3.0.1:*:*:*:enterprise:*:*:*","matchCriteriaId":"5263CB34-1B3D-42ED-8172-CCCB4D81221C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:3.0.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"C2F05FB7-75FE-423B-9535-B901825AA767"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:3.0.3:*:*:*:enterprise:*:*:*","matchCriteriaId":"B26074A4-9DB4-4628-98C1-24E096FF8F13"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:3.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"9F5F8DF2-EDF2-4DF2-BAA0-E0A1D4E99E38"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:4.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"331FB92E-66E1-48F6-9B60-6598692DB899"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:4.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"E6C230E7-6A64-4D1D-8CAA-613BFA9817B1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:4.2.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"E86E2191-6E7E-4F6B-B578-2CBB461A1835"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"77D5DFE4-7AD3-47EB-A53D-78057CBC2B74"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.0.1:*:*:*:enterprise:*:*:*","matchCriteriaId":"0CE62CA8-6140-4C91-ACE2-4A35D48B4AD0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"D3F1C8DC-895F-4203-92CD-80A512C0B3FA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.2.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"1867B5F2-6B02-4CBE-8082-151BC9595A02"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.3.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"78E19895-D307-4237-A8C3-2F2DA9253CFE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.4.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"999B4B61-3F53-4810-9A2E-6526E479B8BD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.4.1:*:*:*:enterprise:*:*:*","matchCriteriaId":"602715E3-A0E7-4990-8FD2-6020FB7FA28E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.4.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"9BFD668F-303C-490C-AD56-6D780E112039"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:6.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"0CB85A2B-4621-473B-AF14-D2C555F2ED58"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:6.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"CAE3803B-C3BF-4B2F-8D3A-94936CB37D07"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab-shell:*:*:*:*:*:*:*:*","versionEndIncluding":"1.7.7","matchCriteriaId":"3523D018-4624-4132-A18E-5309D2FF284A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab-shell:1.0.4:*:*:*:*:*:*:*","matchCriteriaId":"5468E7D1-96FD-4BCC-B35F-20B8A045CEBF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab-shell:1.1.0:*:*:*:*:*:*:*","matchCriteriaId":"8C66C8DB-919E-4D42-A8FB-2F1C08F19EBC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab-shell:1.2.0:*:*:*:*:*:*:*","matchCriteriaId":"989A3DDF-A7A8-4CA8-844C-12A5A7150866"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab-shell:1.3.0:*:*:*:*:*:*:*","matchCriteriaId":"E9693E73-B622-496C-8427-D8E3F8DA9DD7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab-shell:1.4.0:*:*:*:*:*:*:*","matchCriteriaId":"EC8F0260-C2EE-4DFB-B368-B55EB4A6FA93"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab-shell:1.5.0:*:*:*:*:*:*:*","matchCriteriaId":"98BB99C5-45C7-4982-A5C7-10319B2FCBCE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab-shell:1.6.0:*:*:*:*:*:*:*","matchCriteriaId":"E186CC7F-1C1F-41CB-88DB-B8DDE36EB7B8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab-shell:1.7.0:*:*:*:*:*:*:*","matchCriteriaId":"46778FDB-4863-451A-88C0-0C38D14C623D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab-shell:1.7.1:*:*:*:*:*:*:*","matchCriteriaId":"E2E2DA5C-61BB-4218-8FDA-57AC3C9C0172"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab-shell:1.7.2:*:*:*:*:*:*:*","matchCriteriaId":"C54EB6D2-4AAA-4567-B078-AE91317BF083"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab-shell:1.7.3:*:*:*:*:*:*:*","matchCriteriaId":"18CD9D5B-4B87-46D2-A1F8-1F1EFCCA22F4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab-shell:1.7.4:*:*:*:*:*:*:*","matchCriteriaId":"8C99B698-ED57-4655-B835-F469403E4E3A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab-shell:1.7.5:*:*:*:*:*:*:*","matchCriteriaId":"605EA4F6-86D7-4460-B88B-E5A8E88CEF4A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab-shell:1.7.6:*:*:*:*:*:*:*","matchCriteriaId":"F6A2D71C-8E43-4B0D-9A1B-7B328C245FF9"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.0.0:*:*:*:*:*:*:*","matchCriteriaId":"4DA23AF5-81E7-4D04-A224-DF823772EC06"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.0.1:*:*:*:*:*:*:*","matchCriteriaId":"5A780E86-D049-4C46-8481-2E55E974649C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.1.0:*:*:*:*:*:*:*","matchCriteriaId":"960E66D9-2E5B-460A-A262-88FF1CE60750"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.2.0:*:*:*:*:*:*:*","matchCriteriaId":"2D61A37D-1A91-4C85-9737-E54670401FC6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.3.0:*:*:*:*:*:*:*","matchCriteriaId":"81CB5B34-09DE-4589-824C-97A6D696BD43"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.4.0:*:*:*:*:*:*:*","matchCriteriaId":"C9C5A188-6B92-46A2-9345-386F90BE362C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.4.1:*:*:*:*:*:*:*","matchCriteriaId":"6AE14E03-7043-486E-834E-54E39CA3341B"}]}]}],"references":[{"url":"http://www.openwall.com/lists/oss-security/2013/11/15/4","source":"secalert@redhat.com"},{"url":"https://www.gitlab.com/2013/11/14/multiple-critical-vulnerabilities-in-gitlab/","source":"secalert@redhat.com","tags":["Patch","Vendor Advisory"]},{"url":"http://www.openwall.com/lists/oss-security/2013/11/15/4","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.gitlab.com/2013/11/14/multiple-critical-vulnerabilities-in-gitlab/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2013-4490","sourceIdentifier":"secalert@redhat.com","published":"2014-05-13T15:55:03.937","lastModified":"2026-06-16T23:57:19.373","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"The SSH key upload feature (lib/gitlab_keys.rb) in gitlab-shell before 1.7.3, as used in GitLab 5.0 before 5.4.1 and 6.x before 6.2.3, allows remote authenticated users to execute arbitrary commands via shell metacharacters in the public key."},{"lang":"es","value":"La funcionalidad de de subida de clave SSH (lib/gitlab_keys.rb) en gitlab-shell anterior a 1.7.3, utilizado en GitLab 5.0 anterior a 5.4.1 y 6.x anterior a 6.2.3, permite a usuarios remotos autenticados ejecutar comandos arbitrarios a través de metacaracteres de shell en la clave pública."}],"affected":[{"source":"secalert@redhat.com","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.0.0:*:*:*:*:*:*:*","matchCriteriaId":"4DA23AF5-81E7-4D04-A224-DF823772EC06"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.0.1:*:*:*:*:*:*:*","matchCriteriaId":"5A780E86-D049-4C46-8481-2E55E974649C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.1.0:*:*:*:*:*:*:*","matchCriteriaId":"960E66D9-2E5B-460A-A262-88FF1CE60750"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.2.0:*:*:*:*:*:*:*","matchCriteriaId":"2D61A37D-1A91-4C85-9737-E54670401FC6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.3.0:*:*:*:*:*:*:*","matchCriteriaId":"81CB5B34-09DE-4589-824C-97A6D696BD43"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.4.0:*:*:*:*:*:*:*","matchCriteriaId":"C9C5A188-6B92-46A2-9345-386F90BE362C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:6.0.0:*:*:*:*:*:*:*","matchCriteriaId":"E82B301E-25BD-4438-9696-DF3E290F32B7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:6.1.0:*:*:*:*:*:*:*","matchCriteriaId":"E9B36BD3-69FA-4A22-9377-E86B8E9DFF8F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:6.2.0:*:*:*:*:*:*:*","matchCriteriaId":"DDD0A408-7007-4655-A159-12472E4A779E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:6.2.1:*:*:*:*:*:*:*","matchCriteriaId":"4A46F6D6-411B-428A-ACD4-01707433DA88"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:6.2.2:*:*:*:*:*:*:*","matchCriteriaId":"BE2BA4DB-3D3E-4DB2-A35C-52B89D357606"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab-shell:*:*:*:*:*:*:*:*","versionEndIncluding":"1.7.2","matchCriteriaId":"C3797783-B30D-43D8-AAC6-91DB75ABFAC9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab-shell:1.0.4:*:*:*:*:*:*:*","matchCriteriaId":"5468E7D1-96FD-4BCC-B35F-20B8A045CEBF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab-shell:1.1.0:*:*:*:*:*:*:*","matchCriteriaId":"8C66C8DB-919E-4D42-A8FB-2F1C08F19EBC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab-shell:1.2.0:*:*:*:*:*:*:*","matchCriteriaId":"989A3DDF-A7A8-4CA8-844C-12A5A7150866"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab-shell:1.3.0:*:*:*:*:*:*:*","matchCriteriaId":"E9693E73-B622-496C-8427-D8E3F8DA9DD7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab-shell:1.4.0:*:*:*:*:*:*:*","matchCriteriaId":"EC8F0260-C2EE-4DFB-B368-B55EB4A6FA93"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab-shell:1.5.0:*:*:*:*:*:*:*","matchCriteriaId":"98BB99C5-45C7-4982-A5C7-10319B2FCBCE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab-shell:1.6.0:*:*:*:*:*:*:*","matchCriteriaId":"E186CC7F-1C1F-41CB-88DB-B8DDE36EB7B8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab-shell:1.7.0:*:*:*:*:*:*:*","matchCriteriaId":"46778FDB-4863-451A-88C0-0C38D14C623D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab-shell:1.7.1:*:*:*:*:*:*:*","matchCriteriaId":"E2E2DA5C-61BB-4218-8FDA-57AC3C9C0172"}]}]}],"references":[{"url":"https://www.gitlab.com/2013/11/04/gitlab-ce-6-2-and-5-4-security-release/","source":"secalert@redhat.com","tags":["Patch","Vendor Advisory"]},{"url":"https://www.gitlab.com/2013/11/04/gitlab-ce-6-2-and-5-4-security-release/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"]}],"evaluatorComment":"Per: http://cwe.mitre.org/data/definitions/77.html\n\n\"CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')\""}},{"cve":{"id":"CVE-2013-4546","sourceIdentifier":"secalert@redhat.com","published":"2014-05-13T15:55:04.437","lastModified":"2026-06-16T23:57:25.673","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"The repository import feature in gitlab-shell before 1.7.4, as used in GitLab, allows remote authenticated users to execute arbitrary commands via the import URL."},{"lang":"es","value":"La funcionalidad de importación de repositorios en gitlab-shell anterior a 1.7.4, utilizado en GitLab, permite a usuarios remotos autenticados ejecutar comandos arbitrarios a través de la URL de importación."}],"affected":[{"source":"secalert@redhat.com","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.0.0:*:*:*:*:*:*:*","matchCriteriaId":"4DA23AF5-81E7-4D04-A224-DF823772EC06"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.0.1:*:*:*:*:*:*:*","matchCriteriaId":"5A780E86-D049-4C46-8481-2E55E974649C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.1.0:*:*:*:*:*:*:*","matchCriteriaId":"960E66D9-2E5B-460A-A262-88FF1CE60750"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.2.0:*:*:*:*:*:*:*","matchCriteriaId":"2D61A37D-1A91-4C85-9737-E54670401FC6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.3.0:*:*:*:*:*:*:*","matchCriteriaId":"81CB5B34-09DE-4589-824C-97A6D696BD43"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.4.0:*:*:*:*:*:*:*","matchCriteriaId":"C9C5A188-6B92-46A2-9345-386F90BE362C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.4.1:*:*:*:*:*:*:*","matchCriteriaId":"6AE14E03-7043-486E-834E-54E39CA3341B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.4.2:*:*:*:*:*:*:*","matchCriteriaId":"E0BCBC68-555F-4295-8E15-A4127702AAB4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:6.0.0:*:*:*:*:*:*:*","matchCriteriaId":"E82B301E-25BD-4438-9696-DF3E290F32B7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:6.1.0:*:*:*:*:*:*:*","matchCriteriaId":"E9B36BD3-69FA-4A22-9377-E86B8E9DFF8F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:6.2.0:*:*:*:*:*:*:*","matchCriteriaId":"DDD0A408-7007-4655-A159-12472E4A779E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:6.2.1:*:*:*:*:*:*:*","matchCriteriaId":"4A46F6D6-411B-428A-ACD4-01707433DA88"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:6.2.2:*:*:*:*:*:*:*","matchCriteriaId":"BE2BA4DB-3D3E-4DB2-A35C-52B89D357606"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab-shell:*:*:*:*:*:*:*:*","versionEndIncluding":"1.7.3","matchCriteriaId":"362C206A-3DF6-40BB-9534-06E19E62D2B9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab-shell:1.0.4:*:*:*:*:*:*:*","matchCriteriaId":"5468E7D1-96FD-4BCC-B35F-20B8A045CEBF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab-shell:1.1.0:*:*:*:*:*:*:*","matchCriteriaId":"8C66C8DB-919E-4D42-A8FB-2F1C08F19EBC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab-shell:1.2.0:*:*:*:*:*:*:*","matchCriteriaId":"989A3DDF-A7A8-4CA8-844C-12A5A7150866"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab-shell:1.3.0:*:*:*:*:*:*:*","matchCriteriaId":"E9693E73-B622-496C-8427-D8E3F8DA9DD7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab-shell:1.4.0:*:*:*:*:*:*:*","matchCriteriaId":"EC8F0260-C2EE-4DFB-B368-B55EB4A6FA93"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab-shell:1.5.0:*:*:*:*:*:*:*","matchCriteriaId":"98BB99C5-45C7-4982-A5C7-10319B2FCBCE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab-shell:1.6.0:*:*:*:*:*:*:*","matchCriteriaId":"E186CC7F-1C1F-41CB-88DB-B8DDE36EB7B8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab-shell:1.7.0:*:*:*:*:*:*:*","matchCriteriaId":"46778FDB-4863-451A-88C0-0C38D14C623D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab-shell:1.7.1:*:*:*:*:*:*:*","matchCriteriaId":"E2E2DA5C-61BB-4218-8FDA-57AC3C9C0172"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab-shell:1.7.2:*:*:*:*:*:*:*","matchCriteriaId":"C54EB6D2-4AAA-4567-B078-AE91317BF083"}]}]}],"references":[{"url":"http://www.openwall.com/lists/oss-security/2013/11/11/2","source":"secalert@redhat.com"},{"url":"https://gitlab.com/gitlab-org/gitlab-shell/blob/master/CHANGELOG","source":"secalert@redhat.com"},{"url":"https://www.gitlab.com/2013/11/08/security-vulnerability-in-gitlab-shell/","source":"secalert@redhat.com","tags":["Patch","Vendor Advisory"]},{"url":"http://www.openwall.com/lists/oss-security/2013/11/11/2","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://gitlab.com/gitlab-org/gitlab-shell/blob/master/CHANGELOG","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.gitlab.com/2013/11/08/security-vulnerability-in-gitlab-shell/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"]}],"evaluatorComment":"Per: http://cwe.mitre.org/data/definitions/77.html\n\n\"CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')\""}},{"cve":{"id":"CVE-2014-3456","sourceIdentifier":"cve@mitre.org","published":"2014-05-13T15:55:04.950","lastModified":"2026-06-17T00:08:13.063","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in GitLab Enterprise Edition (EE) 6.6.0 before 6.6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors."},{"lang":"es","value":"Vulnerabilidad de XSS en GitLab Enterprise Edition (EE) 6.6.0 anterior a 6.6.2 permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través de vectores no especificados."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:6.6.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"B5CAFFF0-C5A2-4622-BAB0-EEDF1B0488A7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:6.6.1:*:*:*:enterprise:*:*:*","matchCriteriaId":"9FE112F7-ED09-489D-AE8E-7FA212CF17D4"}]}]}],"references":[{"url":"https://www.gitlab.com/2014/02/27/gitlab-ee-6-6-2-security-release/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://www.gitlab.com/2014/02/27/gitlab-ee-6-6-2-security-release/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2013-4489","sourceIdentifier":"secalert@redhat.com","published":"2014-05-17T20:55:02.087","lastModified":"2026-06-16T23:57:19.270","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"The Grit gem for Ruby, as used in GitLab 5.2 before 5.4.1 and 6.x before 6.2.3, allows remote authenticated users to execute arbitrary commands, as demonstrated by the search box for the GitLab code search feature."},{"lang":"es","value":"La gema Grit para Ruby, utilizado en GitLab 5.2 anterior a 5.4.1 y 6.x anterior a 6.2.3, permite a usuarios remotos autenticados ejecutar comandos arbitrarios, tal y como fue demostrado por el cuadro de búsqueda para la funcionalidad de búsqueda de código de GitLab."}],"affected":[{"source":"secalert@redhat.com","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.2.0:*:*:*:*:*:*:*","matchCriteriaId":"2D61A37D-1A91-4C85-9737-E54670401FC6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.3.0:*:*:*:*:*:*:*","matchCriteriaId":"81CB5B34-09DE-4589-824C-97A6D696BD43"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:5.4.0:*:*:*:*:*:*:*","matchCriteriaId":"C9C5A188-6B92-46A2-9345-386F90BE362C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:6.0.0:*:*:*:*:*:*:*","matchCriteriaId":"E82B301E-25BD-4438-9696-DF3E290F32B7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:6.1.0:*:*:*:*:*:*:*","matchCriteriaId":"E9B36BD3-69FA-4A22-9377-E86B8E9DFF8F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:6.2.0:*:*:*:*:*:*:*","matchCriteriaId":"DDD0A408-7007-4655-A159-12472E4A779E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:6.2.1:*:*:*:*:*:*:*","matchCriteriaId":"4A46F6D6-411B-428A-ACD4-01707433DA88"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:6.2.2:*:*:*:*:*:*:*","matchCriteriaId":"BE2BA4DB-3D3E-4DB2-A35C-52B89D357606"}]}]}],"references":[{"url":"https://www.gitlab.com/2013/11/04/gitlab-ce-6-2-and-5-4-security-release/","source":"secalert@redhat.com","tags":["Patch","Vendor Advisory"]},{"url":"https://www.gitlab.com/2013/11/04/gitlab-ce-6-2-and-5-4-security-release/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"]}],"evaluatorComment":"Per: http://cwe.mitre.org/data/definitions/77.html\n\n\"CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')\""}},{"cve":{"id":"CVE-2016-9086","sourceIdentifier":"cve@mitre.org","published":"2016-11-03T10:59:09.763","lastModified":"2026-06-17T00:55:30.017","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab versions 8.9.x and above contain a critical security flaw in the \"import/export project\" feature of GitLab. Added in GitLab 8.9, this feature allows a user to export and then re-import their projects as tape archive files (tar). All GitLab versions prior to 8.13.0 restricted this feature to administrators only. Starting with version 8.13.0 this feature was made available to all users. This feature did not properly check for symbolic links in user-provided archives and therefore it was possible for an authenticated user to retrieve the contents of any file accessible to the GitLab service account. This included sensitive files such as those that contain secret tokens used by the GitLab service to authenticate users. GitLab CE and EE versions 8.13.0 through 8.13.2, 8.12.0 through 8.12.7, 8.11.0 through 8.11.10, 8.10.0 through 8.10.12, and 8.9.0 through 8.9.11 are affected."},{"lang":"es","value":"GitLab en versiones 8.9.x y superiores contienen un fallo crítico de seguridad en la funcionalidad \"import/export project\" de GitLab. Añadida en GitLab 8.9, esta funcionalidad permite a usuarios exportar y después reimportar sus proyectos como fichero de archivador en cinta (tar). Todas las versiones GitLab anteriores a 8.13.0 restringieron esta funcionalidad solo para administradores. Empezando con la versión 8.13.0 esta funcionalidad se hizo disponible para todos los usuarios. Esta funcionalidad no comprobaba correctamente si hay enlaces simbólicos en archivos proporcionados por el usuario y por lo tanto era posible para un usuario autenticado recuperar los contenidos de cualquier archivo accesible a la cuenta de servicio GitLab. Esto incluía archivos sensibles tales como aquellos que contienen tokens secretos usados por el servicio GitLab para autenticar usuarios. GitLab CE y EE versiones 8.13.0 hasta la versión 8.13.2, 8.12.0 hasta la versión 8.12.7, 8.11.0 hasta la versión 8.11.10, 8.10.0 hasta la versión 8.10.12 y 8.9.0 hasta la versión 8.9.11 están afectadas."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-200"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.9.0:*:*:*:*:*:*:*","matchCriteriaId":"D7715B61-3870-465A-BBBB-4B26C8A2D7D2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.9.1:*:*:*:*:*:*:*","matchCriteriaId":"0E789937-C1AD-411D-A40C-F0CE46D806A9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.9.2:*:*:*:*:*:*:*","matchCriteriaId":"34B3AAE7-4172-4C43-87A9-5FD1A3C18EEE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.9.3:*:*:*:*:*:*:*","matchCriteriaId":"18D59DC5-9794-43EF-9DAA-63E6DE319D79"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.9.4:*:*:*:*:*:*:*","matchCriteriaId":"D83EC588-436E-4929-A6E7-9B854A5DF1ED"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.9.5:*:*:*:*:*:*:*","matchCriteriaId":"873D8280-A64D-427D-9A60-36B1AABEC4B5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.9.6:*:*:*:*:*:*:*","matchCriteriaId":"205B8A64-8C90-458B-8355-89915806941F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.9.7:*:*:*:*:*:*:*","matchCriteriaId":"0204D6F7-7FF0-49D6-B17E-707D74ACB0AA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.9.8:*:*:*:*:*:*:*","matchCriteriaId":"1F6E56D3-0737-4C2B-B587-1C351419AA35"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.9.9:*:*:*:*:*:*:*","matchCriteriaId":"A789A4E9-FB36-4F6C-A0F3-A2C0D7F69DCF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.9.10:*:*:*:*:*:*:*","matchCriteriaId":"472A9889-2B4E-4223-A90F-A3A73B03E2DE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.9.11:*:*:*:*:*:*:*","matchCriteriaId":"C8571B1A-ECF9-43BB-A8BF-D8BE4EB0F73A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.10.0:*:*:*:*:*:*:*","matchCriteriaId":"9CAC2DE6-B831-4007-993B-A09174A03287"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.10.1:*:*:*:*:*:*:*","matchCriteriaId":"98818EF5-29F0-4085-9123-41369EA2FDC0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.10.2:*:*:*:*:*:*:*","matchCriteriaId":"6FA1D737-42A6-4C3B-995C-39F081543A85"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.10.3:*:*:*:*:*:*:*","matchCriteriaId":"0473E75B-7990-4A9B-BB34-099C7BAFBBAC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.10.4:*:*:*:*:*:*:*","matchCriteriaId":"A1D5769F-4A12-462F-AAA6-30551C415016"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.10.5:*:*:*:*:*:*:*","matchCriteriaId":"6CD19A0C-7908-4E92-9153-8B197E2AC12B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.10.6:*:*:*:*:*:*:*","matchCriteriaId":"C4A803A0-517E-44A4-B34B-EE7C14DFC041"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.10.7:*:*:*:*:*:*:*","matchCriteriaId":"431B968E-4F85-4366-9E18-8BD9BAD9A58C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.10.8:*:*:*:*:*:*:*","matchCriteriaId":"6FADB9B6-A01B-4F67-A6EA-8CE89DEA68CF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.10.9:*:*:*:*:*:*:*","matchCriteriaId":"E61AFC76-12EA-4F46-AF48-3C94AD108D9A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.10.10:*:*:*:*:*:*:*","matchCriteriaId":"42C6F40E-B26D-442D-BC01-D574D594661A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.10.11:*:*:*:*:*:*:*","matchCriteriaId":"B2695159-5D65-444A-9650-4EF4D5214B01"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.10.12:*:*:*:*:*:*:*","matchCriteriaId":"684B8D23-4FFF-4B51-A2B4-B92B2F2FFD46"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.11.0:*:*:*:*:*:*:*","matchCriteriaId":"DA526583-A266-41A9-B692-189FB4E04DD3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.11.1:*:*:*:*:*:*:*","matchCriteriaId":"E0E2BA5F-C827-46F0-ADE9-C7D5F9BF3623"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.11.2:*:*:*:*:*:*:*","matchCriteriaId":"DECAC17B-6809-4A1A-98D5-F80D391B7D42"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.11.3:*:*:*:*:*:*:*","matchCriteriaId":"57376934-DCCE-4828-AF89-C5A3B865AB70"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.11.4:*:*:*:*:*:*:*","matchCriteriaId":"2AC4AD5F-A8DD-481D-9890-872DC11C34F6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.11.5:*:*:*:*:*:*:*","matchCriteriaId":"EDF04BB7-B751-4E63-9D3A-EF6AAF3896E5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.11.6:*:*:*:*:*:*:*","matchCriteriaId":"24B8F054-2E97-42FD-97EE-3CA23819010C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.11.7:*:*:*:*:*:*:*","matchCriteriaId":"017A2E6C-1F62-41B1-9381-7104BEC719AB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.11.8:*:*:*:*:*:*:*","matchCriteriaId":"88E68FFB-783D-4135-AA5E-8539AAC96BF8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.11.9:*:*:*:*:*:*:*","matchCriteriaId":"CC9C7F22-2BAC-4598-9802-E00A889A776B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.12.0:*:*:*:*:*:*:*","matchCriteriaId":"1E538AD7-ED6B-4092-96A5-FC3C60433BE9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.12.1:*:*:*:*:*:*:*","matchCriteriaId":"9A15047C-B8E9-4268-BEA3-92FD829DBA52"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.12.2:*:*:*:*:*:*:*","matchCriteriaId":"B6DBD66C-811D-4E53-ACBD-8ACDA5A36278"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.12.3:*:*:*:*:*:*:*","matchCriteriaId":"712493CD-ABA0-4DFD-B738-3E3B86D60A8E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.12.4:*:*:*:*:*:*:*","matchCriteriaId":"93B72CAD-84F5-45CD-889A-9DE3644FFF75"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.12.5:*:*:*:*:*:*:*","matchCriteriaId":"CF01C643-4DAE-4D59-8C8A-24AD51AA8439"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.12.6:*:*:*:*:*:*:*","matchCriteriaId":"2A9D62B9-5524-4C04-81CF-777397A91332"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.12.7:*:*:*:*:*:*:*","matchCriteriaId":"8105E28D-A21C-4C89-8235-0292F3D1DCE0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.13.0:*:*:*:*:*:*:*","matchCriteriaId":"C40FEF39-FBD8-49D3-ACB5-DA4CE6275997"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.13.1:*:*:*:*:*:*:*","matchCriteriaId":"B8295BEE-F094-456B-9E7E-F1F5F0BFE3C1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.13.2:*:*:*:*:*:*:*","matchCriteriaId":"AFD032AA-5160-4446-8256-BF3993C0C6D8"}]}]}],"references":[{"url":"http://www.securityfocus.com/bid/94136","source":"cve@mitre.org","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://about.gitlab.com/2016/11/02/cve-2016-9086-patches/","source":"cve@mitre.org","tags":["Mitigation","Patch","Vendor Advisory"]},{"url":"http://www.securityfocus.com/bid/94136","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://about.gitlab.com/2016/11/02/cve-2016-9086-patches/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mitigation","Patch","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2016-4340","sourceIdentifier":"cve@mitre.org","published":"2017-01-23T21:59:01.487","lastModified":"2026-06-17T00:47:22.557","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"The impersonate feature in Gitlab 8.7.0, 8.6.0 through 8.6.7, 8.5.0 through 8.5.11, 8.4.0 through 8.4.9, 8.3.0 through 8.3.8, and 8.2.0 through 8.2.4 allows remote authenticated users to \"log in\" as any other user via unspecified vectors."},{"lang":"es","value":"La característica de suplantación en Gitlab 8.7.0, 8.6.0 hasta la versión 8.6.7, 8.5.0 hasta la versión 8.5.11, 8.4.0 hasta la versión 8.4.9, 8.3.0 hasta la versión 8.3.8 y 8.2.0 hasta la versión 8.2.4 permite a usuarios remotos autenticados para \"iniciar sesión\" como cualquier otro usuario a través de vectores no especificados."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-264"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.2.0:*:*:*:*:*:*:*","matchCriteriaId":"6F6ACB05-8D9C-4ECA-B16B-C921E4FD31DF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.2.1:*:*:*:*:*:*:*","matchCriteriaId":"27A9A324-CAAF-44E2-ADC0-E53AE2A7E938"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.2.2:*:*:*:*:*:*:*","matchCriteriaId":"23B02581-E578-4E7F-96C9-4F7A96BE7860"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.2.3:*:*:*:*:*:*:*","matchCriteriaId":"68D04194-FB0E-453E-B929-D1325DA16A7D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.2.4:*:*:*:*:*:*:*","matchCriteriaId":"557FA9F7-F3EC-488C-95F7-C5C46193FAD5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.3.0:*:*:*:*:*:*:*","matchCriteriaId":"5AB1E9DA-044D-4C0F-B9D2-7968EEAC1E53"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.3.1:*:*:*:*:*:*:*","matchCriteriaId":"8F8C211D-EBB4-4BCA-A2C5-822FF8CDF8EF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.3.2:*:*:*:*:*:*:*","matchCriteriaId":"C4CB8EEA-DEAB-4AD4-982F-4EF9BE64383E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.3.3:*:*:*:*:*:*:*","matchCriteriaId":"1AF5F349-A3F2-428A-9633-6E539FF9076C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.3.4:*:*:*:*:*:*:*","matchCriteriaId":"7F2F3687-5F61-45B7-B8FD-8EE811B498CA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.3.5:*:*:*:*:*:*:*","matchCriteriaId":"899284C0-78D7-4C08-9FD8-914CB9EFDB21"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.3.6:*:*:*:*:*:*:*","matchCriteriaId":"57014FD4-B830-447B-81D0-7D06443A823B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.3.7:*:*:*:*:*:*:*","matchCriteriaId":"8F8F7599-7B77-4FD1-8500-9642C710964F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.3.8:*:*:*:*:*:*:*","matchCriteriaId":"009D7D10-9596-4BDE-8316-7F12C2661DA1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.4.0:*:*:*:*:*:*:*","matchCriteriaId":"9B4C899C-79DD-4BF0-A47F-AC7BDCB0E9D2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.4.1:*:*:*:*:*:*:*","matchCriteriaId":"BF1169BC-5AB5-4AF9-A24E-8248D44B155A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.4.2:*:*:*:*:*:*:*","matchCriteriaId":"35B03219-1693-4EEE-9F1B-60AEE70EE951"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.4.3:*:*:*:*:*:*:*","matchCriteriaId":"758FF583-64B8-4FA5-A93C-6396AD8F7AB1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.4.4:*:*:*:*:*:*:*","matchCriteriaId":"EA96A87C-3BEE-47A2-8B1B-753C83287CDE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.4.5:*:*:*:*:*:*:*","matchCriteriaId":"78565647-D678-4A66-82CF-EEDFFB626E22"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.4.6:*:*:*:*:*:*:*","matchCriteriaId":"24DA2765-EF74-4BEE-B9A7-51AB9BB9243F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.4.7:*:*:*:*:*:*:*","matchCriteriaId":"087421A5-2590-4D51-B495-5F02580D7180"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.4.8:*:*:*:*:*:*:*","matchCriteriaId":"74B5890A-03F7-4819-86BC-7E78F89B2FE8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.4.9:*:*:*:*:*:*:*","matchCriteriaId":"193016A1-7935-43C3-99DF-0DA2810DBDAE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.5.0:*:*:*:*:*:*:*","matchCriteriaId":"BB84AB58-030E-4D9C-80FC-F95D9A9F89C6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.5.1:*:*:*:*:*:*:*","matchCriteriaId":"03166423-5AB0-4E48-BA92-093B892B3A9E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.5.2:*:*:*:*:*:*:*","matchCriteriaId":"29CBEDBE-538B-48F6-9826-38308F1BC145"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.5.3:*:*:*:*:*:*:*","matchCriteriaId":"26E5E290-F466-4155-9880-7582308F5979"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.5.4:*:*:*:*:*:*:*","matchCriteriaId":"0C9E4947-A678-47F1-A1E1-0EFB36B28F26"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.5.5:*:*:*:*:*:*:*","matchCriteriaId":"D53BAE6E-BD98-49E1-9827-B3AB927F6966"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.5.6:*:*:*:*:*:*:*","matchCriteriaId":"C5F5D35D-F1B1-4EF4-B8C6-08D854B24571"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.5.7:*:*:*:*:*:*:*","matchCriteriaId":"3E0DA079-A62F-4AB7-95F9-FCBEC883C37E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.5.8:*:*:*:*:*:*:*","matchCriteriaId":"92096CB1-5482-4FB5-B3ED-B38515CB78F9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.5.9:*:*:*:*:*:*:*","matchCriteriaId":"365CB864-3465-4482-9D22-9E3D4B889A5F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.5.10:*:*:*:*:*:*:*","matchCriteriaId":"4BB1188E-A748-4830-AC6E-DE4B0D57A200"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.5.11:*:*:*:*:*:*:*","matchCriteriaId":"9FA814A1-FD0B-4E47-844A-285E379843F9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.6.0:*:*:*:*:*:*:*","matchCriteriaId":"671B6F4B-DD3F-4E1A-9CE4-A6F9381BC4AC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.6.1:*:*:*:*:*:*:*","matchCriteriaId":"ADB9541A-A7C6-4DD6-A4FA-ABE274E475D5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.6.2:*:*:*:*:*:*:*","matchCriteriaId":"6EDC2B83-2528-416B-A0CF-4A1FE83200D4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.6.3:*:*:*:*:*:*:*","matchCriteriaId":"283ADBFD-F105-4B22-9105-702792D6D6E9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.6.4:*:*:*:*:*:*:*","matchCriteriaId":"8A97D45B-6D3E-48DE-AB58-9177B3646C71"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.6.5:*:*:*:*:*:*:*","matchCriteriaId":"5EA8B14A-68AD-430D-A8D0-419F38CDC31C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.6.6:*:*:*:*:*:*:*","matchCriteriaId":"D359FA9B-37BD-405A-9D85-042FE642AADC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.6.7:*:*:*:*:*:*:*","matchCriteriaId":"C232B818-420C-4ED6-AB7C-FB1605B18984"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.7.0:*:*:*:*:*:*:*","matchCriteriaId":"E41E3701-D240-4B18-919B-E2B64950FCF9"}]}]}],"references":[{"url":"http://packetstormsecurity.com/files/138368/GitLab-Impersonate-Privilege-Escalation.html","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory","VDB Entry"]},{"url":"https://about.gitlab.com/2016/05/02/cve-2016-4340-patches/","source":"cve@mitre.org","tags":["Mitigation","Patch","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/15548","source":"cve@mitre.org","tags":["Issue Tracking","Patch","Vendor Advisory"]},{"url":"https://www.exploit-db.com/exploits/40236/","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory","VDB Entry"]},{"url":"http://packetstormsecurity.com/files/138368/GitLab-Impersonate-Privilege-Escalation.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory","VDB Entry"]},{"url":"https://about.gitlab.com/2016/05/02/cve-2016-4340-patches/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mitigation","Patch","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/15548","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Patch","Vendor Advisory"]},{"url":"https://www.exploit-db.com/exploits/40236/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory","VDB Entry"]}]}},{"cve":{"id":"CVE-2016-9469","sourceIdentifier":"support@hackerone.com","published":"2017-03-28T02:59:01.247","lastModified":"2026-06-17T00:56:07.910","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Multiple versions of GitLab expose a dangerous method to any authenticated user that could lead to the deletion of all Issue and MergeRequest objects on a GitLab instance. For GitLab instances with publicly available projects this vulnerability could be exploited by an unauthenticated user. A fix was included in versions 8.14.3, 8.13.8, and 8.12.11, which were released on December 5th 2016 at 3:59 PST. The GitLab versions vulnerable to this are 8.13.0, 8.13.0-ee, 8.13.1, 8.13.1-ee, 8.13.2, 8.13.2-ee, 8.13.3, 8.13.3-ee, 8.13.4, 8.13.4-ee, 8.13.5, 8.13.5-ee, 8.13.6, 8.13.6-ee, 8.13.7, 8.14.0, 8.14.0-ee, 8.14.1, 8.14.2, and 8.14.2-ee."},{"lang":"es","value":"Multiples versiones de GitLab exponen un método peligroso a cualquier usuario autenticado que podría llevar a la eliminación de todos los problemas y objetos MergeRequest en una instancia de GitLab. Para las instancias de GitLab con proyectos disponibles públicamente, esta vulnerabilidad podría ser explotada por un usuario no autenticado. Se incluyó una revisión en las versiones 8.14.3, 8.13.8 y 8.12.11, que se publicaron el 5 de diciembre de 2016 a las 3:59 PST. Las versiones de GitLab vulnerables a esto son 8.13.0, 8.13.0-ee, 8.13.1, 8.13.1-ee, 8.13.2, 8.13.2-ee, 8.13.3, 8.13.3-ee, 8.13.4 , 8.13.4-ee, 8.13.5, 8.13.5-ee, 8.13.6, 8.13.6-ee, 8.13.7, 8.14.0, 8.14.0-ee, 8.14.1, 8.14.2 y 8.14.2-ee."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"n/a","product":"GitLab Community Edition & GitLab Enterprise Edition 8.13.0, 8.13.0-ee, 8.13.1, 8.13.1-ee, 8.13.2, 8.13.2-ee, 8.13.3, 8.13.3-ee, 8.13.4, 8.13.4-ee, 8.13.5, 8.13.5-ee, 8.13.6, 8.13.6-ee, 8.13.7, 8.14.0, 8.14.0-ee, 8.14.1","versions":[{"version":"GitLab Community Edition & GitLab Enterprise Edition 8.13.0, 8.13.0-ee, 8.13.1, 8.13.1-ee, 8.13.2, 8.13.2-ee, 8.13.3, 8.13.3-ee, 8.13.4, 8.13.4-ee, 8.13.5, 8.13.5-ee, 8.13.6, 8.13.6-ee, 8.13.7, 8.14.0, 8.14.0-ee, 8.14.1","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L","baseScore":8.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":4.2}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":true,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"support@hackerone.com","type":"Secondary","description":[{"lang":"en","value":"CWE-749"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-264"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.13.0:*:*:*:*:*:*:*","matchCriteriaId":"C40FEF39-FBD8-49D3-ACB5-DA4CE6275997"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.13.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"BF27DE16-6B02-4B8C-8171-644F96B91EC5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.13.1:*:*:*:*:*:*:*","matchCriteriaId":"B8295BEE-F094-456B-9E7E-F1F5F0BFE3C1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.13.1:*:*:*:enterprise:*:*:*","matchCriteriaId":"309BE602-C30A-453B-B53E-87559A4A65C6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.13.2:*:*:*:*:*:*:*","matchCriteriaId":"AFD032AA-5160-4446-8256-BF3993C0C6D8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.13.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"0D1AEB22-B278-40B8-959B-59DF4CCE1756"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.13.3:*:*:*:*:*:*:*","matchCriteriaId":"71F7D77B-E9F9-429C-9000-E4EB8D6C6E05"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.13.3:*:*:*:enterprise:*:*:*","matchCriteriaId":"6E6C2412-07E9-494C-8374-D23244896593"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.13.4:*:*:*:*:*:*:*","matchCriteriaId":"EE4D9EBA-9E51-42F3-82EA-B40402B2EBE4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.13.4:*:*:*:enterprise:*:*:*","matchCriteriaId":"8754F4EA-AA92-4308-BCE1-F6214A502368"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.13.5:*:*:*:*:*:*:*","matchCriteriaId":"8EA5D200-683D-46E0-9216-C90C5E5988CA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.13.5:*:*:*:enterprise:*:*:*","matchCriteriaId":"46015599-12C0-4DFA-BBF9-2252446C899A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.13.6:*:*:*:*:*:*:*","matchCriteriaId":"4C63754F-06CE-45CA-A127-9D1F357F76F3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.13.6:*:*:*:enterprise:*:*:*","matchCriteriaId":"38D6EBF6-43D0-4D5E-A21D-29D775593236"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.13.7:*:*:*:*:*:*:*","matchCriteriaId":"0415B7C5-992B-43A0-BD4D-910DF77A985F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.13.7:*:*:*:enterprise:*:*:*","matchCriteriaId":"E36DA897-3A68-454F-90B8-B83E6D28AC73"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.14.0:*:*:*:*:*:*:*","matchCriteriaId":"A6B3C6A7-EB60-41DA-AB67-CB5CF93B0A04"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.14.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"234CD36B-CEAC-4C89-A515-22D088589024"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.14.1:*:*:*:*:*:*:*","matchCriteriaId":"79E47F6A-A7E1-4876-8C05-329959522C97"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.14.1:*:*:*:enterprise:*:*:*","matchCriteriaId":"A044ACCF-7534-4A81-9F66-7235CA4B74C9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.14.2:*:*:*:*:*:*:*","matchCriteriaId":"1CF6FC6C-2489-4798-8143-985C2101CDC5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.14.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"6265E089-155E-474C-B020-85C75EE500E0"}]}]}],"references":[{"url":"https://about.gitlab.com/2016/12/05/cve-2016-9469/","source":"support@hackerone.com","tags":["Patch","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/commit/29ceb98b5162677601702704e89d845580372078","source":"support@hackerone.com","tags":["Patch","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/commit/55196497301eea429913f9c4b1b37c42c2e358ce","source":"support@hackerone.com","tags":["Patch","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/commit/f325e4e734e5e486f3b02db176eb629124052b43","source":"support@hackerone.com","tags":["Patch","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/25064","source":"support@hackerone.com","tags":["Exploit","Vendor Advisory"]},{"url":"https://hackerone.com/reports/186194","source":"support@hackerone.com","tags":["Exploit","Technical Description","Third Party Advisory"]},{"url":"https://about.gitlab.com/2016/12/05/cve-2016-9469/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/commit/29ceb98b5162677601702704e89d845580372078","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/commit/55196497301eea429913f9c4b1b37c42c2e358ce","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/commit/f325e4e734e5e486f3b02db176eb629124052b43","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/25064","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]},{"url":"https://hackerone.com/reports/186194","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Technical Description","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2017-0882","sourceIdentifier":"support@hackerone.com","published":"2017-03-28T02:59:01.497","lastModified":"2026-06-17T00:58:27.460","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Multiple versions of GitLab expose sensitive user credentials when assigning a user to an issue or merge request. A fix was included in versions 8.15.8, 8.16.7, and 8.17.4, which were released on March 20th 2017 at 23:59 UTC."},{"lang":"es","value":"Multiples versiones de GitLab exponen credenciales de usuario confidenciales al asignar un usuario a una solicitud de emisión o de combinación. Una correción fue incluida en las versiones 8.15.8, 8.16.7 y 8.17.4, que se publicaron el 20 de marzo de 2017 a las 23:59 UTC."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"n/a","product":"GitLab Community Edition and GitLab Enterprise Edition 8.7.0 through 8.15.7, 8.16.0 through 8.16.7, 8.17.0 through 8.17.3","versions":[{"version":"GitLab Community Edition and GitLab Enterprise Edition 8.7.0 through 8.15.7, 8.16.0 through 8.16.7, 8.17.0 through 8.17.3","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","baseScore":6.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":3.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":true,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"support@hackerone.com","type":"Secondary","description":[{"lang":"en","value":"CWE-639"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-200"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.2.0:*:*:*:*:*:*:*","matchCriteriaId":"6F6ACB05-8D9C-4ECA-B16B-C921E4FD31DF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.2.1:*:*:*:*:*:*:*","matchCriteriaId":"27A9A324-CAAF-44E2-ADC0-E53AE2A7E938"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.2.2:*:*:*:*:*:*:*","matchCriteriaId":"23B02581-E578-4E7F-96C9-4F7A96BE7860"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.2.3:*:*:*:*:*:*:*","matchCriteriaId":"68D04194-FB0E-453E-B929-D1325DA16A7D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.2.4:*:*:*:*:*:*:*","matchCriteriaId":"557FA9F7-F3EC-488C-95F7-C5C46193FAD5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.2.5:*:*:*:*:*:*:*","matchCriteriaId":"DE38D462-28F8-4356-B80D-7BEB45051E6A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.3.0:*:*:*:*:*:*:*","matchCriteriaId":"5AB1E9DA-044D-4C0F-B9D2-7968EEAC1E53"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.3.8:*:*:*:*:*:*:*","matchCriteriaId":"009D7D10-9596-4BDE-8316-7F12C2661DA1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.3.9:*:*:*:*:*:*:*","matchCriteriaId":"8AADF57A-A54C-4FE9-9DCB-B7FD3C961BA2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.4.0:*:*:*:*:*:*:*","matchCriteriaId":"9B4C899C-79DD-4BF0-A47F-AC7BDCB0E9D2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.4.9:*:*:*:*:*:*:*","matchCriteriaId":"193016A1-7935-43C3-99DF-0DA2810DBDAE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.4.10:*:*:*:*:*:*:*","matchCriteriaId":"EA3D7D48-E172-4F2F-8307-F251B52B175F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.5.0:*:*:*:*:*:*:*","matchCriteriaId":"BB84AB58-030E-4D9C-80FC-F95D9A9F89C6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.5.11:*:*:*:*:*:*:*","matchCriteriaId":"9FA814A1-FD0B-4E47-844A-285E379843F9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.5.12:*:*:*:*:*:*:*","matchCriteriaId":"7A269B0E-7DEC-45BA-8F81-26D38DD10272"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.6.0:*:*:*:*:*:*:*","matchCriteriaId":"671B6F4B-DD3F-4E1A-9CE4-A6F9381BC4AC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.6.7:*:*:*:*:*:*:*","matchCriteriaId":"C232B818-420C-4ED6-AB7C-FB1605B18984"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.6.8:*:*:*:*:*:*:*","matchCriteriaId":"36543899-741F-4C1D-9E40-653D256F5FAE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.7.0:*:*:*:*:*:*:*","matchCriteriaId":"E41E3701-D240-4B18-919B-E2B64950FCF9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.7.1:*:*:*:*:*:*:*","matchCriteriaId":"3A7829B6-98E9-4364-9A2E-2DFD61C3265F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.10.0:*:*:*:*:*:*:*","matchCriteriaId":"9CAC2DE6-B831-4007-993B-A09174A03287"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.10.12:*:*:*:*:*:*:*","matchCriteriaId":"684B8D23-4FFF-4B51-A2B4-B92B2F2FFD46"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.10.13:*:*:*:*:*:*:*","matchCriteriaId":"3376C0CB-F443-40CD-92DE-E2A753BBCB7A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.11.0:*:*:*:*:*:*:*","matchCriteriaId":"DA526583-A266-41A9-B692-189FB4E04DD3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.11.9:*:*:*:*:*:*:*","matchCriteriaId":"CC9C7F22-2BAC-4598-9802-E00A889A776B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.11.10:*:*:*:*:*:*:*","matchCriteriaId":"B3AF796E-AC2A-4960-81E6-988FE2F8F889"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.12.0:*:*:*:*:*:*:*","matchCriteriaId":"1E538AD7-ED6B-4092-96A5-FC3C60433BE9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.12.7:*:*:*:*:*:*:*","matchCriteriaId":"8105E28D-A21C-4C89-8235-0292F3D1DCE0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.12.8:*:*:*:*:*:*:*","matchCriteriaId":"B2E64274-D2C0-4CE2-986C-9DA47D0CF14C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.13.0:*:*:*:*:*:*:*","matchCriteriaId":"C40FEF39-FBD8-49D3-ACB5-DA4CE6275997"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.13.2:*:*:*:*:*:*:*","matchCriteriaId":"AFD032AA-5160-4446-8256-BF3993C0C6D8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.13.3:*:*:*:*:*:*:*","matchCriteriaId":"71F7D77B-E9F9-429C-9000-E4EB8D6C6E05"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.14.0:*:*:*:*:*:*:*","matchCriteriaId":"A6B3C6A7-EB60-41DA-AB67-CB5CF93B0A04"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.14.1:*:*:*:*:*:*:*","matchCriteriaId":"79E47F6A-A7E1-4876-8C05-329959522C97"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.14.2:*:*:*:*:*:*:*","matchCriteriaId":"1CF6FC6C-2489-4798-8143-985C2101CDC5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.14.3:*:*:*:*:*:*:*","matchCriteriaId":"126EE901-4DCB-4404-9B63-91692569A9E9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.14.4:*:*:*:*:*:*:*","matchCriteriaId":"D830B0CD-050C-43BE-8D5C-896B8EE8CBC4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.14.5:*:*:*:*:*:*:*","matchCriteriaId":"0C1A1D52-0962-4330-B81D-B85FCA38F5CD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.14.6:*:*:*:*:*:*:*","matchCriteriaId":"80FF90DE-8982-4F56-8444-11D6C920646D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.15.0:*:*:*:*:*:*:*","matchCriteriaId":"50E67A7C-962E-49EE-8B4C-86D764770EDE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.15.1:*:*:*:*:*:*:*","matchCriteriaId":"8CE48CAF-F691-4409-96F9-CBB3903D251D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.15.2:*:*:*:*:*:*:*","matchCriteriaId":"C2B07763-013A-48EE-AFB7-3CBB3DFAD60C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.15.3:*:*:*:*:*:*:*","matchCriteriaId":"0BDE7E4A-12A3-46A6-AE35-075247CF1226"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.15.4:*:*:*:*:*:*:*","matchCriteriaId":"1F3C2EAC-68C0-4444-A366-238A54A96484"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.15.5:*:*:*:*:*:*:*","matchCriteriaId":"42C1AA52-622D-4867-AB95-C64DDC185454"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.15.6:*:*:*:*:*:*:*","matchCriteriaId":"572A743D-ACAD-43B4-AD99-6C9DFE48A870"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.15.7:*:*:*:*:*:*:*","matchCriteriaId":"0915C33D-41C1-43EB-BA21-D6037362EE8A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.16.0:*:*:*:*:*:*:*","matchCriteriaId":"A1965736-D73F-44DC-BA29-D992CCEA9657"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.16.1:*:*:*:*:*:*:*","matchCriteriaId":"3E274B52-360B-4F06-B307-89C6D044E444"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.16.2:*:*:*:*:*:*:*","matchCriteriaId":"02F132ED-1CC0-4A58-988F-B61D69FEB99E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.16.3:*:*:*:*:*:*:*","matchCriteriaId":"F9663040-C06C-4C11-9384-6DE1DE64A8C6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.16.4:*:*:*:*:*:*:*","matchCriteriaId":"D20B405B-38EB-4F10-AAE3-700EBB5F5E02"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.16.5:*:*:*:*:*:*:*","matchCriteriaId":"5B9BEA77-CE45-4F92-B525-B1544B5B14A9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.16.6:*:*:*:*:*:*:*","matchCriteriaId":"DA429762-A81D-4C40-8A66-1EF4E39DCFEC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.16.7:*:*:*:*:*:*:*","matchCriteriaId":"7C06917C-E634-4C67-8DB9-7C98DA7E3883"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.17.0:*:*:*:*:*:*:*","matchCriteriaId":"CF7CEF22-F432-4D22-87C2-1E13BEBCDE7A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.17.1:*:*:*:*:*:*:*","matchCriteriaId":"94FFBA26-4229-4E61-9B0E-A6E5E09FDB05"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.17.2:*:*:*:*:*:*:*","matchCriteriaId":"08A74068-14F2-4976-86DE-818683A1FF7C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.17.3:*:*:*:*:*:*:*","matchCriteriaId":"045FF5B3-7AE0-48B0-8266-CB515BC9B20D"}]}]}],"references":[{"url":"http://www.securityfocus.com/bid/97157","source":"support@hackerone.com","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://about.gitlab.com/2017/03/20/gitlab-8-dot-17-dot-4-security-release/","source":"support@hackerone.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/commit/43f5a2739dbf8f5c4c16a79f98e2630888f6b5d1","source":"support@hackerone.com","tags":["Patch","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/commit/a70346fc6530aa28a98e4aa4cf0f40e2c3bcef6b","source":"support@hackerone.com","tags":["Patch","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/commit/cdf396f456472ef8decd9598daa8dc0097cd30c5","source":"support@hackerone.com","tags":["Patch","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/29661","source":"support@hackerone.com","tags":["Exploit","Vendor Advisory"]},{"url":"http://www.securityfocus.com/bid/97157","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://about.gitlab.com/2017/03/20/gitlab-8-dot-17-dot-4-security-release/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/commit/43f5a2739dbf8f5c4c16a79f98e2630888f6b5d1","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/commit/a70346fc6530aa28a98e4aa4cf0f40e2c3bcef6b","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/commit/cdf396f456472ef8decd9598daa8dc0097cd30c5","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/29661","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2017-8778","sourceIdentifier":"cve@mitre.org","published":"2017-05-04T15:29:00.157","lastModified":"2026-06-17T01:26:56.687","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab before 8.14.9, 8.15.x before 8.15.6, and 8.16.x before 8.16.5 has XSS via a SCRIPT element in an issue attachment or avatar that is an SVG document."},{"lang":"es","value":"GitLab anteriores a 8.14.9, 8.15.x anteriores a 8.15.6 y 8.16.x anteriores a 8.16.5 tienen XSS a través de un elemento SCRIPT en un archivo adjunto o un avatar que es un documento SVG."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionEndIncluding":"8.14.9","matchCriteriaId":"889A91B5-A5DF-4D15-80DD-8BC66A9AF272"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.15.0:*:*:*:*:*:*:*","matchCriteriaId":"50E67A7C-962E-49EE-8B4C-86D764770EDE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.15.1:*:*:*:*:*:*:*","matchCriteriaId":"8CE48CAF-F691-4409-96F9-CBB3903D251D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.15.2:*:*:*:*:*:*:*","matchCriteriaId":"C2B07763-013A-48EE-AFB7-3CBB3DFAD60C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.15.3:*:*:*:*:*:*:*","matchCriteriaId":"0BDE7E4A-12A3-46A6-AE35-075247CF1226"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.15.4:*:*:*:*:*:*:*","matchCriteriaId":"1F3C2EAC-68C0-4444-A366-238A54A96484"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.15.5:*:*:*:*:*:*:*","matchCriteriaId":"42C1AA52-622D-4867-AB95-C64DDC185454"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.16.0:*:*:*:*:*:*:*","matchCriteriaId":"A1965736-D73F-44DC-BA29-D992CCEA9657"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.16.1:*:*:*:*:*:*:*","matchCriteriaId":"3E274B52-360B-4F06-B307-89C6D044E444"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.16.2:*:*:*:*:*:*:*","matchCriteriaId":"02F132ED-1CC0-4A58-988F-B61D69FEB99E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.16.3:*:*:*:*:*:*:*","matchCriteriaId":"F9663040-C06C-4C11-9384-6DE1DE64A8C6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.16.4:*:*:*:*:*:*:*","matchCriteriaId":"D20B405B-38EB-4F10-AAE3-700EBB5F5E02"}]}]}],"references":[{"url":"https://about.gitlab.com/2017/02/15/gitlab-8-dot-16-dot-5-security-release/","source":"cve@mitre.org","tags":["Patch","Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/27471","source":"cve@mitre.org","tags":["Exploit","Vendor Advisory"]},{"url":"https://about.gitlab.com/2017/02/15/gitlab-8-dot-16-dot-5-security-release/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/27471","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2017-11437","sourceIdentifier":"cve@mitre.org","published":"2017-08-02T19:29:00.803","lastModified":"2026-06-17T01:01:48.643","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab Enterprise Edition (EE) before 8.17.7, 9.0.11, 9.1.8, 9.2.8, and 9.3.8 allows an authenticated user with the ability to create a project to use the mirroring feature to potentially read repositories belonging to other users."},{"lang":"es","value":"GitLab Enterprise Edition (EE) en sus versiones anteriores a la 8.17.7 y las versiones 9.0.11, 9.1.8, 9.2.8 y 9.3.8 permite que un usuario autenticado con la capacidad para crear un proyecto utilice la función de replicación para poder acceder a repositorios de otros usuarios."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-732"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.5.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"F9A689B7-5338-4CD9-817B-6BC7CFBF777B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.5.1:*:*:*:enterprise:*:*:*","matchCriteriaId":"2A545241-72A5-478D-95DE-D16D81D059D3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.5.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"6214BCAC-88CB-4584-9263-4C363E09DF99"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.5.3:*:*:*:enterprise:*:*:*","matchCriteriaId":"B111C038-809E-433A-AEFB-DB08485D433F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.5.4:*:*:*:enterprise:*:*:*","matchCriteriaId":"5703243F-1311-43AF-A4D3-EE481AE6AF89"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.5.5:*:*:*:enterprise:*:*:*","matchCriteriaId":"97D2593C-82F8-4FDA-90E9-5F99FA5E618C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.5.6:*:*:*:enterprise:*:*:*","matchCriteriaId":"9F154A97-727E-4328-8DD4-5ADB5DFF9BBD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.5.7:*:*:*:enterprise:*:*:*","matchCriteriaId":"7050F394-AA21-413C-B7AA-025C6867EA70"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.5.8:*:*:*:enterprise:*:*:*","matchCriteriaId":"60F33D8A-D19A-489A-B7EF-F3B9BB21128C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.5.9:*:*:*:enterprise:*:*:*","matchCriteriaId":"A242BEA6-967C-4AD6-B1B5-6ACF07D7A8F2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.5.10:*:*:*:enterprise:*:*:*","matchCriteriaId":"4EC5D7BC-D90E-4246-8875-D55E733A17D4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.5.11:*:*:*:enterprise:*:*:*","matchCriteriaId":"7835A619-4618-4871-B593-0F852D017FD7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.5.12:*:*:*:enterprise:*:*:*","matchCriteriaId":"2E83AF15-2F16-4C9C-8426-65B1521367FA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.5.13:*:*:*:enterprise:*:*:*","matchCriteriaId":"5FDF0654-A1D5-484C-81FB-C8190358D149"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.6.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"C6026502-F953-4DD6-9045-C261DCF1A8C8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.6.1:*:*:*:enterprise:*:*:*","matchCriteriaId":"16CF71BA-270C-44BA-9901-E340E52A9433"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.6.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"66C84616-682F-48B7-BF50-B1720620A220"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.6.3:*:*:*:enterprise:*:*:*","matchCriteriaId":"42B65A36-4287-4D67-862F-D3F64FA7EA25"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.6.4:*:*:*:enterprise:*:*:*","matchCriteriaId":"361FDAC0-9A78-485E-A761-80594B610E7D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.6.5:*:*:*:enterprise:*:*:*","matchCriteriaId":"E2AFB344-CFB4-43CB-83DF-56E7C152E824"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.6.6:*:*:*:enterprise:*:*:*","matchCriteriaId":"6E132515-1E9D-4ECC-9BEB-A7BD469C7C54"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.6.7:*:*:*:enterprise:*:*:*","matchCriteriaId":"4C90D1E1-F070-4334-9D24-5FDF0D94375D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.6.8:*:*:*:enterprise:*:*:*","matchCriteriaId":"41E3D5D9-7E0C-46CD-B0E9-BC047D5999F5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.6.9:*:*:*:enterprise:*:*:*","matchCriteriaId":"255E7E71-B6A0-4BC1-A0CC-3D96EC9EC5E0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.7.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"F6274FC1-B2DE-4DBE-8771-C1BEC9064707"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.7.1:*:*:*:enterprise:*:*:*","matchCriteriaId":"0F974D2B-B850-4551-A239-2282CB6F4726"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.7.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"7CAAD899-AEFB-47B5-A002-F62931DE2555"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.7.3:*:*:*:enterprise:*:*:*","matchCriteriaId":"ACE69267-26A8-4079-8611-5391D8591A06"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.7.4:*:*:*:enterprise:*:*:*","matchCriteriaId":"E81D3A01-5108-4135-86C3-511CF6BA2DC5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.7.5:*:*:*:enterprise:*:*:*","matchCriteriaId":"FC8A3B06-7F24-4A10-932D-B04C04D79AFA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.7.6:*:*:*:enterprise:*:*:*","matchCriteriaId":"98A064EA-02A1-438B-8F5E-600B65B3EE76"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.7.7:*:*:*:enterprise:*:*:*","matchCriteriaId":"A6E99B95-7887-409E-B661-19BDC4B397E9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.7.8:*:*:*:enterprise:*:*:*","matchCriteriaId":"686E5B3F-A633-42AF-822C-DEA1063373D9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.7.9:*:*:*:enterprise:*:*:*","matchCriteriaId":"47D46996-0BD0-4430-BA1F-681D6C3A063E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.8.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"91644919-EA2F-45F5-99A4-56C3E2CAFE77"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.8.1:*:*:*:enterprise:*:*:*","matchCriteriaId":"30B7F5DD-874F-4384-97FB-7BFF550FFF8A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.8.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"9D67A403-F067-406B-9750-6BFC060564F1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.8.3:*:*:*:enterprise:*:*:*","matchCriteriaId":"197423E1-4AC1-4D26-8699-5DF8F5EE3F24"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.8.4:*:*:*:enterprise:*:*:*","matchCriteriaId":"A93559F4-90A2-40EF-9D69-0D55D3C47CFE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.8.5:*:*:*:enterprise:*:*:*","matchCriteriaId":"BA2868FF-5ACD-44F9-9A57-7EF63C7E640E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.8.6:*:*:*:enterprise:*:*:*","matchCriteriaId":"AD687ECD-BF49-45D6-A35C-AC4E24FB9A99"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.8.7:*:*:*:enterprise:*:*:*","matchCriteriaId":"03DF09B5-D8D6-4467-98FA-DFF6D2B55033"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.8.8:*:*:*:enterprise:*:*:*","matchCriteriaId":"3E8092F0-9AE5-4CF3-B7E3-414F726F2F76"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.8.9:*:*:*:enterprise:*:*:*","matchCriteriaId":"B0B38D4A-6E17-4BE0-9A16-D8A181B4F530"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.9.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"714A27C4-DA0F-40F0-882E-E818EA943EC0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.9.1:*:*:*:enterprise:*:*:*","matchCriteriaId":"413D4C46-571E-4F4C-BA82-C5005F607E87"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.9.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"EBC8BEA5-B157-4058-A60E-55AA9B73B601"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.9.3:*:*:*:enterprise:*:*:*","matchCriteriaId":"419AE443-4512-40F7-82FF-C7EC56D67B3E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.9.4:*:*:*:enterprise:*:*:*","matchCriteriaId":"99743846-474B-436E-8EB1-1CB9F31CF4FB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.9.5:*:*:*:enterprise:*:*:*","matchCriteriaId":"3476E93B-274E-404F-9E34-0C10C21565E2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.9.6:*:*:*:enterprise:*:*:*","matchCriteriaId":"A8C88B77-533B-4552-99E1-DD25EC198AA6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.9.7:*:*:*:enterprise:*:*:*","matchCriteriaId":"A201ABFD-4A87-47A1-8320-9F982B84BEFF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.9.10:*:*:*:enterprise:*:*:*","matchCriteriaId":"F3502F66-C892-41FE-B26C-76E75721D6C0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.9.11:*:*:*:enterprise:*:*:*","matchCriteriaId":"B9AABA2E-550F-4C23-8CF2-3EF3F7379FED"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.10.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"331EE96A-1BE0-474D-86D1-1DB43C74277E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.10.1:*:*:*:enterprise:*:*:*","matchCriteriaId":"B15DB780-A850-41FE-AD9F-6C346B4989C7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.10.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"F4FC046D-7A57-4892-BF69-0E79424F512B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.10.3:*:*:*:enterprise:*:*:*","matchCriteriaId":"2A462CD5-92E9-4C32-B04D-E7B25317F27C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.10.4:*:*:*:enterprise:*:*:*","matchCriteriaId":"269B515B-277B-4807-9159-9DF65D3C0D5F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.10.5:*:*:*:enterprise:*:*:*","matchCriteriaId":"ADF1DAF8-2A35-4775-92F5-A1F8E57FE326"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.10.6:*:*:*:enterprise:*:*:*","matchCriteriaId":"F1CF3A4A-722D-4F0B-815D-DF7D779F45AF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.10.7:*:*:*:enterprise:*:*:*","matchCriteriaId":"38C019DC-04A4-446B-AF57-0D7DA6BBFD3A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.10.8:*:*:*:enterprise:*:*:*","matchCriteriaId":"D6B66E5D-E2BA-4C5B-BBB3-5D813EC70C8B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.10.9:*:*:*:enterprise:*:*:*","matchCriteriaId":"C79BCFD6-1A37-4148-9770-B2109BC553DB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.10.10:*:*:*:enterprise:*:*:*","matchCriteriaId":"71F68373-D0FD-4AD0-B382-A0D09EE36485"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.10.11:*:*:*:enterprise:*:*:*","matchCriteriaId":"49ACBD20-69FE-48F8-B972-95A10430DE2A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.10.12:*:*:*:enterprise:*:*:*","matchCriteriaId":"2B736A41-4879-49EF-88DE-2E8872E54731"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.10.13:*:*:*:enterprise:*:*:*","matchCriteriaId":"C38A9845-4307-463A-BE55-72263468A0F1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.11.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"AB6C28DB-00B5-4DAC-BB5E-5141FCCA7779"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.11.1:*:*:*:enterprise:*:*:*","matchCriteriaId":"09D275A5-FA0A-468A-A490-6D40C2016266"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.11.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"CB22081E-45A1-4599-B0FF-5CD0C4191832"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.11.3:*:*:*:enterprise:*:*:*","matchCriteriaId":"F06FC003-C7E7-4666-AD9A-ED90A42EF582"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.11.4:*:*:*:enterprise:*:*:*","matchCriteriaId":"F607CA2B-1D61-4C15-BA54-9B382CB1B5D7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.11.5:*:*:*:enterprise:*:*:*","matchCriteriaId":"F44BE0E2-97EB-4BE7-8A84-6EDE25649C49"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.11.6:*:*:*:enterprise:*:*:*","matchCriteriaId":"5B0E74E3-C58D-4D89-BFCA-722366B49255"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.11.7:*:*:*:enterprise:*:*:*","matchCriteriaId":"EA760556-96D0-4F69-BC72-6D72CF599AC8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.11.8:*:*:*:enterprise:*:*:*","matchCriteriaId":"D56AC6D5-A08C-4543-97F4-23D77F3DF1DF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.11.9:*:*:*:enterprise:*:*:*","matchCriteriaId":"C53175BE-0F48-4357-B950-75E4C92C1E40"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.11.10:*:*:*:enterprise:*:*:*","matchCriteriaId":"EA8C529E-A755-4DA7-B5FA-CECA7D77BFA1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.11.11:*:*:*:enterprise:*:*:*","matchCriteriaId":"13B92102-2233-43D9-B7D6-7B917ACBC513"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.12.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"48B34C3C-03AB-4459-ABCA-480C07B1B5DD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.12.1:*:*:*:enterprise:*:*:*","matchCriteriaId":"09BB2940-8CF8-4ADA-B734-99A8035BA7D4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.12.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"6ED2E761-8424-47ED-9ECC-9EEE0F06E693"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.12.3:*:*:*:enterprise:*:*:*","matchCriteriaId":"24B2DF94-D1BC-4F94-8AAF-DF4CDBDAE5D1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.12.4:*:*:*:enterprise:*:*:*","matchCriteriaId":"6569CE8E-0C8B-4A2D-91A0-A99354E72A9E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.12.5:*:*:*:enterprise:*:*:*","matchCriteriaId":"7D5853E3-1CA4-4731-A2C3-DE5350FBE685"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.12.6:*:*:*:enterprise:*:*:*","matchCriteriaId":"25B7D422-BEDA-427D-9BE7-04C851D1E20A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.12.7:*:*:*:enterprise:*:*:*","matchCriteriaId":"24D15B0E-D6DB-4A01-B996-026A3FAA2B30"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.12.8:*:*:*:enterprise:*:*:*","matchCriteriaId":"074F2E17-E065-4700-8A6C-60A0555D9CFE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.12.9:*:*:*:enterprise:*:*:*","matchCriteriaId":"4E18FD1C-DEC2-4C95-87BC-E5D4B7CCA2FC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.12.10:*:*:*:enterprise:*:*:*","matchCriteriaId":"8F3D07EF-1030-4B4E-AEAF-FDC6C9EC1152"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.12.11:*:*:*:enterprise:*:*:*","matchCriteriaId":"1053EFC9-1E3F-47D5-B0C1-D3752F89F5A0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.12.12:*:*:*:enterprise:*:*:*","matchCriteriaId":"D3FA1A2B-4EF8-40BF-BF3D-A381AFD3AED7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.13.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"BF27DE16-6B02-4B8C-8171-644F96B91EC5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.13.1:*:*:*:enterprise:*:*:*","matchCriteriaId":"309BE602-C30A-453B-B53E-87559A4A65C6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.13.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"0D1AEB22-B278-40B8-959B-59DF4CCE1756"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.13.3:*:*:*:enterprise:*:*:*","matchCriteriaId":"6E6C2412-07E9-494C-8374-D23244896593"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.13.4:*:*:*:enterprise:*:*:*","matchCriteriaId":"8754F4EA-AA92-4308-BCE1-F6214A502368"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.13.5:*:*:*:enterprise:*:*:*","matchCriteriaId":"46015599-12C0-4DFA-BBF9-2252446C899A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.13.6:*:*:*:enterprise:*:*:*","matchCriteriaId":"38D6EBF6-43D0-4D5E-A21D-29D775593236"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.13.7:*:*:*:enterprise:*:*:*","matchCriteriaId":"E36DA897-3A68-454F-90B8-B83E6D28AC73"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.13.8:*:*:*:enterprise:*:*:*","matchCriteriaId":"9BBB030E-9065-46C5-B53D-1652BE5F8592"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.13.9:*:*:*:enterprise:*:*:*","matchCriteriaId":"95A34884-89DE-4BB1-9E83-34FA67111E6B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.13.10:*:*:*:enterprise:*:*:*","matchCriteriaId":"CDD3228C-F3BE-4C85-90FE-4D29F40CABCA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.13.11:*:*:*:enterprise:*:*:*","matchCriteriaId":"E390DA6B-EC51-4534-A375-F8E30B365409"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.14.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"234CD36B-CEAC-4C89-A515-22D088589024"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.14.1:*:*:*:enterprise:*:*:*","matchCriteriaId":"A044ACCF-7534-4A81-9F66-7235CA4B74C9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.14.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"6265E089-155E-474C-B020-85C75EE500E0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.14.3:*:*:*:enterprise:*:*:*","matchCriteriaId":"62B5B510-E6BE-414A-BAE3-91DBDF571682"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.14.4:*:*:*:enterprise:*:*:*","matchCriteriaId":"EAA4671D-EF34-4325-A992-7C81D5BAADD2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.14.5:*:*:*:enterprise:*:*:*","matchCriteriaId":"C0CE42B2-B475-4D8C-B8AE-BC32BAF6234E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.14.6:*:*:*:enterprise:*:*:*","matchCriteriaId":"C93D5B03-B1D0-4F94-BDF5-4AE508A0BF8B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.14.8:*:*:*:enterprise:*:*:*","matchCriteriaId":"9627D6F1-4EE6-41A5-9C36-295A3E838D94"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.14.9:*:*:*:enterprise:*:*:*","matchCriteriaId":"1B594D99-2948-4A7A-9D0B-F4F62746E6E6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.14.10:*:*:*:enterprise:*:*:*","matchCriteriaId":"507368E5-8FEB-4981-A228-047F081288FC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.15.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"4FE20CBB-70B6-45B9-A477-1E4B50DAB672"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.15.1:*:*:*:enterprise:*:*:*","matchCriteriaId":"A1C4F42E-C2A5-445B-9B82-08CD28A624C8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.15.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"FB98703B-DC7E-4BFA-B11C-23A813FF8F4F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.15.3:*:*:*:enterprise:*:*:*","matchCriteriaId":"FE10D715-8C4B-4915-A063-0E68F12261F0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.15.4:*:*:*:enterprise:*:*:*","matchCriteriaId":"94AF72BC-2F35-4FBA-98AA-37DBC4450B05"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.15.6:*:*:*:enterprise:*:*:*","matchCriteriaId":"7D1FD095-2ECE-4708-A8A0-08713D664881"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.15.7:*:*:*:enterprise:*:*:*","matchCriteriaId":"D4102D04-E8F9-412C-A07A-FC70FD7CCBFE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.15.8:*:*:*:enterprise:*:*:*","matchCriteriaId":"A8C257F5-BA6B-4D97-A810-D8892A65347F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.16.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"FF573E1E-3635-45BD-BD3A-14833BE25037"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.16.1:*:*:*:enterprise:*:*:*","matchCriteriaId":"44E4EFCF-390A-443F-9D8B-9778474280B2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.16.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"19905721-3BA5-4C6C-A706-A814C6C03F5E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.16.3:*:*:*:enterprise:*:*:*","matchCriteriaId":"1C65DD44-8746-4E32-9A71-8E3358577331"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.16.4:*:*:*:enterprise:*:*:*","matchCriteriaId":"ED7EC2EB-4DFA-48BF-BA20-F405C6BED3B2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.16.5:*:*:*:enterprise:*:*:*","matchCriteriaId":"DA6E2911-A293-430D-B8FB-D531074802A6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.16.6:*:*:*:enterprise:*:*:*","matchCriteriaId":"5C6A6C84-71D0-42C1-A54E-01319FFFA9BD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.16.7:*:*:*:enterprise:*:*:*","matchCriteriaId":"9FC9C9FB-DD73-4482-A95C-F9BE5738466E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.16.8:*:*:*:enterprise:*:*:*","matchCriteriaId":"37AE396B-8674-4693-BA62-A4CC4D425EB3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.16.9:*:*:*:enterprise:*:*:*","matchCriteriaId":"437E47B2-BAC5-429A-A16E-730A08F3072B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.17.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"232319FB-619D-45FD-A091-ECE7937B38C6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.17.1:*:*:*:enterprise:*:*:*","matchCriteriaId":"EBC485DB-B02E-44E5-8FD9-BEBB859FFC32"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.17.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"31BC0B13-B59C-41B8-907A-9DFBEC54D3B8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.17.3:*:*:*:enterprise:*:*:*","matchCriteriaId":"BEB69ACB-D9A8-49EF-B9A2-30D3FAAB2684"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.17.4:*:*:*:enterprise:*:*:*","matchCriteriaId":"307769BA-3940-49A0-B428-381DB21048E8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.17.5:*:*:*:enterprise:*:*:*","matchCriteriaId":"B1A330EC-953E-4947-BF3F-59981437478B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:8.17.6:*:*:*:enterprise:*:*:*","matchCriteriaId":"4D9C5763-05A2-4334-AD8D-7F0355D1A712"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"2FD7115D-5389-41E0-A434-E309C589904E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.0.1:*:*:*:enterprise:*:*:*","matchCriteriaId":"56A91763-FD44-400E-A44B-CFF30BED8BD0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.0.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"39CF4E50-959C-4CCD-BA3B-C08801938FF5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.0.3:*:*:*:enterprise:*:*:*","matchCriteriaId":"D4167398-A7FF-4F0A-8BB3-2A61095EADD8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.0.4:*:*:*:enterprise:*:*:*","matchCriteriaId":"2FB25D27-2086-4B5D-98E4-6D5DE385CEE9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.0.5:*:*:*:enterprise:*:*:*","matchCriteriaId":"EB58A6B5-2444-4F0C-8D76-23286A148FD4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.0.6:*:*:*:enterprise:*:*:*","matchCriteriaId":"863D2334-4FC6-43C7-BC79-34FFB932C9B0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.0.7:*:*:*:enterprise:*:*:*","matchCriteriaId":"0542A00D-9B9F-4F31-A71D-C0036868A6BF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.0.8:*:*:*:enterprise:*:*:*","matchCriteriaId":"69DEB9B7-A622-4F02-87C0-D8C073FBC433"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.0.9:*:*:*:enterprise:*:*:*","matchCriteriaId":"1B383F93-5B84-4959-8BF9-5EF589FE3861"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.0.10:*:*:*:enterprise:*:*:*","matchCriteriaId":"CFCA88A2-52A6-46C0-8D04-6D66A25ECC98"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"F0E33B7B-74F6-4180-83DD-B3103FA69973"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.1.1:*:*:*:enterprise:*:*:*","matchCriteriaId":"5B456316-8D07-4FC4-8371-F1FAA6DA66CE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.1.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"A6BD46FF-C9D8-4420-BEF2-55E7865A7408"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.1.3:*:*:*:enterprise:*:*:*","matchCriteriaId":"F2894748-99BB-4105-BF7E-9EBF3A96C591"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.1.4:*:*:*:enterprise:*:*:*","matchCriteriaId":"48F0243B-5E32-4958-907F-28F687BCFEE6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.1.5:*:*:*:enterprise:*:*:*","matchCriteriaId":"B8A8A421-89D4-4D88-AC5E-A4675B57281D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.1.6:*:*:*:enterprise:*:*:*","matchCriteriaId":"9F674ABE-8BD6-45DD-9604-3789D7143ADC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.1.7:*:*:*:enterprise:*:*:*","matchCriteriaId":"7E8D058B-CA9A-4DB0-BA37-B4A8F82B80CC"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.2.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"77E257DF-7EF6-4F94-A901-70D14B230AA6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.2.1:*:*:*:enterprise:*:*:*","matchCriteriaId":"5150656E-DF20-4930-9D8F-F35371E25F5C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.2.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"ED08A352-986E-4B87-A2B3-FD42C99DEBE6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.2.3:*:*:*:enterprise:*:*:*","matchCriteriaId":"F78723C9-5DCC-49D8-A81C-2ABEFF93DCF1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.2.4:*:*:*:enterprise:*:*:*","matchCriteriaId":"FA0BE35C-0CE7-49C3-882B-9E8751CF780E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.2.5:*:*:*:enterprise:*:*:*","matchCriteriaId":"78F36A2D-0BAF-461B-9C45-28F5E5919FA2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.2.6:*:*:*:enterprise:*:*:*","matchCriteriaId":"A1ED26D9-9138-40E7-8040-7758A3C55DC5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.2.7:*:*:*:enterprise:*:*:*","matchCriteriaId":"D8BA8D86-FEB3-4EF6-AD02-AC7EB724A8B1"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.3.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"3978E438-C566-4D20-8A61-35BE3DD53216"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.3.1:*:*:*:enterprise:*:*:*","matchCriteriaId":"E1B7646D-8AA1-4C71-A200-1F4AF69C15F9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.3.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"8706044B-BC22-4808-8C91-F212A9597CA7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.3.3:*:*:*:enterprise:*:*:*","matchCriteriaId":"6813D127-BD01-47C3-B2C2-28C48D15E662"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.3.4:*:*:*:enterprise:*:*:*","matchCriteriaId":"F7E8D785-1D9F-4DCE-BDDB-3F43A3D1A121"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.3.5:*:*:*:enterprise:*:*:*","matchCriteriaId":"D039DB11-A182-43C7-9D1C-CADC03E4EEB0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.3.6:*:*:*:enterprise:*:*:*","matchCriteriaId":"706DC40E-D1A8-4124-A038-8F1AF94FDA32"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.3.7:*:*:*:enterprise:*:*:*","matchCriteriaId":"4CCEF509-13C2-4DD0-A578-FDA31EE9B152"}]}]}],"references":[{"url":"https://about.gitlab.com/2017/07/19/gitlab-9-dot-3-dot-8-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/2017/07/19/gitlab-9-dot-3-dot-8-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2017-11438","sourceIdentifier":"cve@mitre.org","published":"2017-08-02T19:29:00.837","lastModified":"2026-06-17T01:01:48.780","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab Community Edition (CE) and Enterprise Edition (EE) before 9.0.11, 9.1.8, 9.2.8 allow an authenticated user with the ability to create a group to add themselves to any project that is inside a subgroup."},{"lang":"es","value":"GitLab Community Edition (CE) y Enterprise Edition (EE) anteriores a la 9.0.11, 9.0.11, 9.1.8 y 9.2.8 permiten que un usuario autenticado con la capacidad para crear un grupo se añada a sí mismo en cualquier proyecto que se sitúe dentro de un subgrupo."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","baseScore":6.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":3.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-269"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.0.0:*:*:*:community:*:*:*","matchCriteriaId":"CA141AF7-A786-4484-89C6-641FE75304EE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"2FD7115D-5389-41E0-A434-E309C589904E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.0.1:*:*:*:community:*:*:*","matchCriteriaId":"7184277D-C727-4364-8926-BFADAAD65111"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.0.1:*:*:*:enterprise:*:*:*","matchCriteriaId":"56A91763-FD44-400E-A44B-CFF30BED8BD0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.0.2:*:*:*:community:*:*:*","matchCriteriaId":"6D737A3C-7FCE-40FF-8B4F-73ACCF72A95A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.0.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"39CF4E50-959C-4CCD-BA3B-C08801938FF5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.0.3:*:*:*:community:*:*:*","matchCriteriaId":"7FB672A5-0079-4174-9B05-87B7830ADE97"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.0.3:*:*:*:enterprise:*:*:*","matchCriteriaId":"D4167398-A7FF-4F0A-8BB3-2A61095EADD8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.0.4:*:*:*:community:*:*:*","matchCriteriaId":"5D760B70-6A23-4A86-862D-358DED91273F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.0.4:*:*:*:enterprise:*:*:*","matchCriteriaId":"2FB25D27-2086-4B5D-98E4-6D5DE385CEE9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.0.5:*:*:*:community:*:*:*","matchCriteriaId":"95CB5974-672E-45B5-8251-2E31AB4B56C1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.0.5:*:*:*:enterprise:*:*:*","matchCriteriaId":"EB58A6B5-2444-4F0C-8D76-23286A148FD4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.0.6:*:*:*:community:*:*:*","matchCriteriaId":"134815AB-D605-4148-9358-11B56347F94F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.0.6:*:*:*:enterprise:*:*:*","matchCriteriaId":"863D2334-4FC6-43C7-BC79-34FFB932C9B0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.0.7:*:*:*:community:*:*:*","matchCriteriaId":"C0AADEAB-5C55-4E5D-9291-8EB7A3C9749C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.0.7:*:*:*:enterprise:*:*:*","matchCriteriaId":"0542A00D-9B9F-4F31-A71D-C0036868A6BF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.0.8:*:*:*:community:*:*:*","matchCriteriaId":"11733956-6E02-4157-9FBC-3FA2EA0FD476"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.0.8:*:*:*:enterprise:*:*:*","matchCriteriaId":"69DEB9B7-A622-4F02-87C0-D8C073FBC433"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.0.9:*:*:*:community:*:*:*","matchCriteriaId":"E1CDD134-AE19-4B1C-8ADB-40E1B4AEE963"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.0.9:*:*:*:enterprise:*:*:*","matchCriteriaId":"1B383F93-5B84-4959-8BF9-5EF589FE3861"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.0.10:*:*:*:community:*:*:*","matchCriteriaId":"D7555266-A0C7-440F-88C1-CF3C2F6ECA8C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.0.10:*:*:*:enterprise:*:*:*","matchCriteriaId":"CFCA88A2-52A6-46C0-8D04-6D66A25ECC98"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.1.0:*:*:*:community:*:*:*","matchCriteriaId":"3BCC102E-DB51-4449-9518-B01B7894AAE6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"F0E33B7B-74F6-4180-83DD-B3103FA69973"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.1.1:*:*:*:community:*:*:*","matchCriteriaId":"7396F198-4E66-460C-AAC2-7B8DDD2F3D84"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.1.1:*:*:*:enterprise:*:*:*","matchCriteriaId":"5B456316-8D07-4FC4-8371-F1FAA6DA66CE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.1.2:*:*:*:community:*:*:*","matchCriteriaId":"90F5AE42-8D2F-434B-B6B1-57B9B6024D21"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.1.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"A6BD46FF-C9D8-4420-BEF2-55E7865A7408"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.1.3:*:*:*:community:*:*:*","matchCriteriaId":"E8084DEF-E62E-4C55-9E3F-9985966717DA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.1.3:*:*:*:enterprise:*:*:*","matchCriteriaId":"F2894748-99BB-4105-BF7E-9EBF3A96C591"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.1.4:*:*:*:community:*:*:*","matchCriteriaId":"D6074F33-B363-4070-B572-C669650425AB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.1.4:*:*:*:enterprise:*:*:*","matchCriteriaId":"48F0243B-5E32-4958-907F-28F687BCFEE6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.1.5:*:*:*:community:*:*:*","matchCriteriaId":"BF6F7B4C-E0EE-4B89-944D-25539CE7F54F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.1.5:*:*:*:enterprise:*:*:*","matchCriteriaId":"B8A8A421-89D4-4D88-AC5E-A4675B57281D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.1.6:*:*:*:community:*:*:*","matchCriteriaId":"4EADBBD3-DC56-4E06-ABED-000CB59FADF2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.1.6:*:*:*:enterprise:*:*:*","matchCriteriaId":"9F674ABE-8BD6-45DD-9604-3789D7143ADC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.1.7:*:*:*:community:*:*:*","matchCriteriaId":"6E987824-25AB-4BC2-BBAB-032EA3640BF9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.1.7:*:*:*:enterprise:*:*:*","matchCriteriaId":"7E8D058B-CA9A-4DB0-BA37-B4A8F82B80CC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.2.0:*:*:*:community:*:*:*","matchCriteriaId":"D80390B9-CDBF-413B-A4BD-DC070DE965FC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.2.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"77E257DF-7EF6-4F94-A901-70D14B230AA6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.2.1:*:*:*:community:*:*:*","matchCriteriaId":"2F9C1467-8D27-4AF8-B6E1-F8BBFB92C4F5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.2.1:*:*:*:enterprise:*:*:*","matchCriteriaId":"5150656E-DF20-4930-9D8F-F35371E25F5C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.2.2:*:*:*:community:*:*:*","matchCriteriaId":"341C87D3-A74B-41AF-BBA2-205997F8B0F6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.2.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"ED08A352-986E-4B87-A2B3-FD42C99DEBE6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.2.3:*:*:*:community:*:*:*","matchCriteriaId":"C84AF9BB-5A67-432F-AB71-310953407EFF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.2.3:*:*:*:enterprise:*:*:*","matchCriteriaId":"F78723C9-5DCC-49D8-A81C-2ABEFF93DCF1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.2.4:*:*:*:community:*:*:*","matchCriteriaId":"FD2D4D56-9218-4962-88C2-44A1728F1EED"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.2.4:*:*:*:enterprise:*:*:*","matchCriteriaId":"FA0BE35C-0CE7-49C3-882B-9E8751CF780E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.2.5:*:*:*:community:*:*:*","matchCriteriaId":"8289D1E1-8DE2-4795-B602-E357C4A3B7A8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.2.5:*:*:*:enterprise:*:*:*","matchCriteriaId":"78F36A2D-0BAF-461B-9C45-28F5E5919FA2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.2.6:*:*:*:community:*:*:*","matchCriteriaId":"0BBDC678-4A27-4236-A27E-25C88EFC2008"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.2.6:*:*:*:enterprise:*:*:*","matchCriteriaId":"A1ED26D9-9138-40E7-8040-7758A3C55DC5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.2.7:*:*:*:community:*:*:*","matchCriteriaId":"E2B2A42C-7860-46CF-AB24-05FDFF58D26B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.2.7:*:*:*:enterprise:*:*:*","matchCriteriaId":"D8BA8D86-FEB3-4EF6-AD02-AC7EB724A8B1"}]}]}],"references":[{"url":"https://about.gitlab.com/2017/07/19/gitlab-9-dot-3-dot-8-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/2017/07/19/gitlab-9-dot-3-dot-8-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2017-12426","sourceIdentifier":"cve@mitre.org","published":"2017-08-14T21:29:00.213","lastModified":"2026-06-17T01:03:17.030","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab Community Edition (CE) and Enterprise Edition (EE) before 8.17.8, 9.0.x before 9.0.13, 9.1.x before 9.1.10, 9.2.x before 9.2.10, 9.3.x before 9.3.10, and 9.4.x before 9.4.4 might allow remote attackers to execute arbitrary code via a crafted SSH URL in a project import."},{"lang":"es","value":"GitLab Community Edition (CE) y Enterprise Edition (EE) en versiones anteriores a la 8.17.8, 9.0.x en versiones anteriores a la 9.0.13, 9.1.x en versiones anteriores a la 9.1.10, 9.2.x en versiones anteriores a la 9.2.10, 9.3.x en versiones anteriores a la 9.3.10, y 9.4.x en versiones anteriores a la 9.4.4 podría permitir que atacantes remotos ejecuten código arbitrario mediante una URL SSH manipulada en una importación de proyecto."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-20"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndIncluding":"8.17.7","matchCriteriaId":"3437C074-9275-4375-80C6-D803FA8424A4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndIncluding":"8.17.7","matchCriteriaId":"C7E6CB12-5A39-4A37-81EB-4DE53B8AFC3D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.0.0:*:*:*:community:*:*:*","matchCriteriaId":"CA141AF7-A786-4484-89C6-641FE75304EE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"2FD7115D-5389-41E0-A434-E309C589904E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.0.1:*:*:*:community:*:*:*","matchCriteriaId":"7184277D-C727-4364-8926-BFADAAD65111"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.0.1:*:*:*:enterprise:*:*:*","matchCriteriaId":"56A91763-FD44-400E-A44B-CFF30BED8BD0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.0.2:*:*:*:community:*:*:*","matchCriteriaId":"6D737A3C-7FCE-40FF-8B4F-73ACCF72A95A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.0.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"39CF4E50-959C-4CCD-BA3B-C08801938FF5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.0.3:*:*:*:community:*:*:*","matchCriteriaId":"7FB672A5-0079-4174-9B05-87B7830ADE97"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.0.3:*:*:*:enterprise:*:*:*","matchCriteriaId":"D4167398-A7FF-4F0A-8BB3-2A61095EADD8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.0.4:*:*:*:community:*:*:*","matchCriteriaId":"5D760B70-6A23-4A86-862D-358DED91273F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.0.4:*:*:*:enterprise:*:*:*","matchCriteriaId":"2FB25D27-2086-4B5D-98E4-6D5DE385CEE9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.0.5:*:*:*:community:*:*:*","matchCriteriaId":"95CB5974-672E-45B5-8251-2E31AB4B56C1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.0.5:*:*:*:enterprise:*:*:*","matchCriteriaId":"EB58A6B5-2444-4F0C-8D76-23286A148FD4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.0.6:*:*:*:community:*:*:*","matchCriteriaId":"134815AB-D605-4148-9358-11B56347F94F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.0.6:*:*:*:enterprise:*:*:*","matchCriteriaId":"863D2334-4FC6-43C7-BC79-34FFB932C9B0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.0.7:*:*:*:community:*:*:*","matchCriteriaId":"C0AADEAB-5C55-4E5D-9291-8EB7A3C9749C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.0.7:*:*:*:enterprise:*:*:*","matchCriteriaId":"0542A00D-9B9F-4F31-A71D-C0036868A6BF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.0.8:*:*:*:community:*:*:*","matchCriteriaId":"11733956-6E02-4157-9FBC-3FA2EA0FD476"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.0.8:*:*:*:enterprise:*:*:*","matchCriteriaId":"69DEB9B7-A622-4F02-87C0-D8C073FBC433"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.0.9:*:*:*:community:*:*:*","matchCriteriaId":"E1CDD134-AE19-4B1C-8ADB-40E1B4AEE963"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.0.9:*:*:*:enterprise:*:*:*","matchCriteriaId":"1B383F93-5B84-4959-8BF9-5EF589FE3861"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.0.10:*:*:*:community:*:*:*","matchCriteriaId":"D7555266-A0C7-440F-88C1-CF3C2F6ECA8C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.0.10:*:*:*:enterprise:*:*:*","matchCriteriaId":"CFCA88A2-52A6-46C0-8D04-6D66A25ECC98"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.0.11:*:*:*:community:*:*:*","matchCriteriaId":"D2F43A32-769D-4C8E-A1B3-86512D2C05FE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.0.11:*:*:*:enterprise:*:*:*","matchCriteriaId":"2F96255F-95ED-4F8B-A891-EDC80F75EFB1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.0.12:*:*:*:community:*:*:*","matchCriteriaId":"8E16D6A5-6F0A-4A60-A082-0765ADB8B0BC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.0.12:*:*:*:enterprise:*:*:*","matchCriteriaId":"E9084EEF-9FE1-4885-BA7E-2ACD497B4E95"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.1.0:*:*:*:community:*:*:*","matchCriteriaId":"3BCC102E-DB51-4449-9518-B01B7894AAE6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"F0E33B7B-74F6-4180-83DD-B3103FA69973"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.1.1:*:*:*:community:*:*:*","matchCriteriaId":"7396F198-4E66-460C-AAC2-7B8DDD2F3D84"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.1.1:*:*:*:enterprise:*:*:*","matchCriteriaId":"5B456316-8D07-4FC4-8371-F1FAA6DA66CE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.1.2:*:*:*:community:*:*:*","matchCriteriaId":"90F5AE42-8D2F-434B-B6B1-57B9B6024D21"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.1.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"A6BD46FF-C9D8-4420-BEF2-55E7865A7408"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.1.3:*:*:*:community:*:*:*","matchCriteriaId":"E8084DEF-E62E-4C55-9E3F-9985966717DA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.1.3:*:*:*:enterprise:*:*:*","matchCriteriaId":"F2894748-99BB-4105-BF7E-9EBF3A96C591"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.1.4:*:*:*:community:*:*:*","matchCriteriaId":"D6074F33-B363-4070-B572-C669650425AB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.1.4:*:*:*:enterprise:*:*:*","matchCriteriaId":"48F0243B-5E32-4958-907F-28F687BCFEE6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.1.5:*:*:*:community:*:*:*","matchCriteriaId":"BF6F7B4C-E0EE-4B89-944D-25539CE7F54F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.1.5:*:*:*:enterprise:*:*:*","matchCriteriaId":"B8A8A421-89D4-4D88-AC5E-A4675B57281D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.1.6:*:*:*:community:*:*:*","matchCriteriaId":"4EADBBD3-DC56-4E06-ABED-000CB59FADF2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.1.6:*:*:*:enterprise:*:*:*","matchCriteriaId":"9F674ABE-8BD6-45DD-9604-3789D7143ADC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.1.7:*:*:*:community:*:*:*","matchCriteriaId":"6E987824-25AB-4BC2-BBAB-032EA3640BF9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.1.7:*:*:*:enterprise:*:*:*","matchCriteriaId":"7E8D058B-CA9A-4DB0-BA37-B4A8F82B80CC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.1.8:*:*:*:community:*:*:*","matchCriteriaId":"106A7C2B-64C7-49EB-8440-0C8F85B1B834"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.1.8:*:*:*:enterprise:*:*:*","matchCriteriaId":"C8965CE9-87FE-4FA2-B753-E4EF270D733A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.1.9:*:*:*:community:*:*:*","matchCriteriaId":"F1519903-67B1-498B-B805-BDFDC467EB3A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.1.9:*:*:*:enterprise:*:*:*","matchCriteriaId":"A4474444-B743-4E02-9D5B-3F6B1E450CED"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.2.0:*:*:*:community:*:*:*","matchCriteriaId":"D80390B9-CDBF-413B-A4BD-DC070DE965FC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.2.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"77E257DF-7EF6-4F94-A901-70D14B230AA6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.2.1:*:*:*:community:*:*:*","matchCriteriaId":"2F9C1467-8D27-4AF8-B6E1-F8BBFB92C4F5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.2.1:*:*:*:enterprise:*:*:*","matchCriteriaId":"5150656E-DF20-4930-9D8F-F35371E25F5C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.2.2:*:*:*:community:*:*:*","matchCriteriaId":"341C87D3-A74B-41AF-BBA2-205997F8B0F6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.2.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"ED08A352-986E-4B87-A2B3-FD42C99DEBE6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.2.3:*:*:*:community:*:*:*","matchCriteriaId":"C84AF9BB-5A67-432F-AB71-310953407EFF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.2.3:*:*:*:enterprise:*:*:*","matchCriteriaId":"F78723C9-5DCC-49D8-A81C-2ABEFF93DCF1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.2.4:*:*:*:community:*:*:*","matchCriteriaId":"FD2D4D56-9218-4962-88C2-44A1728F1EED"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.2.4:*:*:*:enterprise:*:*:*","matchCriteriaId":"FA0BE35C-0CE7-49C3-882B-9E8751CF780E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.2.5:*:*:*:community:*:*:*","matchCriteriaId":"8289D1E1-8DE2-4795-B602-E357C4A3B7A8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.2.5:*:*:*:enterprise:*:*:*","matchCriteriaId":"78F36A2D-0BAF-461B-9C45-28F5E5919FA2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.2.6:*:*:*:community:*:*:*","matchCriteriaId":"0BBDC678-4A27-4236-A27E-25C88EFC2008"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.2.6:*:*:*:enterprise:*:*:*","matchCriteriaId":"A1ED26D9-9138-40E7-8040-7758A3C55DC5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.2.7:*:*:*:community:*:*:*","matchCriteriaId":"E2B2A42C-7860-46CF-AB24-05FDFF58D26B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.2.7:*:*:*:enterprise:*:*:*","matchCriteriaId":"D8BA8D86-FEB3-4EF6-AD02-AC7EB724A8B1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.2.8:*:*:*:community:*:*:*","matchCriteriaId":"1D55194E-7027-4F64-BFCA-7380FC0B9F4E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.2.8:*:*:*:enterprise:*:*:*","matchCriteriaId":"BC83D69E-AB3C-4538-A240-9CFD71C17180"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.2.9:*:*:*:community:*:*:*","matchCriteriaId":"00E69F6C-69B8-4789-BFC2-669D86F6E129"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.2.9:*:*:*:enterprise:*:*:*","matchCriteriaId":"1C9D27C6-718F-464E-A304-2B555D4D8BBA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.3.0:*:*:*:community:*:*:*","matchCriteriaId":"87C5D7F8-F57E-408A-B069-7197B8A721CD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.3.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"3978E438-C566-4D20-8A61-35BE3DD53216"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.3.1:*:*:*:community:*:*:*","matchCriteriaId":"472EDFE6-2AF5-452C-AF40-CACCDD0C00EB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.3.1:*:*:*:enterprise:*:*:*","matchCriteriaId":"E1B7646D-8AA1-4C71-A200-1F4AF69C15F9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.3.2:*:*:*:community:*:*:*","matchCriteriaId":"00594FEE-AF50-4725-84E0-217051C02F8D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.3.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"8706044B-BC22-4808-8C91-F212A9597CA7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.3.3:*:*:*:community:*:*:*","matchCriteriaId":"470AF5CB-8F15-4D7C-B1FB-73335CA9F52C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.3.3:*:*:*:enterprise:*:*:*","matchCriteriaId":"6813D127-BD01-47C3-B2C2-28C48D15E662"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.3.4:*:*:*:community:*:*:*","matchCriteriaId":"1C750B16-1605-43B0-894D-055600E635B3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.3.4:*:*:*:enterprise:*:*:*","matchCriteriaId":"F7E8D785-1D9F-4DCE-BDDB-3F43A3D1A121"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.3.5:*:*:*:community:*:*:*","matchCriteriaId":"CA5576C8-FCB7-440F-92E1-34809E91AA00"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.3.5:*:*:*:enterprise:*:*:*","matchCriteriaId":"D039DB11-A182-43C7-9D1C-CADC03E4EEB0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.3.6:*:*:*:community:*:*:*","matchCriteriaId":"C87EF839-2B6F-4C6F-A6CE-5B8F03B30209"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.3.6:*:*:*:enterprise:*:*:*","matchCriteriaId":"706DC40E-D1A8-4124-A038-8F1AF94FDA32"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.3.7:*:*:*:community:*:*:*","matchCriteriaId":"388525B6-2021-4EC7-A030-A8B1836B81ED"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.3.7:*:*:*:enterprise:*:*:*","matchCriteriaId":"4CCEF509-13C2-4DD0-A578-FDA31EE9B152"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.3.8:*:*:*:community:*:*:*","matchCriteriaId":"DFB211D1-224F-49E0-9FAA-8C254805C000"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.3.8:*:*:*:enterprise:*:*:*","matchCriteriaId":"3785EDB4-0F39-4A5B-86B2-84D176621284"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.3.9:*:*:*:community:*:*:*","matchCriteriaId":"48DB2E8F-7C64-48D8-B28D-BC1F6987C2E4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.3.9:*:*:*:enterprise:*:*:*","matchCriteriaId":"B577A91B-7BFE-4BDC-A3F0-C9F0BE383B23"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.4.0:*:*:*:community:*:*:*","matchCriteriaId":"559AB080-B1A7-429C-9EC0-8AB2D0833CFD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.4.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"8A7B88CC-DD9F-47F8-9528-ADC067F425E7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.4.1:*:*:*:community:*:*:*","matchCriteriaId":"872C5FE5-BE2F-49E3-B26A-376645CA8893"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.4.1:*:*:*:enterprise:*:*:*","matchCriteriaId":"931EC96C-12A2-4CBC-86D3-C75223373A82"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.4.2:*:*:*:community:*:*:*","matchCriteriaId":"066065C9-485C-4C29-A5C1-7E0948F7396B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.4.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"648F9926-6F22-4663-90DB-92D299443FC8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.4.3:*:*:*:community:*:*:*","matchCriteriaId":"FEA56D27-8AB6-464E-A211-C4E801EB3874"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.4.3:*:*:*:enterprise:*:*:*","matchCriteriaId":"9AF64005-6780-4628-80EF-6F45CD69A0DC"}]}]}],"references":[{"url":"https://about.gitlab.com/2017/08/10/gitlab-9-dot-4-dot-4-released/","source":"cve@mitre.org","tags":["Mitigation","Release Notes","Vendor Advisory"]},{"url":"https://www.mail-archive.com/linux-kernel%40vger.kernel.org/msg1466490.html","source":"cve@mitre.org"},{"url":"https://about.gitlab.com/2017/08/10/gitlab-9-dot-4-dot-4-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mitigation","Release Notes","Vendor Advisory"]},{"url":"https://www.mail-archive.com/linux-kernel%40vger.kernel.org/msg1466490.html","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2017-17716","sourceIdentifier":"cve@mitre.org","published":"2017-12-17T17:29:00.227","lastModified":"2026-06-17T01:11:32.020","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab 9.4.x before 9.4.2 does not support LDAP SSL certificate verification, but a verify_certificates LDAP option was mentioned in the 9.4 release announcement. This issue occurred because code was not merged. This is related to use of the omniauth-ldap library and the gitlab_omniauth-ldap gem."},{"lang":"es","value":"GitLab en versiones 9.4.x anteriores a la 9.4.2 no es compatible con la verificación de certificados SSL LDAP, pero se mencionó la opción LDAP verify_certificates en el anuncio del lanzamiento de la versión 9.4. Este problema ocurrió porque el código no se combinó. Esto está relacionado con el uso de la biblioteca omniauth-ldap y la gema gitlab_omniauth-ldap."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-295"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.4.0:*:*:*:*:*:*:*","matchCriteriaId":"3AF21323-20AC-42E8-BD90-4D4930E2AB20"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.4.0:rc1:*:*:*:*:*:*","matchCriteriaId":"ECB4CA9C-115A-4D84-A416-B7FBF660DD26"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.4.0:rc2:*:*:*:*:*:*","matchCriteriaId":"65FCBAEE-15CD-4701-972B-DD00CAEF6436"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.4.0:rc3:*:*:*:*:*:*","matchCriteriaId":"00436DEC-8B1B-428C-A516-4B7734C85117"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.4.0:rc4:*:*:*:*:*:*","matchCriteriaId":"CB7EA1F7-E01F-4140-9616-44164C248BCC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.4.0:rc5:*:*:*:*:*:*","matchCriteriaId":"D9CC3C7C-300A-43BC-8B1F-C466E186AE11"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.4.0:rc6:*:*:*:*:*:*","matchCriteriaId":"392BCD31-E28B-49E5-8B36-39986106F9CC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.4.1:*:*:*:*:*:*:*","matchCriteriaId":"DCACA5A4-C284-4B93-AB74-A6E28C6C95C4"}]}]}],"references":[{"url":"https://about.gitlab.com/2017/07/22/gitlab-9-4-released/#security---add-ldap-ssl-certificate-verification","source":"cve@mitre.org","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://about.gitlab.com/2017/07/28/gitlab-9-dot-4-dot-2-released/","source":"cve@mitre.org","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/30420","source":"cve@mitre.org","tags":["Issue Tracking","Patch","Vendor Advisory"]},{"url":"https://about.gitlab.com/2017/07/22/gitlab-9-4-released/#security---add-ldap-ssl-certificate-verification","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://about.gitlab.com/2017/07/28/gitlab-9-dot-4-dot-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/30420","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Patch","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2014-8540","sourceIdentifier":"cve@mitre.org","published":"2018-01-05T16:29:00.323","lastModified":"2026-06-17T00:16:54.070","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"The groups API in GitLab 6.x and 7.x before 7.4.3 allows remote authenticated guest users to modify ownership of arbitrary groups by leveraging improper permission checks."},{"lang":"es","value":"La API de grupos en GitLab 6.x y 7.x anteriores a la 7.4.3 permite que los usuarios guest autenticados remotos modifiquen la propiedad de grupos arbitrarios aprovechándose de las comprobaciones incorrectas de permisos."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-264"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0.0","versionEndIncluding":"6.9.2","matchCriteriaId":"7686C898-E819-4E78-BD25-5B90C734812B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"7.0.0","versionEndExcluding":"7.4.3","matchCriteriaId":"D159E2C4-A5C4-472C-B0B4-FF6EC026155B"}]}]}],"references":[{"url":"http://www.openwall.com/lists/oss-security/2014/10/31/2","source":"cve@mitre.org","tags":["Mailing List","Third Party Advisory"]},{"url":"http://www.securityfocus.com/bid/70841","source":"cve@mitre.org","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://about.gitlab.com/2014/10/30/gitlab-7-4-3-released/","source":"cve@mitre.org","tags":["Patch","Vendor Advisory"]},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/98449","source":"cve@mitre.org","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/commit/a2dfff418bf2532ebb5aee88414107929b17eefd","source":"cve@mitre.org","tags":["Patch"]},{"url":"http://www.openwall.com/lists/oss-security/2014/10/31/2","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"]},{"url":"http://www.securityfocus.com/bid/70841","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://about.gitlab.com/2014/10/30/gitlab-7-4-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"]},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/98449","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/commit/a2dfff418bf2532ebb5aee88414107929b17eefd","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"]}]}},{"cve":{"id":"CVE-2017-0914","sourceIdentifier":"support@hackerone.com","published":"2018-03-21T20:29:00.230","lastModified":"2026-06-17T00:58:31.127","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Gitlab Community and Enterprise Editions version 10.1, 10.2, and 10.2.4 are vulnerable to a SQL injection in the MilestoneFinder component resulting in disclosure of all data in a GitLab instance's database."},{"lang":"es","value":"Las ediciones Community y Enterprise de Gitlab, en sus versiones 10.1, 10.2 y 10.2.4, son vulnerables a una inyección SQL en el componente MilestoneFinder que resulta en la divulgación de todos los datos en la base de datos de una instancia de Gitlab."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"GitLab","product":"GitLab Community and Enterprise Editions","versions":[{"version":"9.1.0 - 10.1.5 Fixed in 10.1.6","status":"affected"},{"version":"10.2.0 - 10.2.5 Fixed in 10.2.6","status":"affected"},{"version":"10.3.0 - 10.3.3 Fixed in 10.3.4","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"support@hackerone.com","type":"Secondary","description":[{"lang":"en","value":"CWE-89"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-89"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"9.4.0","versionEndIncluding":"9.5.10","matchCriteriaId":"6E361A47-7091-4BA7-A0E0-9B549C440676"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"9.4.0","versionEndIncluding":"9.5.10","matchCriteriaId":"B3AF96C8-23DF-4055-A827-4FEC6B58B0FE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.0.0","versionEndIncluding":"10.1.5","matchCriteriaId":"81E7F704-BE11-4C38-A69B-27D22298703D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.0.0","versionEndIncluding":"10.1.5","matchCriteriaId":"64162AE5-7888-44B6-9E40-F8003806408C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.2.0","versionEndIncluding":"10.2.5","matchCriteriaId":"643E78E8-2909-41D4-BC2A-2CADDA141DCB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.2.0","versionEndIncluding":"10.2.5","matchCriteriaId":"AA884C1E-9F66-41DA-9F23-1231086A75CA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.3.0","versionEndIncluding":"10.3.3","matchCriteriaId":"7E7D952B-AB31-4962-B178-53260246B33E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.3.0","versionEndIncluding":"10.3.3","matchCriteriaId":"3CEEA359-A827-43C5-8489-FD49AE744CC4"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released/","source":"support@hackerone.com","tags":["Vendor Advisory"]},{"url":"https://hackerone.com/reports/298176","source":"support@hackerone.com","tags":["Permissions Required"]},{"url":"https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://hackerone.com/reports/298176","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2017-0915","sourceIdentifier":"support@hackerone.com","published":"2018-03-21T20:29:00.293","lastModified":"2026-06-17T00:58:31.233","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Gitlab Community Edition version 10.2.4 is vulnerable to a lack of input validation in the GitlabProjectsImportService resulting in remote code execution."},{"lang":"es","value":"Gitlab Community Edition 10.2.4 es vulnerable a una falta de validación de entradas en GitlabProjectsImportService que resulta en la ejecución remota de código."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"GitLab","product":"GitLab Community and Enterprise Editions","versions":[{"version":"8.9 - 10.1.5 Fixed in 10.1.6","status":"affected"},{"version":"10.2.0 - 10.2.5 Fixed in 10.2.6","status":"affected"},{"version":"10.3.0 - 10.3.3 Fixed in 10.3.4","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"support@hackerone.com","type":"Secondary","description":[{"lang":"en","value":"CWE-77"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-20"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.9.0","versionEndIncluding":"9.5.10","matchCriteriaId":"492C2FA2-F309-417A-A04E-D218264806AF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.9.0","versionEndIncluding":"9.5.10","matchCriteriaId":"EE2C46FA-7B81-452E-A413-4AB4983753FD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.0.0","versionEndIncluding":"10.1.5","matchCriteriaId":"81E7F704-BE11-4C38-A69B-27D22298703D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.0.0","versionEndIncluding":"10.1.5","matchCriteriaId":"64162AE5-7888-44B6-9E40-F8003806408C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.2.0","versionEndIncluding":"10.2.5","matchCriteriaId":"643E78E8-2909-41D4-BC2A-2CADDA141DCB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.2.0","versionEndIncluding":"10.2.5","matchCriteriaId":"AA884C1E-9F66-41DA-9F23-1231086A75CA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.3.0","versionEndIncluding":"10.3.3","matchCriteriaId":"7E7D952B-AB31-4962-B178-53260246B33E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.3.0","versionEndIncluding":"10.3.3","matchCriteriaId":"3CEEA359-A827-43C5-8489-FD49AE744CC4"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*","matchCriteriaId":"DEECE5FC-CACF-4496-A3E7-164736409252"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released/","source":"support@hackerone.com","tags":["Vendor Advisory"]},{"url":"https://hackerone.com/reports/298873","source":"support@hackerone.com","tags":["Permissions Required"]},{"url":"https://www.debian.org/security/2018/dsa-4145","source":"support@hackerone.com","tags":["Third Party Advisory"]},{"url":"https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://hackerone.com/reports/298873","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]},{"url":"https://www.debian.org/security/2018/dsa-4145","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2017-0916","sourceIdentifier":"support@hackerone.com","published":"2018-03-21T20:29:00.357","lastModified":"2026-06-17T00:58:31.337","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Gitlab Community Edition version 10.3 is vulnerable to a lack of input validation in the system_hook_push queue through web hook component resulting in remote code execution."},{"lang":"es","value":"Gitlab Community Edition 10.3 es vulnerable a una falta de validación de entradas en la cola system_hook_push mediante el componente de enlace web que resulta en la ejecución remota de código."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"GitLab","product":"GitLab Community and Enterprise Editions","versions":[{"version":"9.1.0 - 10.1.5 Fixed in 10.1.6","status":"affected"},{"version":"10.2.0 - 10.2.5 Fixed in 10.2.6","status":"affected"},{"version":"10.3.0 - 10.3.3 Fixed in 10.3.4","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"support@hackerone.com","type":"Secondary","description":[{"lang":"en","value":"CWE-77"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-20"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.8.0","versionEndIncluding":"10.1.5","matchCriteriaId":"B7170487-5E65-4281-A5B4-6CCFE975B670"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.8.0","versionEndIncluding":"10.1.5","matchCriteriaId":"19E0A120-3CE9-43FE-AEB6-A93F70BDD776"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.2.0","versionEndIncluding":"10.2.5","matchCriteriaId":"643E78E8-2909-41D4-BC2A-2CADDA141DCB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.2.0","versionEndIncluding":"10.2.5","matchCriteriaId":"AA884C1E-9F66-41DA-9F23-1231086A75CA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.3.0","versionEndIncluding":"10.3.3","matchCriteriaId":"7E7D952B-AB31-4962-B178-53260246B33E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.3.0","versionEndIncluding":"10.3.3","matchCriteriaId":"3CEEA359-A827-43C5-8489-FD49AE744CC4"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*","matchCriteriaId":"DEECE5FC-CACF-4496-A3E7-164736409252"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released/","source":"support@hackerone.com","tags":["Vendor Advisory"]},{"url":"https://hackerone.com/reports/299473","source":"support@hackerone.com","tags":["Permissions Required"]},{"url":"https://www.debian.org/security/2018/dsa-4145","source":"support@hackerone.com","tags":["Third Party Advisory"]},{"url":"https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://hackerone.com/reports/299473","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]},{"url":"https://www.debian.org/security/2018/dsa-4145","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2017-0917","sourceIdentifier":"support@hackerone.com","published":"2018-03-21T20:29:00.417","lastModified":"2026-06-17T00:58:31.443","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Gitlab Community Edition version 10.2.4 is vulnerable to lack of input validation in the CI job component resulting in persistent cross site scripting."},{"lang":"es","value":"Gitlab Community Edition 10.2.4 es vulnerable a una falta de validación de entradas en el componente de trabajo CI que resulta en Cross-Site Scripting (XSS) persistente."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"GitLab","product":"GitLab Community and Enterprise Editions","versions":[{"version":"9.1.0 - 10.1.5 Fixed in 10.1.6","status":"affected"},{"version":"10.2.0 - 10.2.5 Fixed in 10.2.6","status":"affected"},{"version":"10.3.0 - 10.3.3 Fixed in 10.3.4","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"support@hackerone.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-20"},{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.1.0","versionEndIncluding":"10.1.5","matchCriteriaId":"5E1314D0-32F8-4DE6-BC90-0D37B1D132B1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.1.0","versionEndIncluding":"10.1.5","matchCriteriaId":"4EC6E637-7340-438F-BBFD-996A60D7D6DA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.2.0","versionEndIncluding":"10.2.5","matchCriteriaId":"643E78E8-2909-41D4-BC2A-2CADDA141DCB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.2.0","versionEndIncluding":"10.2.5","matchCriteriaId":"AA884C1E-9F66-41DA-9F23-1231086A75CA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.3.0","versionEndIncluding":"10.3.3","matchCriteriaId":"7E7D952B-AB31-4962-B178-53260246B33E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.3.0","versionEndIncluding":"10.3.3","matchCriteriaId":"3CEEA359-A827-43C5-8489-FD49AE744CC4"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*","matchCriteriaId":"DEECE5FC-CACF-4496-A3E7-164736409252"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released/","source":"support@hackerone.com","tags":["Vendor Advisory"]},{"url":"https://hackerone.com/reports/299525","source":"support@hackerone.com","tags":["Permissions Required"]},{"url":"https://www.debian.org/security/2018/dsa-4145","source":"support@hackerone.com","tags":["Third Party Advisory"]},{"url":"https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://hackerone.com/reports/299525","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]},{"url":"https://www.debian.org/security/2018/dsa-4145","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2017-0918","sourceIdentifier":"support@hackerone.com","published":"2018-03-21T20:29:00.467","lastModified":"2026-06-17T00:58:31.550","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Gitlab Community Edition version 10.3 is vulnerable to a path traversal issue in the GitLab CI runner component resulting in remote code execution."},{"lang":"es","value":"Gitlab Community Edition 10.3 es vulnerable a un problema de salto de directorio en el componente GitLab CI runner que resulta en la ejecución remota de código."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"GitLab","product":"GitLab Community and Enterprise Editions","versions":[{"version":"8.4.0 - 10.1.5 Fixed in 10.1.6","status":"affected"},{"version":"10.2.0 - 10.2.5 Fixed in 10.2.6","status":"affected"},{"version":"10.3.0 - 10.3.3 Fixed in 10.3.4","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"support@hackerone.com","type":"Secondary","description":[{"lang":"en","value":"CWE-23"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-22"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.4.0","versionEndIncluding":"9.5.10","matchCriteriaId":"1033EBE8-93CE-4E62-AC6D-FDA3AEB607FA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.4.0","versionEndIncluding":"9.5.10","matchCriteriaId":"A5815FFE-1A31-4936-89B7-30CCA633295A"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.0.0","versionEndIncluding":"10.1.5","matchCriteriaId":"64162AE5-7888-44B6-9E40-F8003806408C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.0.0","versionEndIncluding":"10.1.15","matchCriteriaId":"377A106A-E5AA-4572-A3AA-04DEE8757307"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartExcluding":"10.2.0","versionEndIncluding":"10.2.5","matchCriteriaId":"DBE72BC6-155E-4E8C-A2DC-B9B4B6610F02"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.2.0","versionEndIncluding":"10.2.5","matchCriteriaId":"AA884C1E-9F66-41DA-9F23-1231086A75CA"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartExcluding":"10.3.0","versionEndIncluding":"10.3.3","matchCriteriaId":"14A161A7-2715-447D-8E30-6D11500B3B8B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.3.0","versionEndIncluding":"10.3.3","matchCriteriaId":"3CEEA359-A827-43C5-8489-FD49AE744CC4"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*","matchCriteriaId":"DEECE5FC-CACF-4496-A3E7-164736409252"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released/","source":"support@hackerone.com","tags":["Vendor Advisory"]},{"url":"https://hackerone.com/reports/301432","source":"support@hackerone.com","tags":["Permissions Required"]},{"url":"https://www.debian.org/security/2018/dsa-4145","source":"support@hackerone.com","tags":["Third Party Advisory"]},{"url":"https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://hackerone.com/reports/301432","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]},{"url":"https://www.debian.org/security/2018/dsa-4145","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2017-0922","sourceIdentifier":"support@hackerone.com","published":"2018-03-21T20:29:00.527","lastModified":"2026-06-17T00:58:31.987","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Gitlab Enterprise Edition version 10.3 is vulnerable to an authorization bypass issue in the GitLab Projects::BoardsController component resulting in an information disclosure on any board object."},{"lang":"es","value":"Gitlab Enterprise Edition 10.3 es vulnerable a un problema de omisión de autenticación en el componente GitLab Projects::BoardsController que resulta en la divulgación de información en cualquier objeto board."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"GitLab","product":"GitLab Community and Enterprise Editions","versions":[{"version":"9.1.0 - 10.1.5 Fixed in 10.1.6","status":"affected"},{"version":"10.2.0 - 10.2.5 Fixed in 10.2.6","status":"affected"},{"version":"10.3.0 - 10.3.3 Fixed in 10.3.4","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"support@hackerone.com","type":"Secondary","description":[{"lang":"en","value":"CWE-639"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"9.1.0","versionEndIncluding":"9.5.10","matchCriteriaId":"CE655DA2-9821-4004-A47A-A2E2CFDFDFF3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"9.1.0","versionEndIncluding":"9.5.10","matchCriteriaId":"9D0E09B1-7E2D-43AC-A0D2-E16DEE929E3D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.0.0","versionEndIncluding":"10.1.5","matchCriteriaId":"81E7F704-BE11-4C38-A69B-27D22298703D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.0.0","versionEndIncluding":"10.1.5","matchCriteriaId":"64162AE5-7888-44B6-9E40-F8003806408C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.2.0","versionEndIncluding":"10.2.5","matchCriteriaId":"643E78E8-2909-41D4-BC2A-2CADDA141DCB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.2.0","versionEndIncluding":"10.2.5","matchCriteriaId":"AA884C1E-9F66-41DA-9F23-1231086A75CA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.3.0","versionEndIncluding":"10.3.3","matchCriteriaId":"7E7D952B-AB31-4962-B178-53260246B33E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.3.0","versionEndIncluding":"10.3.3","matchCriteriaId":"3CEEA359-A827-43C5-8489-FD49AE744CC4"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released/","source":"support@hackerone.com","tags":["Vendor Advisory"]},{"url":"https://hackerone.com/reports/301123","source":"support@hackerone.com","tags":["Permissions Required"]},{"url":"https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://hackerone.com/reports/301123","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2017-0923","sourceIdentifier":"support@hackerone.com","published":"2018-03-21T20:29:00.620","lastModified":"2026-06-17T00:58:32.090","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Gitlab Community Edition version 9.1 is vulnerable to lack of input validation in the IPython notebooks component resulting in persistent cross site scripting."},{"lang":"es","value":"Gitlab Community Edition 9.1 es vulnerable a una falta de validación de entradas en el componente IPython notebooks que resulta en Cross-Site Scripting (XSS) persistente."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"GitLab","product":"GitLab Community and Enterprise Editions","versions":[{"version":"9.1.0 - 10.1.5 Fixed in 10.1.6","status":"affected"},{"version":"10.2.0 - 10.2.5 Fixed in 10.2.6","status":"affected"},{"version":"10.3.0 - 10.3.3 Fixed in 10.3.4","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"support@hackerone.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.5.10:*:*:*:community:*:*:*","matchCriteriaId":"CBC18895-4291-4172-830B-AB92434083A8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:9.5.10:*:*:*:enterprise:*:*:*","matchCriteriaId":"D2B5DC8B-85D4-478A-9CEB-CA94E149628D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:10.1.5:*:*:*:community:*:*:*","matchCriteriaId":"EE50DF93-D1C9-41CC-BBD7-CE91E0351A05"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:10.1.5:*:*:*:enterprise:*:*:*","matchCriteriaId":"8EBFDA9D-CA29-4831-A8F7-D71F7F9ED4DF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:10.2.5:*:*:*:community:*:*:*","matchCriteriaId":"BCD5E2ED-8C98-4E24-A7B9-65787D27F747"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:10.2.5:*:*:*:enterprise:*:*:*","matchCriteriaId":"99A00636-B6CC-4708-9EB0-5A728F45FAA6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:10.3.3:*:*:*:community:*:*:*","matchCriteriaId":"9F0F462A-CC51-470E-8CE6-EF28B06E88E7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:10.3.3:*:*:*:enterprise:*:*:*","matchCriteriaId":"93689CC4-AFC7-4A8D-87A7-01F2A467A832"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released/","source":"support@hackerone.com","tags":["Vendor Advisory"]},{"url":"https://hackerone.com/reports/293740","source":"support@hackerone.com","tags":["Permissions Required"]},{"url":"https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://hackerone.com/reports/293740","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2017-0924","sourceIdentifier":"support@hackerone.com","published":"2018-03-21T20:29:00.683","lastModified":"2026-06-17T00:58:32.197","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Gitlab Community Edition version 10.2.4 is vulnerable to lack of input validation in the labels component resulting in persistent cross site scripting."},{"lang":"es","value":"Gitlab Community Edition 10.2.4 es vulnerable a una falta de validación de entradas en el componente labels que resulta en Cross-Site Scripting (XSS) persistente."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"GitLab","product":"GitLab Community and Enterprise Editions","versions":[{"version":"9.1.0 - 10.0.5 Fixed in 10.0.5","status":"affected"},{"version":"10.1.0 - 10.1.5 Fixed in 10.1.6","status":"affected"},{"version":"10.2.0 - 10.2.5 Fixed in 10.2.6","status":"affected"},{"version":"10.3.0 - 10.3.3 Fixed in 10.3.4","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"support@hackerone.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"9.0.0","versionEndIncluding":"9.5.10","matchCriteriaId":"9B7A2187-0C1C-4B6C-8F1F-5317331A3C0B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"9.0.0","versionEndIncluding":"9.5.10","matchCriteriaId":"6B3402C2-32D0-4B4E-B889-07863D0BAF3B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.0.0","versionEndIncluding":"10.1.5","matchCriteriaId":"81E7F704-BE11-4C38-A69B-27D22298703D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.0.0","versionEndIncluding":"10.1.5","matchCriteriaId":"64162AE5-7888-44B6-9E40-F8003806408C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.2.0","versionEndIncluding":"10.2.5","matchCriteriaId":"643E78E8-2909-41D4-BC2A-2CADDA141DCB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.2.0","versionEndIncluding":"10.2.5","matchCriteriaId":"AA884C1E-9F66-41DA-9F23-1231086A75CA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.3.0","versionEndIncluding":"10.3.3","matchCriteriaId":"7E7D952B-AB31-4962-B178-53260246B33E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.3.0","versionEndIncluding":"10.3.3","matchCriteriaId":"3CEEA359-A827-43C5-8489-FD49AE744CC4"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released/","source":"support@hackerone.com","tags":["Vendor Advisory"]},{"url":"https://hackerone.com/reports/294099","source":"support@hackerone.com","tags":["Permissions Required"]},{"url":"https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://hackerone.com/reports/294099","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2017-0925","sourceIdentifier":"support@hackerone.com","published":"2018-03-21T20:29:00.747","lastModified":"2026-06-17T00:58:32.297","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Gitlab Enterprise Edition version 10.1.0 is vulnerable to an insufficiently protected credential issue in the project service integration API endpoint resulting in an information disclosure of plaintext password."},{"lang":"es","value":"Gitlab Enterprise Edition 10.1.0 es vulnerable a un problema de credenciales protegidas de forma insuficiente en el endpoint de API de proyecto de integración de servicio que resulta en la divulgación de información de contraseñas en texto plano."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"GitLab","product":"GitLab Community and Enterprise Editions","versions":[{"version":"8.10.6 - 10.1.5 Fixed in 10.1.6","status":"affected"},{"version":"10.2.0 - 10.2.5 Fixed in 10.2.6","status":"affected"},{"version":"10.3.0 - 10.3.3 Fixed in 10.3.4","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"support@hackerone.com","type":"Secondary","description":[{"lang":"en","value":"CWE-522"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-319"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.0.0","versionEndIncluding":"9.5.10","matchCriteriaId":"05870508-1CE3-4659-858A-6065F3D8B6B4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.0.0","versionEndIncluding":"9.5.10","matchCriteriaId":"8D9B47D4-A6DB-4EBC-BD09-31CD3A77E430"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.0.0","versionEndIncluding":"10.1.5","matchCriteriaId":"81E7F704-BE11-4C38-A69B-27D22298703D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.0.0","versionEndIncluding":"10.1.5","matchCriteriaId":"64162AE5-7888-44B6-9E40-F8003806408C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.2.0","versionEndIncluding":"10.2.5","matchCriteriaId":"643E78E8-2909-41D4-BC2A-2CADDA141DCB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.2.0","versionEndIncluding":"10.2.5","matchCriteriaId":"AA884C1E-9F66-41DA-9F23-1231086A75CA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.3.0","versionEndIncluding":"10.3.3","matchCriteriaId":"7E7D952B-AB31-4962-B178-53260246B33E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.3.0","versionEndIncluding":"10.3.3","matchCriteriaId":"3CEEA359-A827-43C5-8489-FD49AE744CC4"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*","matchCriteriaId":"DEECE5FC-CACF-4496-A3E7-164736409252"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released/","source":"support@hackerone.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ee/issues/3847","source":"support@hackerone.com","tags":["Issue Tracking"]},{"url":"https://www.debian.org/security/2018/dsa-4145","source":"support@hackerone.com","tags":["Third Party Advisory"]},{"url":"https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ee/issues/3847","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking"]},{"url":"https://www.debian.org/security/2018/dsa-4145","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2017-0926","sourceIdentifier":"support@hackerone.com","published":"2018-03-21T20:29:00.810","lastModified":"2026-06-17T00:58:32.407","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the Oauth sign-in component resulting in unauthorized user login."},{"lang":"es","value":"Gitlab Community Edition 10.3 es vulnerable a un problema de autorización incorrecta en el componente Oauth sign-in que resulta en el inicio de sesión de un usuario no autorizado."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"GitLab","product":"GitLab Community and Enterprise Editions","versions":[{"version":"9.1.0 - 10.0.5 Fixed in 10.0.5","status":"affected"},{"version":"10.1.0 - 10.1.5 Fixed in 10.1.6","status":"affected"},{"version":"10.2.0 - 10.2.5 Fixed in 10.2.6","status":"affected"},{"version":"10.3.0 - 10.3.3 Fixed in 10.3.4","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"support@hackerone.com","type":"Secondary","description":[{"lang":"en","value":"CWE-285"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.8.0","versionEndIncluding":"9.5.10","matchCriteriaId":"B1883059-C7CA-4A1C-8602-1747AA3D07E4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.8.0","versionEndIncluding":"9.5.10","matchCriteriaId":"CA9D3B79-2565-4F11-87CD-745D2F49A477"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.0.0","versionEndIncluding":"10.1.5","matchCriteriaId":"81E7F704-BE11-4C38-A69B-27D22298703D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.0.0","versionEndIncluding":"10.1.5","matchCriteriaId":"64162AE5-7888-44B6-9E40-F8003806408C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.2.0","versionEndIncluding":"10.2.5","matchCriteriaId":"643E78E8-2909-41D4-BC2A-2CADDA141DCB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.2.0","versionEndIncluding":"10.2.5","matchCriteriaId":"AA884C1E-9F66-41DA-9F23-1231086A75CA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.3.0","versionEndIncluding":"10.3.3","matchCriteriaId":"7E7D952B-AB31-4962-B178-53260246B33E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.3.0","versionEndIncluding":"10.3.3","matchCriteriaId":"3CEEA359-A827-43C5-8489-FD49AE744CC4"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*","matchCriteriaId":"DEECE5FC-CACF-4496-A3E7-164736409252"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released/","source":"support@hackerone.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/32198","source":"support@hackerone.com","tags":["Exploit","Issue Tracking"]},{"url":"https://www.debian.org/security/2018/dsa-4145","source":"support@hackerone.com","tags":["Third Party Advisory"]},{"url":"https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/32198","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking"]},{"url":"https://www.debian.org/security/2018/dsa-4145","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2017-0927","sourceIdentifier":"support@hackerone.com","published":"2018-03-21T20:29:00.857","lastModified":"2026-06-17T00:58:32.513","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the deployment keys component resulting in unauthorized use of deployment keys by guest users."},{"lang":"es","value":"Gitlab Community Edition 10.3 es vulnerable a un problema de autorización incorrecta en el componente deployment keys que resulta en el uso no autorizado de claves de implementación por parte de usuarios invitados."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"GitLab","product":"GitLab Community and Enterprise Editions","versions":[{"version":"8.10.6 - 10.1.5 Fixed in 10.1.6","status":"affected"},{"version":"10.2.0 - 10.2.5 Fixed in 10.2.6","status":"affected"},{"version":"10.3.0 - 10.3.3 Fixed in 10.3.4","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"support@hackerone.com","type":"Secondary","description":[{"lang":"en","value":"CWE-285"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.16.0","versionEndIncluding":"9.5.10","matchCriteriaId":"8895687A-8E7F-41BF-9219-C0B7A1E30DD7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.16.0","versionEndIncluding":"9.5.10","matchCriteriaId":"CC959153-DA6C-452B-B06B-8C925CEFEE71"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.0.0","versionEndIncluding":"10.1.5","matchCriteriaId":"81E7F704-BE11-4C38-A69B-27D22298703D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.0.0","versionEndIncluding":"10.1.5","matchCriteriaId":"64162AE5-7888-44B6-9E40-F8003806408C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.2.0","versionEndIncluding":"10.2.5","matchCriteriaId":"643E78E8-2909-41D4-BC2A-2CADDA141DCB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.2.0","versionEndIncluding":"10.2.5","matchCriteriaId":"AA884C1E-9F66-41DA-9F23-1231086A75CA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.3.0","versionEndIncluding":"10.3.3","matchCriteriaId":"7E7D952B-AB31-4962-B178-53260246B33E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.3.0","versionEndIncluding":"10.3.3","matchCriteriaId":"3CEEA359-A827-43C5-8489-FD49AE744CC4"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released/","source":"support@hackerone.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/37594","source":"support@hackerone.com","tags":["Issue Tracking","Third Party Advisory"]},{"url":"https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/37594","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2018-3710","sourceIdentifier":"support@hackerone.com","published":"2018-03-21T20:29:01.027","lastModified":"2026-06-17T01:57:42.223","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Gitlab Community and Enterprise Editions version 10.3.3 is vulnerable to an Insecure Temporary File in the project import component resulting remote code execution."},{"lang":"es","value":"Las ediciones Community y Enterprise de Gitlab, en su versión 10.3.3, son vulnerables a un archivo temporal inseguro en el componente de importación de proyectos, lo que resulta en una ejecución remota de código."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"GitLab","product":"GitLab Community and Enterprise Editions","versions":[{"version":"8.9 - 10.1.5 Fixed in 10.1.6","status":"affected"},{"version":"10.2.0 - 10.2.5 Fixed in 10.2.6","status":"affected"},{"version":"10.3.0 - 10.3.3 Fixed in 10.3.4","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"support@hackerone.com","type":"Secondary","description":[{"lang":"en","value":"CWE-377"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-22"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.9.0","versionEndIncluding":"9.5.10","matchCriteriaId":"492C2FA2-F309-417A-A04E-D218264806AF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.9.0","versionEndIncluding":"9.5.10","matchCriteriaId":"EE2C46FA-7B81-452E-A413-4AB4983753FD"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.0.0","versionEndIncluding":"10.1.5","matchCriteriaId":"64162AE5-7888-44B6-9E40-F8003806408C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.0.0","versionEndIncluding":"10.1.15","matchCriteriaId":"377A106A-E5AA-4572-A3AA-04DEE8757307"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartExcluding":"10.2.0","versionEndIncluding":"10.2.5","matchCriteriaId":"DBE72BC6-155E-4E8C-A2DC-B9B4B6610F02"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.2.0","versionEndIncluding":"10.2.5","matchCriteriaId":"AA884C1E-9F66-41DA-9F23-1231086A75CA"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartExcluding":"10.3.0","versionEndIncluding":"10.3.3","matchCriteriaId":"14A161A7-2715-447D-8E30-6D11500B3B8B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.3.0","versionEndIncluding":"10.3.3","matchCriteriaId":"3CEEA359-A827-43C5-8489-FD49AE744CC4"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*","matchCriteriaId":"DEECE5FC-CACF-4496-A3E7-164736409252"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released/","source":"support@hackerone.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-com/infrastructure/issues/3510","source":"support@hackerone.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/41757","source":"support@hackerone.com","tags":["Vendor Advisory"]},{"url":"https://hackerone.com/reports/302959","source":"support@hackerone.com","tags":["Permissions Required"]},{"url":"https://www.debian.org/security/2018/dsa-4145","source":"support@hackerone.com","tags":["Third Party Advisory"]},{"url":"https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-com/infrastructure/issues/3510","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/41757","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://hackerone.com/reports/302959","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]},{"url":"https://www.debian.org/security/2018/dsa-4145","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2017-0920","sourceIdentifier":"support@hackerone.com","published":"2018-03-22T15:29:00.217","lastModified":"2026-06-17T00:58:31.777","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the Projects::MergeRequests::CreationsController component resulting in an attacker to see every project name and their respective namespace on a GitLab instance."},{"lang":"es","value":"Las ediciones Community y Enterprise de Gitlab, en versiones anteriores a la 10.1.6, 10.2.6 y 10.3.4, son vulnerables a un problema de omisión de autenticación en el componente Projects::MergeRequests::CreationsController. Esto resulta en que un atacante puede ver todos los nombres de proyecto y sus respectivos espacios de nombre en una instancia de GitLab."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"GitLab","product":"GitLab Community and Enterprise Editions","versions":[{"version":"Versions before 10.1.6, 10.2.6, and 10.3.4","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"support@hackerone.com","type":"Secondary","description":[{"lang":"en","value":"CWE-639"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartExcluding":"8.8.0","versionEndIncluding":"10.1.5","matchCriteriaId":"403C99AA-5E14-4ECB-AF6A-20DBE371998D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.8.0","versionEndIncluding":"10.1.5","matchCriteriaId":"19E0A120-3CE9-43FE-AEB6-A93F70BDD776"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartExcluding":"10.2.0","versionEndIncluding":"10.2.5","matchCriteriaId":"DBE72BC6-155E-4E8C-A2DC-B9B4B6610F02"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.2.0","versionEndIncluding":"10.2.5","matchCriteriaId":"AA884C1E-9F66-41DA-9F23-1231086A75CA"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartExcluding":"10.3.0","versionEndIncluding":"10.3.3","matchCriteriaId":"14A161A7-2715-447D-8E30-6D11500B3B8B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.3.0","versionEndIncluding":"10.3.3","matchCriteriaId":"3CEEA359-A827-43C5-8489-FD49AE744CC4"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released/","source":"support@hackerone.com","tags":["Vendor Advisory"]},{"url":"https://hackerone.com/reports/301336","source":"support@hackerone.com","tags":["Permissions Required"]},{"url":"https://www.debian.org/security/2018/dsa-4206","source":"support@hackerone.com"},{"url":"https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://hackerone.com/reports/301336","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]},{"url":"https://www.debian.org/security/2018/dsa-4206","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2018-8971","sourceIdentifier":"cve@mitre.org","published":"2018-03-24T21:29:00.303","lastModified":"2026-06-17T02:05:44.933","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"The Auth0 integration in GitLab before 10.3.9, 10.4.x before 10.4.6, and 10.5.x before 10.5.6 has an incorrect omniauth-auth0 configuration, leading to signing in unintended users."},{"lang":"es","value":"La integración de Auth0 en GitLab, en versiones anteriores a la 10.3.9, versiones 10.4.x anteriores a la 10.4.6 y versiones 10.5.x anteriores a la 10.5.6 tiene una configuración omniauth-auth0 incorrecta, lo que da lugar al firmado de usuarios no deseados."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":6.4,"acInsufInfo":true,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-20"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionEndIncluding":"10.3.8","matchCriteriaId":"2632438F-31F7-47E5-95B7-5605CD032F38"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"10.4.0","versionEndIncluding":"10.4.5","matchCriteriaId":"3CBC7175-90A3-43B6-8017-CCD7C0F37C6E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"10.5.0","versionEndIncluding":"10.5.5","matchCriteriaId":"64309B20-7910-4DF4-BB99-5CC1562C21FB"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*","matchCriteriaId":"DEECE5FC-CACF-4496-A3E7-164736409252"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/03/20/critical-security-release-gitlab-10-dot-5-dot-6-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://www.debian.org/security/2018/dsa-4206","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"https://about.gitlab.com/2018/03/20/critical-security-release-gitlab-10-dot-5-dot-6-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://www.debian.org/security/2018/dsa-4206","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2018-9243","sourceIdentifier":"cve@mitre.org","published":"2018-04-05T14:29:00.327","lastModified":"2026-06-17T02:06:16.670","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab Community and Enterprise Editions version 8.4 up to 10.4 are vulnerable to XSS because a lack of input validation in the merge request component leads to cross site scripting (specifically, filenames in changes tabs of merge requests). This is fixed in 10.6.3, 10.5.7, and 10.4.7."},{"lang":"es","value":"Las ediciones Community y Enterprise de GitLab, de la versión 8.4 hasta la 10.4, son vulnerables a Cross-Site Scripting (XSS) debido a la falta de validación de entradas en el componente merge request que desemboca en Cross-Site Scripting (XSS) (específicamente, los nombres de archivo en las pestañas de cambios de merge requests). La vulnerabilidad se ha solucionado en las versiones 10.6.3, 10.5.7 y 10.4.7."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.4","versionEndExcluding":"10.4.7","matchCriteriaId":"A55FE8A1-4E2F-4E05-90E3-B11855E7ADCE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.4","versionEndExcluding":"10.4.7","matchCriteriaId":"B88BE348-D973-40A3-B767-5A44A25A5A84"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.5.0","versionEndExcluding":"10.5.7","matchCriteriaId":"921DFEAF-7C36-4EC3-8D53-3D5CCDA66AA0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.5.0","versionEndExcluding":"10.5.7","matchCriteriaId":"DF00F4B6-1A22-425D-8073-63560D8C8953"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.6.0","versionEndExcluding":"10.6.3","matchCriteriaId":"7C3CF9AA-F2FA-407B-98B3-7F6C6101AB4A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.6.0","versionEndExcluding":"10.6.3","matchCriteriaId":"9ED9973D-3933-4477-9178-8ACB974782A6"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/04/04/security-release-gitlab-10-dot-6-dot-3-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/42028","source":"cve@mitre.org","tags":["Exploit","Vendor Advisory"]},{"url":"https://about.gitlab.com/2018/04/04/security-release-gitlab-10-dot-6-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/42028","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-9244","sourceIdentifier":"cve@mitre.org","published":"2018-04-05T14:29:00.387","lastModified":"2026-06-17T02:06:16.803","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab Community and Enterprise Editions version 9.2 up to 10.4 are vulnerable to XSS because a lack of input validation in the milestones component leads to cross site scripting (specifically, data-milestone-id in the milestone dropdown feature). This is fixed in 10.6.3, 10.5.7, and 10.4.7."},{"lang":"es","value":"Las ediciones Community y Enterprise de GitLab, de la versión 9.2 hasta la 10.4, son vulnerables a Cross-Site Scripting (XSS) debido a la falta de validación de entradas en el componente milestones que desemboca en Cross-Site Scripting (XSS) (específicamente, data-milestone-id en la característica desplegable milestone). La vulnerabilidad se ha solucionado en las versiones 10.6.3, 10.5.7 y 10.4.7."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"9.2","versionEndExcluding":"10.4.7","matchCriteriaId":"0947F935-F58C-4756-BBDB-03538FBCCB83"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"9.2","versionEndExcluding":"10.4.7","matchCriteriaId":"50CA8BFA-B3D5-46FF-85C5-41AF041FFF75"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.5.0","versionEndExcluding":"10.5.7","matchCriteriaId":"921DFEAF-7C36-4EC3-8D53-3D5CCDA66AA0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.5.0","versionEndExcluding":"10.5.7","matchCriteriaId":"DF00F4B6-1A22-425D-8073-63560D8C8953"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.6.0","versionEndExcluding":"10.6.3","matchCriteriaId":"7C3CF9AA-F2FA-407B-98B3-7F6C6101AB4A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.6.0","versionEndExcluding":"10.6.3","matchCriteriaId":"9ED9973D-3933-4477-9178-8ACB974782A6"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/04/04/security-release-gitlab-10-dot-6-dot-3-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/41838","source":"cve@mitre.org","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://about.gitlab.com/2018/04/04/security-release-gitlab-10-dot-6-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/41838","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-8801","sourceIdentifier":"cve@mitre.org","published":"2018-04-25T09:29:00.770","lastModified":"2026-06-17T02:05:25.177","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab Community and Enterprise Editions version 8.3 up to 10.x before 10.3 are vulnerable to SSRF in the Services and webhooks component."},{"lang":"es","value":"Las ediciones Community y Enterprise de GitLab, desde la versión 8.3 hasta las versiones 10.x anteriores a la 10.3, son vulnerables a SSRF en el componente Services and webhooks."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.3","versionEndExcluding":"10.3","matchCriteriaId":"626D6B34-1175-4A32-A762-F6A219BCD796"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.3","versionEndExcluding":"10.3","matchCriteriaId":"63DA2B16-15FC-40CB-92E2-C02004CE27F4"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab-ce/blob/master/CHANGELOG.md","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/41642","source":"cve@mitre.org","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/301924","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/blob/master/CHANGELOG.md","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/41642","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/301924","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2018-10379","sourceIdentifier":"cve@mitre.org","published":"2018-05-31T21:29:00.230","lastModified":"2026-06-17T01:33:56.413","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) before 10.5.8, 10.6.x before 10.6.5, and 10.7.x before 10.7.2. The Move Issue feature contained a persistent XSS vulnerability."},{"lang":"es","value":"Se ha descubierto un problema en GitLab Community Edition (CE) y Enterprise Edition (EE), en versiones anteriores a la 10.5.8, versiones 10.6.x anteriores a la 10.6.5 y versiones 10.7.x anteriores a la 10.7.2. La característica Move Issue contenía una vulnerabilidad Cross-Site Scripting (XSS) persistente."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"10.5.8","matchCriteriaId":"C4483DE5-1B54-4283-B923-551D450D8B28"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.6.0","versionEndExcluding":"10.6.5","matchCriteriaId":"6BE40D09-F93A-4A53-82CD-7B16115ED0A3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.7.0","versionEndExcluding":"10.7.2","matchCriteriaId":"BFAB986C-0F4C-4931-9E10-7B4E5AFC3778"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"10.5.8","matchCriteriaId":"228CFEAB-DA8F-42D5-8A5E-B21DCBD37866"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.6.0","versionEndExcluding":"10.6.5","matchCriteriaId":"4AA2862A-EA27-4015-9514-D5AD8DE07C2D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.7.0","versionEndExcluding":"10.7.2","matchCriteriaId":"7B653234-A794-4CF7-8498-D42971AC7405"}]}]}],"references":[{"url":"http://www.securityfocus.com/bid/104491","source":"cve@mitre.org","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://about.gitlab.com/2018/04/30/security-release-gitlab-10-dot-7-dot-2-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"http://www.securityfocus.com/bid/104491","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://about.gitlab.com/2018/04/30/security-release-gitlab-10-dot-7-dot-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2017-0919","sourceIdentifier":"support@hackerone.com","published":"2018-07-03T21:29:00.293","lastModified":"2026-06-17T00:58:31.660","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the GitLab import component resulting in an attacker being able to perform operations under a group in which they were previously unauthorized."},{"lang":"es","value":"Las ediciones Community y Enterprise de Gitlab, en versiones anteriores a la 10.1.6, 10.2.6 y 10.3.4, son vulnerables a un problema de omisión de autorización en el componente de importación de GitLab. Esto resulta en que un atacante puede realizar operaciones bajo un grupo en el que antes no estaban autorizados."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-306"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"10.1.6","matchCriteriaId":"BFB57431-FE27-4D54-9A61-020DFD237029"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"10.1.6","matchCriteriaId":"84575803-64B2-4E3A-81A0-F1B964D91258"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.2.0","versionEndExcluding":"10.2.6","matchCriteriaId":"18CE7EFC-7939-4B85-8E2D-D9A584A303C3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.2.0","versionEndExcluding":"10.2.6","matchCriteriaId":"42BEB1BB-7805-40E9-B323-525A0C2506AE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.3.0","versionEndExcluding":"10.3.4","matchCriteriaId":"13F71B19-2DB0-453E-9020-947E26D61C38"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.3.0","versionEndExcluding":"10.3.4","matchCriteriaId":"18718016-0189-4AA9-8BD3-F0D172082B92"}]}]}],"references":[{"url":"https://hackerone.com/reports/301137","source":"support@hackerone.com","tags":["Third Party Advisory"]},{"url":"https://hackerone.com/reports/301137","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2017-0921","sourceIdentifier":"support@hackerone.com","published":"2018-07-03T21:29:00.340","lastModified":"2026-06-17T00:58:31.887","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an unverified password change issue in the PasswordsController component resulting in potential account takeover if a victim's session is compromised."},{"lang":"es","value":"Las ediciones Community y Enterprise de Gitlab, en versiones anteriores a la 10.1.6, 10.2.6 y 10.3.4, son vulnerables a un problema de cambio de contraseña sin verificar en el componente PasswordsController, lo que resulta en la toma de control de la cuenta si la sesión de la víctima se ve comprometida."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.2,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-640"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"10.1.6","matchCriteriaId":"BFB57431-FE27-4D54-9A61-020DFD237029"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"10.1.6","matchCriteriaId":"84575803-64B2-4E3A-81A0-F1B964D91258"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.2.0","versionEndExcluding":"10.2.6","matchCriteriaId":"18CE7EFC-7939-4B85-8E2D-D9A584A303C3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.2.0","versionEndExcluding":"10.2.6","matchCriteriaId":"42BEB1BB-7805-40E9-B323-525A0C2506AE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.3.0","versionEndExcluding":"10.3.4","matchCriteriaId":"13F71B19-2DB0-453E-9020-947E26D61C38"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.3.0","versionEndExcluding":"10.3.4","matchCriteriaId":"18718016-0189-4AA9-8BD3-F0D172082B92"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/05/29/security-release-gitlab-10-dot-8-dot-2-released/","source":"support@hackerone.com","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/2018/05/29/security-release-gitlab-10-dot-8-dot-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-14364","sourceIdentifier":"cve@mitre.org","published":"2018-07-18T19:29:00.213","lastModified":"2026-06-17T01:40:53.513","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab Community and Enterprise Edition before 10.7.7, 10.8.x before 10.8.6, and 11.x before 11.0.4 allows Directory Traversal with write access and resultant remote code execution via the GitLab projects import component."},{"lang":"es","value":"Las ediciones Community y Enterprise de GitLab, en versiones anteriores a la 10.7.7, versiones 10.8.x anteriores a la 10.8.6 y versiones 11.x anteriores a la 11.0.4, permiten un salto de directorio con acceso de escritura y una ejecución remota de código resultante mediante el componente de importación de proyectos de GitLab."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-22"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"10.7.7","matchCriteriaId":"6D5210F0-0088-45EA-AAF1-2CEC763CB58B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"10.7.7","matchCriteriaId":"E52DEADB-32B3-4261-BDF1-4CA35F0DF9C1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.8.0","versionEndExcluding":"10.8.6","matchCriteriaId":"BE5A37FE-8452-4D6A-80B3-0BF67C7401E1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.8.0","versionEndExcluding":"10.8.6","matchCriteriaId":"4CB0CCAA-3E00-4DCE-840A-F201A6CD7DC9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.0","versionEndExcluding":"11.0.4","matchCriteriaId":"60CB4187-4735-4144-B16E-41E669E1BE12"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.0","versionEndExcluding":"11.0.4","matchCriteriaId":"EDB44526-8984-4439-963E-B80751D09134"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/07/17/critical-security-release-gitlab-11-dot-0-dot-4-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/49133","source":"cve@mitre.org","tags":["Exploit","Vendor Advisory"]},{"url":"https://hackerone.com/reports/378148","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory"]},{"url":"https://about.gitlab.com/2018/07/17/critical-security-release-gitlab-11-dot-0-dot-4-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/49133","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]},{"url":"https://hackerone.com/reports/378148","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2018-14601","sourceIdentifier":"cve@mitre.org","published":"2018-07-27T02:29:00.233","lastModified":"2026-06-17T01:41:15.770","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 11.1.x before 11.1.2. A Denial of Service can occur because Markdown rendering times are slow."},{"lang":"es","value":"Se ha descubierto un problema en las ediciones Community y Enterprise de GitLab en versiones 11.1.x anteriores a la 11.1.2. Puede ocurrir una denegación de servicio (DoS) porque los tiempos de renderizado de Markdown son lentos."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":true,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.1.0","versionEndExcluding":"11.1.2","matchCriteriaId":"B5E7E61F-FB1C-40B2-841C-2357AE3BC30B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.1.0","versionEndExcluding":"11.1.2","matchCriteriaId":"5DA4BB5B-8BB7-4DE2-9102-BE98EE99309A"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/07/26/security-release-gitlab-11-dot-1-dot-2-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/49409","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/2018/07/26/security-release-gitlab-11-dot-1-dot-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/49409","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-14602","sourceIdentifier":"cve@mitre.org","published":"2018-07-27T02:29:00.297","lastModified":"2026-06-17T01:41:15.893","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2. Information Disclosure can occur because the Prometheus metrics feature discloses private project pathnames."},{"lang":"es","value":"Se ha descubierto un problema en las ediciones Community y Enterprise de GitLab, en versiones anteriores a la 10.8.7, versiones 11.0.x anteriores a la 11.0.5 y versiones 11.1.x anteriores a la 11.1.2. Puede ocurrir una divulgación de información porque la característica de métricas de Prometheus revela nombres de rutas de proyectos privados."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":true,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-200"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"10.8.7","matchCriteriaId":"52956CBE-7E8C-4494-8CCE-724DF745745C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"10.8.7","matchCriteriaId":"100B73B1-CEE9-496C-BDEA-4F8CC6711E8D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"11.0.5","matchCriteriaId":"4E7C5CD4-761D-456E-A82F-78A12C111F7D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"11.0.5","matchCriteriaId":"B182A27D-FF39-44B2-BFC0-686BF2A491FE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.1.0","versionEndExcluding":"11.1.2","matchCriteriaId":"B5E7E61F-FB1C-40B2-841C-2357AE3BC30B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.1.0","versionEndExcluding":"11.1.2","matchCriteriaId":"5DA4BB5B-8BB7-4DE2-9102-BE98EE99309A"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/07/26/security-release-gitlab-11-dot-1-dot-2-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-com/infrastructure/issues/4423","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/2018/07/26/security-release-gitlab-11-dot-1-dot-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-com/infrastructure/issues/4423","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-14603","sourceIdentifier":"cve@mitre.org","published":"2018-07-27T02:29:00.327","lastModified":"2026-06-17T01:41:16.023","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2. CSRF can occur in the Test feature of the System Hooks component."},{"lang":"es","value":"Se ha descubierto un problema en las ediciones Community y Enterprise de GitLab, en versiones anteriores a la 10.8.7, versiones 11.0.x anteriores a la 11.0.5 y versiones 11.1.x anteriores a la 11.1.2. Puede ocurrir Cross-Site Request Forgery (CSRF) en la característica Test del componente System Hooks."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-352"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"10.8.7","matchCriteriaId":"52956CBE-7E8C-4494-8CCE-724DF745745C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"10.8.7","matchCriteriaId":"100B73B1-CEE9-496C-BDEA-4F8CC6711E8D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"11.0.5","matchCriteriaId":"4E7C5CD4-761D-456E-A82F-78A12C111F7D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"11.0.5","matchCriteriaId":"B182A27D-FF39-44B2-BFC0-686BF2A491FE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.1.0","versionEndExcluding":"11.1.2","matchCriteriaId":"B5E7E61F-FB1C-40B2-841C-2357AE3BC30B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.1.0","versionEndExcluding":"11.1.2","matchCriteriaId":"5DA4BB5B-8BB7-4DE2-9102-BE98EE99309A"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/07/26/security-release-gitlab-11-dot-1-dot-2-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/2018/07/26/security-release-gitlab-11-dot-1-dot-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-14604","sourceIdentifier":"cve@mitre.org","published":"2018-07-27T02:29:00.377","lastModified":"2026-06-17T01:41:16.143","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2. XSS can occur in the tooltip of the job inside the CI/CD pipeline."},{"lang":"es","value":"Se ha descubierto un problema en las ediciones Community y Enterprise de GitLab, en versiones anteriores a la 10.8.7, versiones 11.0.x anteriores a la 11.0.5 y versiones 11.1.x anteriores a la 11.1.2. Puede ocurrir Cross-Site Scripting (XSS) en el tooltip del job dento del pipeline CI/CD."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"10.8.7","matchCriteriaId":"52956CBE-7E8C-4494-8CCE-724DF745745C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"10.8.7","matchCriteriaId":"100B73B1-CEE9-496C-BDEA-4F8CC6711E8D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"11.0.5","matchCriteriaId":"4E7C5CD4-761D-456E-A82F-78A12C111F7D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"11.0.5","matchCriteriaId":"B182A27D-FF39-44B2-BFC0-686BF2A491FE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.1.0","versionEndExcluding":"11.1.2","matchCriteriaId":"B5E7E61F-FB1C-40B2-841C-2357AE3BC30B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.1.0","versionEndExcluding":"11.1.2","matchCriteriaId":"5DA4BB5B-8BB7-4DE2-9102-BE98EE99309A"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/07/26/security-release-gitlab-11-dot-1-dot-2-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/2018/07/26/security-release-gitlab-11-dot-1-dot-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-14605","sourceIdentifier":"cve@mitre.org","published":"2018-07-27T02:29:00.423","lastModified":"2026-06-17T01:41:16.273","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2. XSS can occur in the branch name during a Web IDE file commit."},{"lang":"es","value":"Se ha descubierto un problema en las ediciones Community y Enterprise de GitLab, en versiones anteriores a la 10.8.7, versiones 11.0.x anteriores a la 11.0.5 y versiones 11.1.x anteriores a la 11.1.2. Puede ocurrir Cross-Site Scripting (XSS) en el nombre de branch durante un commit de archivo IDE web."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"10.8.7","matchCriteriaId":"52956CBE-7E8C-4494-8CCE-724DF745745C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"10.8.7","matchCriteriaId":"100B73B1-CEE9-496C-BDEA-4F8CC6711E8D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"11.0.5","matchCriteriaId":"4E7C5CD4-761D-456E-A82F-78A12C111F7D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"11.0.5","matchCriteriaId":"B182A27D-FF39-44B2-BFC0-686BF2A491FE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.1.0","versionEndExcluding":"11.1.2","matchCriteriaId":"B5E7E61F-FB1C-40B2-841C-2357AE3BC30B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.1.0","versionEndExcluding":"11.1.2","matchCriteriaId":"5DA4BB5B-8BB7-4DE2-9102-BE98EE99309A"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/07/26/security-release-gitlab-11-dot-1-dot-2-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/47793","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/2018/07/26/security-release-gitlab-11-dot-1-dot-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/47793","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-14606","sourceIdentifier":"cve@mitre.org","published":"2018-07-27T02:29:00.470","lastModified":"2026-06-17T01:41:16.393","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2. XSS can occur via a Milestone name during a promotion."},{"lang":"es","value":"Se ha descubierto un problema en las ediciones Community y Enterprise de GitLab, en versiones anteriores a la 10.8.7, versiones 11.0.x anteriores a la 11.0.5 y versiones 11.1.x anteriores a la 11.1.2. Puede ocurrir Cross-Site Scripting (XSS) mediante un nombre Milestone durante una promoción."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"10.8.7","matchCriteriaId":"52956CBE-7E8C-4494-8CCE-724DF745745C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"10.8.7","matchCriteriaId":"100B73B1-CEE9-496C-BDEA-4F8CC6711E8D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"11.0.5","matchCriteriaId":"4E7C5CD4-761D-456E-A82F-78A12C111F7D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"11.0.5","matchCriteriaId":"B182A27D-FF39-44B2-BFC0-686BF2A491FE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.1.0","versionEndExcluding":"11.1.2","matchCriteriaId":"B5E7E61F-FB1C-40B2-841C-2357AE3BC30B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.1.0","versionEndExcluding":"11.1.2","matchCriteriaId":"5DA4BB5B-8BB7-4DE2-9102-BE98EE99309A"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/07/26/security-release-gitlab-11-dot-1-dot-2-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/48617","source":"cve@mitre.org","tags":["Exploit","Vendor Advisory"]},{"url":"https://about.gitlab.com/2018/07/26/security-release-gitlab-11-dot-1-dot-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/48617","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-12605","sourceIdentifier":"cve@mitre.org","published":"2018-08-03T18:29:00.267","lastModified":"2026-06-17T01:38:03.087","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community Edition and Enterprise Edition 10.7.x before 10.7.6. The usage of 'url_for' contained a XSS issue due to it allowing arbitrary protocols as a parameter."},{"lang":"es","value":"Se ha descubierto un problema en las ediciones Community y Enterprise de GitLab, en versiones 10.7.x anteriores a la 10.7.6. El uso de \"url_for\" contenía un problema de Cross-Site Scripting (XSS) debido a que se permiten protocolos arbitrarios como parámetro."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.7.0","versionEndExcluding":"10.7.6","matchCriteriaId":"1BD67BA0-E248-471B-9BCB-EB5246ADBFDD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.7.0","versionEndExcluding":"10.7.6","matchCriteriaId":"81115F8E-8542-495E-A602-54BB2247E330"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/06/25/security-release-gitlab-11-dot-0-dot-1-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/45168","source":"cve@mitre.org","tags":["Exploit","Issue Tracking","Patch","Vendor Advisory"]},{"url":"https://about.gitlab.com/2018/06/25/security-release-gitlab-11-dot-0-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/45168","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Patch","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-12606","sourceIdentifier":"cve@mitre.org","published":"2018-08-03T18:29:00.313","lastModified":"2026-06-17T01:38:03.220","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community Edition and Enterprise Edition before 10.7.6, 10.8.x before 10.8.5, and 11.x before 11.0.1. The wiki contains a persistent XSS issue due to a lack of output encoding affecting a specific markdown feature."},{"lang":"es","value":"Se ha descubierto un problema en las ediciones Community y Enterprise de GitLab, en versiones anteriores a la 10.7.6, versiones 10.8.x anteriores a la 10.8.5 y versiones 11.x anteriores a la 11.0.1. La wiki contiene un problema de Cross-Site Scripting (XSS) persistente debido a la falta de cifrado de salida que afecta a una característica de marcado determinada."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"10.7.6","matchCriteriaId":"2C5DD2E3-9F92-4BC0-97FB-1AF618765E19"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"10.7.6","matchCriteriaId":"DD8B6749-AD96-409F-BCA9-E5BE769C617D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.8.0","versionEndExcluding":"10.8.5","matchCriteriaId":"9C518092-DBA4-4C29-AAD2-532DA0B59520"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.8.0","versionEndExcluding":"10.8.5","matchCriteriaId":"8877A85F-4940-4808-BAF9-C046C5E5DF27"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"11.0.1","matchCriteriaId":"FC4E3F8C-819E-4177-BBE0-C418E1FD3582"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"11.0.1","matchCriteriaId":"CC3294CF-6B94-45E1-9A7D-8F4168FA595D"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/06/25/security-release-gitlab-11-dot-0-dot-1-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/46957","source":"cve@mitre.org","tags":["Exploit","Issue Tracking","Patch","Vendor Advisory"]},{"url":"https://about.gitlab.com/2018/06/25/security-release-gitlab-11-dot-0-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/46957","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Patch","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-12607","sourceIdentifier":"cve@mitre.org","published":"2018-08-03T18:29:00.347","lastModified":"2026-06-17T01:38:03.350","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community Edition and Enterprise Edition before 10.7.6, 10.8.x before 10.8.5, and 11.x before 11.0.1. The charts feature contained a persistent XSS issue due to a lack of output encoding."},{"lang":"es","value":"Se ha descubierto un problema en las ediciones Community y Enterprise de GitLab, en versiones anteriores a la 10.7.6, versiones 10.8.x anteriores a la 10.8.5 y versiones 11.x anteriores a la 11.0.1. La característica charts contenía un problema de Cross-Site Scripting (XSS) persistente debido a la falta de cifrado de salida."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"10.7.6","matchCriteriaId":"2C5DD2E3-9F92-4BC0-97FB-1AF618765E19"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"10.7.6","matchCriteriaId":"DD8B6749-AD96-409F-BCA9-E5BE769C617D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.8.0","versionEndExcluding":"10.8.5","matchCriteriaId":"9C518092-DBA4-4C29-AAD2-532DA0B59520"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.8.0","versionEndExcluding":"10.8.5","matchCriteriaId":"8877A85F-4940-4808-BAF9-C046C5E5DF27"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"11.0.1","matchCriteriaId":"FC4E3F8C-819E-4177-BBE0-C418E1FD3582"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"11.0.1","matchCriteriaId":"CC3294CF-6B94-45E1-9A7D-8F4168FA595D"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/06/25/security-release-gitlab-11-dot-0-dot-1-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/45903","source":"cve@mitre.org","tags":["Exploit","Issue Tracking","Patch","Vendor Advisory"]},{"url":"https://about.gitlab.com/2018/06/25/security-release-gitlab-11-dot-0-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/45903","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Patch","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-16048","sourceIdentifier":"cve@mitre.org","published":"2018-10-03T16:29:00.293","lastModified":"2026-06-17T01:43:36.070","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x before 11.2.2. There is Missing Authorization Control for API Repository Storage."},{"lang":"es","value":"Se ha descubierto un problema en las ediciones Community y Enterprise de GitLab, en versiones anteriores a la 11.0.6, versiones 11.1.x anteriores a la 11.1.5 y versiones 11.2.x anteriores a la 11.2.2. Hay una falta de controles de autorización para el almacenamiento de repositorios de la API."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.10.0","versionEndExcluding":"11.0.6","matchCriteriaId":"BE7373AC-4676-4157-AB70-E5D74D579E52"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.1.0","versionEndExcluding":"11.1.5","matchCriteriaId":"E56022FE-6145-452C-AAB5-F7DC59BFDF7B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.2.0","versionEndExcluding":"11.2.2","matchCriteriaId":"42E3481C-50E6-4C84-A464-AC37309A1FED"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/08/28/security-release-gitlab-11-dot-2-dot-2-released/","source":"cve@mitre.org","tags":["Exploit","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/49947","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/2018/08/28/security-release-gitlab-11-dot-2-dot-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/49947","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-16049","sourceIdentifier":"cve@mitre.org","published":"2018-10-03T16:29:00.463","lastModified":"2026-06-17T01:43:36.197","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x before 11.2.2. There is Sensitive Data Disclosure in Sidekiq Logs through an Error Message."},{"lang":"es","value":"Se ha descubierto un problema en las ediciones Community y Enterprise de GitLab, en versiones anteriores a la 11.0.6, versiones 11.1.x anteriores a la 11.1.5 y versiones 11.2.x anteriores a la 11.2.2. Hay una divulgación de datos sensibles en los logs Sidekiq mediante un mensaje de error."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-532"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.10.0","versionEndExcluding":"11.0.6","matchCriteriaId":"5504E335-CB71-4CDB-B8EA-9C987F67C330"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.10.0","versionEndExcluding":"11.0.6","matchCriteriaId":"BE7373AC-4676-4157-AB70-E5D74D579E52"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.1.0","versionEndExcluding":"11.1.5","matchCriteriaId":"65F31A05-8761-4EBC-8EC2-E3C5246D3D36"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.1.0","versionEndExcluding":"11.1.5","matchCriteriaId":"E56022FE-6145-452C-AAB5-F7DC59BFDF7B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.2.0","versionEndExcluding":"11.2.2","matchCriteriaId":"FA04BE89-2E28-4175-BE89-FA15B4E8EE99"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.2.0","versionEndExcluding":"11.2.2","matchCriteriaId":"42E3481C-50E6-4C84-A464-AC37309A1FED"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/08/28/security-release-gitlab-11-dot-2-dot-2-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/46967","source":"cve@mitre.org","tags":["Exploit","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/49272","source":"cve@mitre.org","tags":["Exploit","Vendor Advisory"]},{"url":"https://about.gitlab.com/2018/08/28/security-release-gitlab-11-dot-2-dot-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/46967","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/49272","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-16050","sourceIdentifier":"cve@mitre.org","published":"2018-10-03T16:29:00.713","lastModified":"2026-06-17T01:43:36.327","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 11.1.x before 11.1.5 and 11.2.x before 11.2.2. There is Persistent XSS in the Merge Request Changes View."},{"lang":"es","value":"Se ha descubierto un problema en las ediciones Community y Enterprise de GitLab, en versiones 11.1.x anteriores a la 11.1.5 y versiones 11.2.x anteriores a la 11.2.2. Hay Cross-Site Scripting (XSS) persistente en la vista Merge Request Changes."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.7.0","versionEndIncluding":"10.7.7","matchCriteriaId":"4DC51305-D98B-4B46-BFDE-AD14F7693F5C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.7.0","versionEndIncluding":"10.7.7","matchCriteriaId":"EEEDC6B6-0AD5-4CDB-B36F-8B006ECE62C4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.8.0","versionEndIncluding":"10.8.6","matchCriteriaId":"C04F812F-6C2F-4815-B2B4-4D21DA15CAE0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.8.0","versionEndIncluding":"10.8.6","matchCriteriaId":"A36BDA4E-8E35-4E0F-9B9F-0309F7D3B93A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.1.0","versionEndExcluding":"11.1.5","matchCriteriaId":"65F31A05-8761-4EBC-8EC2-E3C5246D3D36"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.1.0","versionEndExcluding":"11.1.5","matchCriteriaId":"E56022FE-6145-452C-AAB5-F7DC59BFDF7B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.2.0","versionEndExcluding":"11.2.2","matchCriteriaId":"FA04BE89-2E28-4175-BE89-FA15B4E8EE99"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.2.0","versionEndExcluding":"11.2.2","matchCriteriaId":"42E3481C-50E6-4C84-A464-AC37309A1FED"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/08/28/security-release-gitlab-11-dot-2-dot-2-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/49085","source":"cve@mitre.org","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://about.gitlab.com/2018/08/28/security-release-gitlab-11-dot-2-dot-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/49085","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-16051","sourceIdentifier":"cve@mitre.org","published":"2018-10-03T16:29:00.887","lastModified":"2026-06-17T01:43:36.457","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x before 11.2.2. There is Orphaned Upload Files Exposure."},{"lang":"es","value":"Se ha descubierto un problema en las ediciones Community y Enterprise de GitLab, en versiones anteriores a la 11.0.6, versiones 11.1.x anteriores a la 11.1.5 y versiones 11.2.x anteriores a la 11.2.2. Hay una exposición de archivos de subida huérfanos."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-200"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.10.0","versionEndExcluding":"11.0.6","matchCriteriaId":"5504E335-CB71-4CDB-B8EA-9C987F67C330"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.10.0","versionEndExcluding":"11.0.6","matchCriteriaId":"BE7373AC-4676-4157-AB70-E5D74D579E52"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.1.0","versionEndExcluding":"11.1.5","matchCriteriaId":"65F31A05-8761-4EBC-8EC2-E3C5246D3D36"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.1.0","versionEndExcluding":"11.1.5","matchCriteriaId":"E56022FE-6145-452C-AAB5-F7DC59BFDF7B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.2.0","versionEndExcluding":"11.2.2","matchCriteriaId":"FA04BE89-2E28-4175-BE89-FA15B4E8EE99"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.2.0","versionEndExcluding":"11.2.2","matchCriteriaId":"42E3481C-50E6-4C84-A464-AC37309A1FED"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/08/28/security-release-gitlab-11-dot-2-dot-2-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ee/issues/6012","source":"cve@mitre.org","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://about.gitlab.com/2018/08/28/security-release-gitlab-11-dot-2-dot-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ee/issues/6012","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-18649","sourceIdentifier":"cve@mitre.org","published":"2018-11-29T15:29:00.600","lastModified":"2026-06-17T01:47:38.250","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in the wiki API in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It allows for remote code execution."},{"lang":"es","value":"Se ha descubierto un problema en la API wiki en GitLab Community and Enterprise Edition en versiones anteriores a la 11.2.7, 11.3.x anteriores a la 11.3.8 y 11.4.x anteriores a la 11.4.3. Esto permite la ejecución remota de código."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"11.3.8","matchCriteriaId":"65A03890-419C-4CFF-AFE0-9B823F2800AF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"11.3.8","matchCriteriaId":"C5E12452-10A9-43A1-9021-EB421C8D6BC4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.3","matchCriteriaId":"E47DCD39-45DD-4F20-856C-77498FAA7B2B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.3","matchCriteriaId":"65A24CB4-9D78-46AA-AE58-FFACDD44BFD7"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/10/29/security-release-gitlab-11-dot-4-dot-3-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/53072","source":"cve@mitre.org","tags":["Broken Link","Vendor Advisory"]},{"url":"https://about.gitlab.com/2018/10/29/security-release-gitlab-11-dot-4-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/53072","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-17939","sourceIdentifier":"cve@mitre.org","published":"2018-12-04T23:29:00.240","lastModified":"2026-06-17T01:46:34.390","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 11.1.x before 11.1.8, 11.2.x before 11.2.5, and 11.3.x before 11.3.2. There is Information Exposure via the merge request JSON endpoint."},{"lang":"es","value":"Se ha descubierto un problema en las ediciones Community y Enterprise de GitLab, en versiones 11.1.x anteriores a la 11.1.8, versiones 11.2.x anteriores a la 11.2.5 y versiones 11.3.x anteriores a la 11.3.2. Hay una exposición de información mediante el endpoint de petición JSON \"merge\"."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-200"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.1.0","versionEndExcluding":"11.1.8","matchCriteriaId":"D12BF0A5-0472-4E1A-B835-765E5645DAEE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.1.0","versionEndExcluding":"11.1.8","matchCriteriaId":"DA5E671F-853E-4C82-B5CF-1482701AA89B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.2.0","versionEndExcluding":"11.2.5","matchCriteriaId":"1537C7BA-BF68-4090-B578-28DEEE7DE260"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.2.0","versionEndExcluding":"11.2.5","matchCriteriaId":"FEF6DD01-7F50-4D2A-B57B-B298A63B469B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"11.3.2","matchCriteriaId":"C812A796-A01D-4EAB-873B-B234819C7DC9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"11.3.2","matchCriteriaId":"F09D6911-DCC0-4367-A2D3-8E8E541859A3"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/10/05/critical-security-release-11-3-4/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/51956","source":"cve@mitre.org","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://about.gitlab.com/2018/10/05/critical-security-release-11-3-4/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/51956","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-17975","sourceIdentifier":"cve@mitre.org","published":"2018-12-04T23:29:00.303","lastModified":"2026-06-17T01:46:38.070","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community Edition 11.x before 11.1.8, 11.2.x before 11.2.5, and 11.3.x before 11.3.2. There is Information Exposure via the GFM markdown API."},{"lang":"es","value":"Se ha descubierto un problema en la edición Community de GitLab, en versiones 11.1.x anteriores a la 11.1.8, versiones 11.2.x anteriores a la 11.2.5 y versiones 11.3.x anteriores a la 11.3.2. Hay una exposición de información mediante la API de marcado GFM."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-200"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"11.1.8","matchCriteriaId":"49535CE9-CB07-4C1D-BA44-2755887E4082"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.2.0","versionEndExcluding":"11.2.5","matchCriteriaId":"1537C7BA-BF68-4090-B578-28DEEE7DE260"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"11.3.2","matchCriteriaId":"C812A796-A01D-4EAB-873B-B234819C7DC9"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/10/05/critical-security-release-11-3-4/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/50744","source":"cve@mitre.org","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://about.gitlab.com/2018/10/05/critical-security-release-11-3-4/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/50744","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-17976","sourceIdentifier":"cve@mitre.org","published":"2018-12-04T23:29:00.350","lastModified":"2026-06-17T01:46:38.197","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community Edition 11.x before 11.1.8, 11.2.x before 11.2.5, and 11.3.x before 11.3.2. There is Information Exposure via Epic change descriptions."},{"lang":"es","value":"Se ha descubierto un problema en la edición Community de GitLab, en versiones 11.1.x anteriores a la 11.1.8, versiones 11.2.x anteriores a la 11.2.5 y versiones 11.3.x anteriores a la 11.3.2. Hay una exposición de información mediante las descripciones de cambios Epic."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-200"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"11.1.8","matchCriteriaId":"49535CE9-CB07-4C1D-BA44-2755887E4082"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.2.0","versionEndExcluding":"11.2.5","matchCriteriaId":"1537C7BA-BF68-4090-B578-28DEEE7DE260"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"11.3.2","matchCriteriaId":"C812A796-A01D-4EAB-873B-B234819C7DC9"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/10/05/critical-security-release-11-3-4/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/51581","source":"cve@mitre.org","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://about.gitlab.com/2018/10/05/critical-security-release-11-3-4/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/51581","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-18640","sourceIdentifier":"cve@mitre.org","published":"2018-12-04T23:29:00.413","lastModified":"2026-06-17T01:47:37.083","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It has Information Exposure Through Browser Caching."},{"lang":"es","value":"Se ha descubierto un problema en las ediciones Community y Enterprise de GitLab, en versiones anteriores a la 11.2.7, versiones 11.3.x anteriores a la 11.3.8 y versiones 11.4.x anteriores a la 11.4.3. Tiene una exposición de información mediante el cacheo del navegador."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-200"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"11.2.7","matchCriteriaId":"4D2C5FCB-808B-4990-925D-EAA37BD71BB6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"11.2.7","matchCriteriaId":"AEF6C56E-F167-4F90-8E3D-AFB0DAE851D8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"11.3.8","matchCriteriaId":"65A03890-419C-4CFF-AFE0-9B823F2800AF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"11.3.8","matchCriteriaId":"C5E12452-10A9-43A1-9021-EB421C8D6BC4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.3","matchCriteriaId":"E47DCD39-45DD-4F20-856C-77498FAA7B2B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.3","matchCriteriaId":"65A24CB4-9D78-46AA-AE58-FFACDD44BFD7"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/10/29/security-release-gitlab-11-dot-4-dot-3-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/51423","source":"cve@mitre.org","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://about.gitlab.com/2018/10/29/security-release-gitlab-11-dot-4-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/51423","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-18641","sourceIdentifier":"cve@mitre.org","published":"2018-12-04T23:29:00.460","lastModified":"2026-06-17T01:47:37.207","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It has Cleartext Storage of Sensitive Information."},{"lang":"es","value":"Se ha descubierto un problema en las ediciones Community y Enterprise de GitLab, en versiones anteriores a la 11.2.7, versiones 11.3.x anteriores a la 11.3.8 y versiones 11.4.x anteriores a la 11.4.3. Tiene almacenamiento en texto claro de información sensible."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-312"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.10.0","versionEndExcluding":"11.2.7","matchCriteriaId":"2C19463D-E261-4456-A637-559C28769317"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.10.0","versionEndExcluding":"11.2.7","matchCriteriaId":"D4C4FCF2-7BEB-403F-80D6-6C8B31A228F0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"11.3.8","matchCriteriaId":"65A03890-419C-4CFF-AFE0-9B823F2800AF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"11.3.8","matchCriteriaId":"C5E12452-10A9-43A1-9021-EB421C8D6BC4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.3","matchCriteriaId":"E47DCD39-45DD-4F20-856C-77498FAA7B2B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.3","matchCriteriaId":"65A24CB4-9D78-46AA-AE58-FFACDD44BFD7"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/10/29/security-release-gitlab-11-dot-4-dot-3-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/51113","source":"cve@mitre.org","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://about.gitlab.com/2018/10/29/security-release-gitlab-11-dot-4-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/51113","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-18642","sourceIdentifier":"cve@mitre.org","published":"2018-12-04T23:29:00.507","lastModified":"2026-06-17T01:47:37.330","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It has XSS."},{"lang":"es","value":"Se ha descubierto un problema en las ediciones Community y Enterprise de GitLab, en versiones anteriores a la 11.2.7, versiones 11.3.x anteriores a la 11.3.8 y versiones 11.4.x anteriores a la 11.4.3. Tiene Cross-Site Scripting (XSS)."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.4.0","versionEndExcluding":"11.2.7","matchCriteriaId":"429FBAEF-730A-45EA-9608-E09FAF44C81B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.4.0","versionEndExcluding":"11.2.7","matchCriteriaId":"C5932AB8-8596-465B-8C56-3FD90E34A2ED"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"11.3.8","matchCriteriaId":"65A03890-419C-4CFF-AFE0-9B823F2800AF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"11.3.8","matchCriteriaId":"C5E12452-10A9-43A1-9021-EB421C8D6BC4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.3","matchCriteriaId":"E47DCD39-45DD-4F20-856C-77498FAA7B2B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.3","matchCriteriaId":"65A24CB4-9D78-46AA-AE58-FFACDD44BFD7"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/10/29/security-release-gitlab-11-dot-4-dot-3-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/52551","source":"cve@mitre.org","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://about.gitlab.com/2018/10/29/security-release-gitlab-11-dot-4-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/52551","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-18644","sourceIdentifier":"cve@mitre.org","published":"2018-12-04T23:29:00.567","lastModified":"2026-06-17T01:47:37.597","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It allows Information Exposure via a Gitlab Prometheus integration."},{"lang":"es","value":"Se ha descubierto un problema en las ediciones Community y Enterprise de GitLab, en versiones 11.x anteriores a la 11.2.7, versiones 11.3.x anteriores a la 11.3.8 y versiones 11.4.x anteriores a la 11.4.3. Permite la exposición de información mediante la integración con Gitlab Prometheus."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-200"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.2.0","versionEndExcluding":"11.2.7","matchCriteriaId":"271BBBB2-4B9F-40B1-8F11-EC9728B4A73C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.2.0","versionEndExcluding":"11.2.7","matchCriteriaId":"B5D4A769-63B5-45FF-801C-59F550DE3BC8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"11.3.8","matchCriteriaId":"65A03890-419C-4CFF-AFE0-9B823F2800AF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"11.3.8","matchCriteriaId":"C5E12452-10A9-43A1-9021-EB421C8D6BC4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.3","matchCriteriaId":"E47DCD39-45DD-4F20-856C-77498FAA7B2B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.3","matchCriteriaId":"65A24CB4-9D78-46AA-AE58-FFACDD44BFD7"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/10/29/security-release-gitlab-11-dot-4-dot-3-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ee/issues/7528","source":"cve@mitre.org","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://about.gitlab.com/2018/10/29/security-release-gitlab-11-dot-4-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ee/issues/7528","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-18645","sourceIdentifier":"cve@mitre.org","published":"2018-12-04T23:29:00.617","lastModified":"2026-06-17T01:47:37.730","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It allows for Information Exposure via unsubscribe links in email replies."},{"lang":"es","value":"Se ha descubierto un problema en las ediciones Community y Enterprise de GitLab, en versiones anteriores a la 11.2.7, versiones 11.3.x anteriores a la 11.3.8 y versiones 11.4.x anteriores a la 11.4.3. Permite la exposición de información mediante los enlaces de desuscripción en las respuestas de emails."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-200"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"11.2.7","matchCriteriaId":"4D2C5FCB-808B-4990-925D-EAA37BD71BB6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"11.2.7","matchCriteriaId":"AEF6C56E-F167-4F90-8E3D-AFB0DAE851D8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"11.3.8","matchCriteriaId":"65A03890-419C-4CFF-AFE0-9B823F2800AF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"11.3.8","matchCriteriaId":"C5E12452-10A9-43A1-9021-EB421C8D6BC4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.3","matchCriteriaId":"E47DCD39-45DD-4F20-856C-77498FAA7B2B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.3","matchCriteriaId":"65A24CB4-9D78-46AA-AE58-FFACDD44BFD7"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/10/29/security-release-gitlab-11-dot-4-dot-3-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/24498","source":"cve@mitre.org","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://about.gitlab.com/2018/10/29/security-release-gitlab-11-dot-4-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/24498","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-18646","sourceIdentifier":"cve@mitre.org","published":"2018-12-04T23:29:00.663","lastModified":"2026-06-17T01:47:37.853","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It allows SSRF."},{"lang":"es","value":"Se ha descubierto un problema en las ediciones Community y Enterprise de GitLab, en versiones anteriores a la 11.2.7, versiones 11.3.x anteriores a la 11.3.8 y versiones 11.4.x anteriores a la 11.4.3. Permite Server-Side Request Forgery (SSRF)."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"5.3","versionEndExcluding":"11.2.7","matchCriteriaId":"7825EA9F-4A70-47D1-92AA-093CF68ECFA9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"5.3","versionEndExcluding":"11.2.7","matchCriteriaId":"913C94F4-9531-42C2-BC5A-7AE8E455FEEA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"11.3.8","matchCriteriaId":"65A03890-419C-4CFF-AFE0-9B823F2800AF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"11.3.8","matchCriteriaId":"C5E12452-10A9-43A1-9021-EB421C8D6BC4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.3","matchCriteriaId":"E47DCD39-45DD-4F20-856C-77498FAA7B2B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.3","matchCriteriaId":"65A24CB4-9D78-46AA-AE58-FFACDD44BFD7"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/10/29/security-release-gitlab-11-dot-4-dot-3-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/51142","source":"cve@mitre.org","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://about.gitlab.com/2018/10/29/security-release-gitlab-11-dot-4-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/51142","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-18647","sourceIdentifier":"cve@mitre.org","published":"2018-12-04T23:29:00.723","lastModified":"2026-06-17T01:47:37.980","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It has Missing Authorization."},{"lang":"es","value":"Se ha descubierto un problema en las ediciones Community y Enterprise de GitLab, en versiones anteriores a la 11.2.7, versiones 11.3.x anteriores a la 11.3.8 y versiones 11.4.x anteriores a la 11.4.3. Tiene una falta de autorización."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:P","baseScore":5.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.11","versionEndExcluding":"11.2.7","matchCriteriaId":"185AD75F-EFC6-47F0-9605-85AE0B4D2FD6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.11","versionEndExcluding":"11.2.7","matchCriteriaId":"FEBC7958-2A6D-46A7-812C-918644F204FD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"11.3.8","matchCriteriaId":"65A03890-419C-4CFF-AFE0-9B823F2800AF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"11.3.8","matchCriteriaId":"C5E12452-10A9-43A1-9021-EB421C8D6BC4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.3","matchCriteriaId":"E47DCD39-45DD-4F20-856C-77498FAA7B2B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.3","matchCriteriaId":"65A24CB4-9D78-46AA-AE58-FFACDD44BFD7"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/10/29/security-release-gitlab-11-dot-4-dot-3-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ee/issues/7538","source":"cve@mitre.org","tags":["Exploit","Issue Tracking","Patch","Vendor Advisory"]},{"url":"https://about.gitlab.com/2018/10/29/security-release-gitlab-11-dot-4-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ee/issues/7538","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Patch","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-18648","sourceIdentifier":"cve@mitre.org","published":"2018-12-04T23:29:00.770","lastModified":"2026-06-17T01:47:38.117","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It has Information Exposure Through an Error Message."},{"lang":"es","value":"Se ha descubierto un problema en las ediciones Community y Enterprise de GitLab, en versiones anteriores a la 11.2.7, versiones 11.3.x anteriores a la 11.3.8 y versiones 11.4.x anteriores a la 11.4.3. Tiene una exposición de información mediante un mensaje de error."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-200"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.2.0","versionEndExcluding":"11.2.7","matchCriteriaId":"271BBBB2-4B9F-40B1-8F11-EC9728B4A73C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.2.0","versionEndExcluding":"11.2.7","matchCriteriaId":"B5D4A769-63B5-45FF-801C-59F550DE3BC8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"11.3.8","matchCriteriaId":"65A03890-419C-4CFF-AFE0-9B823F2800AF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"11.3.8","matchCriteriaId":"C5E12452-10A9-43A1-9021-EB421C8D6BC4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.3","matchCriteriaId":"E47DCD39-45DD-4F20-856C-77498FAA7B2B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.3","matchCriteriaId":"65A24CB4-9D78-46AA-AE58-FFACDD44BFD7"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/10/29/security-release-gitlab-11-dot-4-dot-3-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/50975","source":"cve@mitre.org","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://about.gitlab.com/2018/10/29/security-release-gitlab-11-dot-4-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/50975","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-18843","sourceIdentifier":"cve@mitre.org","published":"2018-12-04T23:29:00.833","lastModified":"2026-06-17T01:48:00.690","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"The Kubernetes integration in GitLab Enterprise Edition 11.x before 11.2.8, 11.3.x before 11.3.9, and 11.4.x before 11.4.4 has SSRF."},{"lang":"es","value":"La integración con Kubernetes en la edición Enterprise de GitLab, en versiones 11.1.x anteriores a la 11.2.8, versiones 11.3.x anteriores a la 11.3.9 y versiones 11.4.x anteriores a la 11.4.4, tiene Server-Side Request Forgery (SSRF)."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","baseScore":10.0,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":6.0}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"11.2.8","matchCriteriaId":"FB94DAB7-4336-4606-9E6A-95B7E53FEBEA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"11.3.9","matchCriteriaId":"C4A59CCE-0AB6-4F61-ABF8-4A4A2F99518B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.4","matchCriteriaId":"36933D43-44C5-46F5-81B3-8B0603E69B7C"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/11/01/critical-security-release-gitlab-11-dot-4-dot-4-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/53158","source":"cve@mitre.org","tags":["Exploit","Issue Tracking","Patch","Vendor Advisory"]},{"url":"https://about.gitlab.com/2018/11/01/critical-security-release-gitlab-11-dot-4-dot-4-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/53158","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Patch","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-6240","sourceIdentifier":"cve@mitre.org","published":"2019-03-25T17:29:01.107","lastModified":"2026-06-17T02:38:52.187","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.4. It allows Directory Traversal."},{"lang":"es","value":"Se ha descubierto un problema en GitLab Community y Enterprise Edition en versiones anteriores a la 11.14. Permite el salto de directorio."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-22"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"11.4.0","matchCriteriaId":"70607C18-97AB-41EE-BBDD-5B2B1F62AB3E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"11.4.0","matchCriteriaId":"2C0523B8-5228-45AD-BD2A-48BE9C72CE3B"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/01/16/critical-security-release-gitlab-11-dot-6-dot-4-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Product","Vendor Advisory"]},{"url":"https://about.gitlab.com/2019/01/16/critical-security-release-gitlab-11-dot-6-dot-4-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Product","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-19856","sourceIdentifier":"cve@mitre.org","published":"2019-03-26T16:29:00.400","lastModified":"2026-06-17T01:50:00.243","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab CE/EE before 11.3.12, 11.4.x before 11.4.10, and 11.5.x before 11.5.3 allows Directory Traversal in Templates API."},{"lang":"es","value":"GitLab CE/EE, en versiones anteriores a la 11.3.12, versiones 11.4.x anteriores a la 11.4.10 y versiones 11.5.x anteriores a la 11.5.3, permite el salto de directorio en la API de plantillas."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-22"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"11.3.12","matchCriteriaId":"1AD0D865-6B44-4B84-9082-90D2928AA5C1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"11.3.12","matchCriteriaId":"48AC1FF1-B7C7-4EAA-897D-40E7B43C74BA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.10","matchCriteriaId":"FA471F6B-363F-49BC-B8FB-4C09FCA240AB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.10","matchCriteriaId":"9607E055-CD9B-4601-823C-DEB90B610421"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.3","matchCriteriaId":"FDBB2F3C-A8CF-4A0F-9307-A739AE3F7DFB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.3","matchCriteriaId":"A8E0C86B-B01E-43D6-B616-CFD66EA9D553"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/12/06/critical-security-release-gitlab-11-dot-5-dot-3-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/54857","source":"cve@mitre.org","tags":["Exploit","Vendor Advisory"]},{"url":"https://about.gitlab.com/2018/12/06/critical-security-release-gitlab-11-dot-5-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/54857","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-20144","sourceIdentifier":"cve@mitre.org","published":"2019-03-28T15:29:00.247","lastModified":"2026-06-17T01:52:20.223","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab Community and Enterprise Edition 11.x before 11.3.13, 11.4.x before 11.4.11, and 11.5.x before 11.5.4 has Incorrect Access Control."},{"lang":"es","value":"GitLab Community and Enterprise Edition, en las versiones 11.x anteriores a la 11.3.13 y en las 11.4.x anteriores a la 11.4.11 y en las 11.5.x anteriores a la 11.5.4, tiene un control de acceso incorrecto."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-22"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"11.3.13","matchCriteriaId":"16FD1486-1F89-45F4-A38C-9CE49D3C168C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"11.3.13","matchCriteriaId":"489488F4-BEB8-4B90-87B2-9A315D432C74"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.11","matchCriteriaId":"8DC443A1-4D36-49FE-A4DB-FAA950076F2D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.11","matchCriteriaId":"A4EBB2FB-602A-4088-92B4-AFEBD03E4628"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.4","matchCriteriaId":"5184E1B5-649A-456B-9711-1FE8FEBC25D0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.4","matchCriteriaId":"B9702026-71D4-4216-8D62-9EA55936CF4A"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/12/13/critical-security-release-gitlab-11-dot-5-dot-4-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Product","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/55200","source":"cve@mitre.org","tags":["Exploit","Vendor Advisory"]},{"url":"https://about.gitlab.com/2018/12/13/critical-security-release-gitlab-11-dot-5-dot-4-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Product","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/55200","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-20229","sourceIdentifier":"cve@mitre.org","published":"2019-04-04T17:29:00.890","lastModified":"2026-06-17T01:52:31.037","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab Community and Enterprise Edition before 11.3.14, 11.4.x before 11.4.12, and 11.5.x before 11.5.5 allows Directory Traversal."},{"lang":"es","value":"GitLab Community and Enterprise Edition, en versiones anteriores a la 11.3.14, las 11.4.x en versiones anteriores a la 11.4.12 y las 11.5.x en versiones anteriores a la 11.5.5 permite saltos de directorio."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-22"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"11.3.14","matchCriteriaId":"E0BBE35C-E68A-4D07-8DA8-88CC3B7D8ACB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"11.3.14","matchCriteriaId":"A6E58636-7EF3-4CDB-9A12-45EABA1F650E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.12","matchCriteriaId":"026D284A-44CA-4A96-876F-8E23B0D792EA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.12","matchCriteriaId":"8934F026-7991-42AD-ADDF-90A661DF1DF0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.5","matchCriteriaId":"5274BD4F-9BC7-46C1-807A-55C08ABD0EF6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.5","matchCriteriaId":"AA3A6C26-A87F-4D7E-8224-EACE2B750DDC"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/12/20/critical-security-release-gitlab-11-dot-5-dot-5-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/2018/12/20/critical-security-release-gitlab-11-dot-5-dot-5-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-6796","sourceIdentifier":"cve@mitre.org","published":"2019-04-11T20:29:00.667","lastModified":"2026-06-17T02:39:41.870","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows XSS (issue 2 of 2). The user status field contains a lack of input validation and output encoding that results in a persistent XSS."},{"lang":"es","value":"Se detecto un problema en GitLab Community and Enterprise Edition anterior a versión 11.5.8, versión 11.6.x anterior a 11.6.6 y versión 11.7.x anterior a 11.7.1. Permite una vulnerabilidad de tipo XSS (problema 2 de 2). El campo de estado del usuario contiene una falta de validación de entrada y codificación de salida que resulta en un XSS persistente."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"11.5.8","matchCriteriaId":"3505D02B-D60F-4E91-AB07-F704D04BEDF4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"11.5.8","matchCriteriaId":"5CAB52EA-9EE4-424C-80D8-0987AEDE045E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.6.0","versionEndIncluding":"11.6.5","matchCriteriaId":"1FA359C7-EDAE-4AF0-9BFE-8AD1FFBAA7C3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.6.0","versionEndIncluding":"11.6.5","matchCriteriaId":"B8AD6594-01D0-437D-A6DC-EC67DA589757"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.1","matchCriteriaId":"3BAE4B6C-8F1F-4C42-ADF9-A9CBD3895C68"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.1","matchCriteriaId":"3A67FE77-4048-41B8-8734-CA62393ED632"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/2019/02/05/critical-security-release-gitlab-11-dot-7-dot-4-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/55320","source":"cve@mitre.org"},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/57112","source":"cve@mitre.org","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/2019/02/05/critical-security-release-gitlab-11-dot-7-dot-4-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/55320","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/57112","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-7155","sourceIdentifier":"cve@mitre.org","published":"2019-04-16T22:29:00.733","lastModified":"2026-06-17T02:40:11.063","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. A user retains their role within a project in a private group after being removed from the group, if their privileges within the project are different from the group."},{"lang":"es","value":"Se detectó un problema en GitLab Community and Enterprise Edition versiones 9.x, 10.x, y 11.x en versiones anteriores a la 11.5.8, 11.6.x en versiones anteriores a la 11.6.6, y 11.7.x en versiones anteriores a la 11.7.1. Presenta un control de acceso incorrecto. Un usuario conserva su rol dentro de un proyecto en un grupo privado después de ser eliminado del grupo, si sus privilegios dentro del proyecto son diferentes del grupo."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-269"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"9.0.0","versionEndExcluding":"11.5.8","matchCriteriaId":"01FF5284-807E-47AB-A400-4A4384DFE735"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"9.0.0","versionEndExcluding":"11.5.8","matchCriteriaId":"C27A3343-2502-4B4A-9127-BF668B67050F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.6","matchCriteriaId":"794CA42E-5409-455B-956C-21BC431E0B98"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.6","matchCriteriaId":"35A01A1A-A0F1-4952-B15A-A898FD185B3F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.1","matchCriteriaId":"3BAE4B6C-8F1F-4C42-ADF9-A9CBD3895C68"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.1","matchCriteriaId":"3A67FE77-4048-41B8-8734-CA62393ED632"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/42726","source":"cve@mitre.org","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/42726","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-9170","sourceIdentifier":"cve@mitre.org","published":"2019-04-17T17:29:00.553","lastModified":"2026-06-17T02:43:11.580","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control."},{"lang":"es","value":"Se descubrió un problema en GitLab Community and Enterprise Edition antes de 11.6.10, 11.7.x antes de 11.7.6 y 11.8.x antes de 11.8.1. Tiene control de acceso incorrecto."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-639"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"11.6.10","matchCriteriaId":"13C741F9-E2E3-4C28-8331-F22BF96E6E95"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"11.6.10","matchCriteriaId":"4DF47DD3-57E7-40B1-BE2A-9041A083597B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.6","matchCriteriaId":"5D8490E0-F40D-479C-ADF9-6A8A6D1B4C31"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.6","matchCriteriaId":"A0143A98-2A68-45AE-9DC6-6053113DD4F2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.1","matchCriteriaId":"9361A997-0735-41EB-B251-605E0174E602"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.1","matchCriteriaId":"6DFB4A63-4FE4-4499-8834-E6BCE8E9EF24"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/03/04/security-release-gitlab-11-dot-8-dot-1-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Product","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/51971","source":"cve@mitre.org","tags":["Exploit","Vendor Advisory"]},{"url":"https://about.gitlab.com/2019/03/04/security-release-gitlab-11-dot-8-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Product","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/51971","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-9171","sourceIdentifier":"cve@mitre.org","published":"2019-04-17T17:29:00.617","lastModified":"2026-06-17T02:43:11.697","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Information Exposure (issue 1 of 5)."},{"lang":"es","value":"Se detecto un problema en GitLab Community and Enterprise Edition anterior a versión 11.6.10, versión 11.7.x anterior a 11.7.6 y versión 11.8.x anterior a 11.8.1. Permite la Exposición de Información (número 1 de 5)."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":3.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"11.6.10","matchCriteriaId":"13C741F9-E2E3-4C28-8331-F22BF96E6E95"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"11.6.10","matchCriteriaId":"4DF47DD3-57E7-40B1-BE2A-9041A083597B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.6","matchCriteriaId":"5D8490E0-F40D-479C-ADF9-6A8A6D1B4C31"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.6","matchCriteriaId":"A0143A98-2A68-45AE-9DC6-6053113DD4F2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.1","matchCriteriaId":"9361A997-0735-41EB-B251-605E0174E602"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.1","matchCriteriaId":"6DFB4A63-4FE4-4499-8834-E6BCE8E9EF24"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/03/04/security-release-gitlab-11-dot-8-dot-1-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Product","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/54635","source":"cve@mitre.org","tags":["Exploit","Vendor Advisory"]},{"url":"https://about.gitlab.com/2019/03/04/security-release-gitlab-11-dot-8-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Product","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/54635","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-9172","sourceIdentifier":"cve@mitre.org","published":"2019-04-17T17:29:00.677","lastModified":"2026-06-17T02:43:11.807","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Information Exposure (issue 2 of 5)."},{"lang":"es","value":"Se detecto un problema en GitLab Community and Enterprise Edition anterior a versión 11.6.10, versión 11.7.x anterior a 11.7.6 y versión 11.8.x anterior a 11.8.1. Permite la Exposición de Información (número 2 de 5)."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"11.6.10","matchCriteriaId":"13C741F9-E2E3-4C28-8331-F22BF96E6E95"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"11.6.10","matchCriteriaId":"4DF47DD3-57E7-40B1-BE2A-9041A083597B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.6","matchCriteriaId":"5D8490E0-F40D-479C-ADF9-6A8A6D1B4C31"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.6","matchCriteriaId":"A0143A98-2A68-45AE-9DC6-6053113DD4F2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.1","matchCriteriaId":"9361A997-0735-41EB-B251-605E0174E602"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.1","matchCriteriaId":"6DFB4A63-4FE4-4499-8834-E6BCE8E9EF24"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/03/04/security-release-gitlab-11-dot-8-dot-1-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Product","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/54795","source":"cve@mitre.org","tags":["Exploit","Vendor Advisory"]},{"url":"https://about.gitlab.com/2019/03/04/security-release-gitlab-11-dot-8-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Product","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/54795","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-9174","sourceIdentifier":"cve@mitre.org","published":"2019-04-17T17:29:00.740","lastModified":"2026-06-17T02:43:11.920","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows SSRF."},{"lang":"es","value":"Se descubrió un problema en GitLab Community y Enterprise Edition versión anterior a 11.6.10,versión 11.7.x anterior a 11.7.6 y versión 11.8.x anterior a 11.8.1. Permite Server Side Request Forgery (SSRF)."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","baseScore":10.0,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":6.0}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"11.6.10","matchCriteriaId":"13C741F9-E2E3-4C28-8331-F22BF96E6E95"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"11.6.10","matchCriteriaId":"4DF47DD3-57E7-40B1-BE2A-9041A083597B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.6","matchCriteriaId":"5D8490E0-F40D-479C-ADF9-6A8A6D1B4C31"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.6","matchCriteriaId":"A0143A98-2A68-45AE-9DC6-6053113DD4F2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.1","matchCriteriaId":"9361A997-0735-41EB-B251-605E0174E602"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.1","matchCriteriaId":"6DFB4A63-4FE4-4499-8834-E6BCE8E9EF24"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/03/04/security-release-gitlab-11-dot-8-dot-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/55468","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/2019/03/04/security-release-gitlab-11-dot-8-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/55468","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-9175","sourceIdentifier":"cve@mitre.org","published":"2019-04-17T17:29:00.787","lastModified":"2026-06-17T02:43:12.033","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Information Exposure (issue 3 of 5)."},{"lang":"es","value":"Se detecto un problema en GitLab Community and Enterprise Edition anterior a versión 11.6.10, versión 11.7.x anterior a 11.7.6 y versión 11.8.x anterior a 11.8.1. Permite la Exposición de Información (problema 3 de 5)."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-200"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"11.6.10","matchCriteriaId":"13C741F9-E2E3-4C28-8331-F22BF96E6E95"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"11.6.10","matchCriteriaId":"4DF47DD3-57E7-40B1-BE2A-9041A083597B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.6","matchCriteriaId":"5D8490E0-F40D-479C-ADF9-6A8A6D1B4C31"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.6","matchCriteriaId":"A0143A98-2A68-45AE-9DC6-6053113DD4F2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.1","matchCriteriaId":"9361A997-0735-41EB-B251-605E0174E602"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.1","matchCriteriaId":"6DFB4A63-4FE4-4499-8834-E6BCE8E9EF24"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/03/04/security-release-gitlab-11-dot-8-dot-1-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Product","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/52524","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/2019/03/04/security-release-gitlab-11-dot-8-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Product","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/52524","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-9176","sourceIdentifier":"cve@mitre.org","published":"2019-04-17T17:29:00.850","lastModified":"2026-06-17T02:43:12.143","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows CSRF."},{"lang":"es","value":"Se descubrió un problema en GitLab Community y Enterprise Edition en la versión anterior a 11.6.10, versión 11.7.x anterior a 11.7.6 y versión 11.8.x anterior a 11.8.1. Permite Cross Site Request Forgery (CSRF)."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:P","baseScore":5.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-352"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"11.6.10","matchCriteriaId":"13C741F9-E2E3-4C28-8331-F22BF96E6E95"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"11.6.10","matchCriteriaId":"4DF47DD3-57E7-40B1-BE2A-9041A083597B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.6","matchCriteriaId":"5D8490E0-F40D-479C-ADF9-6A8A6D1B4C31"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.6","matchCriteriaId":"A0143A98-2A68-45AE-9DC6-6053113DD4F2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.1","matchCriteriaId":"9361A997-0735-41EB-B251-605E0174E602"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.1","matchCriteriaId":"6DFB4A63-4FE4-4499-8834-E6BCE8E9EF24"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/03/04/security-release-gitlab-11-dot-8-dot-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/55664","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/2019/03/04/security-release-gitlab-11-dot-8-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/55664","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-9178","sourceIdentifier":"cve@mitre.org","published":"2019-04-17T17:29:00.927","lastModified":"2026-06-17T02:43:12.273","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Information Exposure (issue 4 of 5)."},{"lang":"es","value":"Se detecto un problema en GitLab Community and Enterprise Edition anterior a versión 11.6.10, versión 11.7.x anterior a 11.7.6 y versión 11.8.x anterior a 11.8.1. Permite la Exposición de Información (problema 4 de 5)."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"11.6.10","matchCriteriaId":"13C741F9-E2E3-4C28-8331-F22BF96E6E95"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"11.6.10","matchCriteriaId":"4DF47DD3-57E7-40B1-BE2A-9041A083597B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.6","matchCriteriaId":"5D8490E0-F40D-479C-ADF9-6A8A6D1B4C31"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.6","matchCriteriaId":"A0143A98-2A68-45AE-9DC6-6053113DD4F2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.1","matchCriteriaId":"9361A997-0735-41EB-B251-605E0174E602"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.1","matchCriteriaId":"6DFB4A63-4FE4-4499-8834-E6BCE8E9EF24"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/03/04/security-release-gitlab-11-dot-8-dot-1-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Product","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/54803","source":"cve@mitre.org","tags":["Exploit","Vendor Advisory"]},{"url":"https://about.gitlab.com/2019/03/04/security-release-gitlab-11-dot-8-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Product","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/54803","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-9179","sourceIdentifier":"cve@mitre.org","published":"2019-04-17T17:29:00.977","lastModified":"2026-06-17T02:43:12.413","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Information Exposure (issue 5 of 5)."},{"lang":"es","value":"Se detecto un problema en GitLab Community and Enterprise Edition anterior a versión 11.6.10, versión 11.7.x anterior a 11.7.6 y versión 11.8.x anterior a 11.8.1. Permite la Exposición de Información (problema 5 de 5)."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":3.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-200"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"11.6.10","matchCriteriaId":"13C741F9-E2E3-4C28-8331-F22BF96E6E95"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"11.6.10","matchCriteriaId":"4DF47DD3-57E7-40B1-BE2A-9041A083597B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.6","matchCriteriaId":"5D8490E0-F40D-479C-ADF9-6A8A6D1B4C31"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.6","matchCriteriaId":"A0143A98-2A68-45AE-9DC6-6053113DD4F2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.1","matchCriteriaId":"9361A997-0735-41EB-B251-605E0174E602"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.1","matchCriteriaId":"6DFB4A63-4FE4-4499-8834-E6BCE8E9EF24"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/03/04/security-release-gitlab-11-dot-8-dot-1-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Product","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/54783","source":"cve@mitre.org","tags":["Exploit","Vendor Advisory"]},{"url":"https://about.gitlab.com/2019/03/04/security-release-gitlab-11-dot-8-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Product","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/54783","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-9217","sourceIdentifier":"cve@mitre.org","published":"2019-04-17T17:29:01.037","lastModified":"2026-06-17T02:43:22.550","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. Its User Interface has a Misrepresentation of Critical Information."},{"lang":"es","value":"Se descubrió un problema en GitLab Community y Enterprise Edition versión  anterior a 11.6.10, versión 11.7.x anterior a 11.7.6 y versión 11.8.x anterior a 11.8.1. Su interfaz de usuario presenta una falsificación  de información crítica."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"11.6.10","matchCriteriaId":"13C741F9-E2E3-4C28-8331-F22BF96E6E95"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"11.6.10","matchCriteriaId":"4DF47DD3-57E7-40B1-BE2A-9041A083597B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.6","matchCriteriaId":"5D8490E0-F40D-479C-ADF9-6A8A6D1B4C31"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.6","matchCriteriaId":"A0143A98-2A68-45AE-9DC6-6053113DD4F2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.1","matchCriteriaId":"9361A997-0735-41EB-B251-605E0174E602"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.1","matchCriteriaId":"6DFB4A63-4FE4-4499-8834-E6BCE8E9EF24"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/03/04/security-release-gitlab-11-dot-8-dot-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/2019/03/04/security-release-gitlab-11-dot-8-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-9219","sourceIdentifier":"cve@mitre.org","published":"2019-04-17T17:29:01.100","lastModified":"2026-06-17T02:43:22.767","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control (issue 2 of 5)."},{"lang":"es","value":"Se descubrió un problema en GitLab Community and Enterprise Edition antes de 11.6.10, 11.7.x antes de 11.7.6 y 11.8.x antes de 11.8.1. Tiene control de acceso incorrecto (problema 2 de 5)."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":3.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-639"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"11.6.10","matchCriteriaId":"13C741F9-E2E3-4C28-8331-F22BF96E6E95"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"11.6.10","matchCriteriaId":"4DF47DD3-57E7-40B1-BE2A-9041A083597B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.6","matchCriteriaId":"5D8490E0-F40D-479C-ADF9-6A8A6D1B4C31"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.6","matchCriteriaId":"A0143A98-2A68-45AE-9DC6-6053113DD4F2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.1","matchCriteriaId":"9361A997-0735-41EB-B251-605E0174E602"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.1","matchCriteriaId":"6DFB4A63-4FE4-4499-8834-E6BCE8E9EF24"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/03/04/security-release-gitlab-11-dot-8-dot-1-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Product","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/54159","source":"cve@mitre.org","tags":["Exploit","Vendor Advisory"]},{"url":"https://about.gitlab.com/2019/03/04/security-release-gitlab-11-dot-8-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Product","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/54159","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-9220","sourceIdentifier":"cve@mitre.org","published":"2019-04-17T17:29:01.163","lastModified":"2026-06-17T02:43:22.883","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Uncontrolled Resource Consumption."},{"lang":"es","value":"Se descubrió un problema en GitLab Community and Enterprise Edition antes de 11.6.10, 11.7.x antes de 11.7.6 y 11.8.x antes de 11.8.1. Permite el consumo de recursos no controlados."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-400"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"11.6.10","matchCriteriaId":"13C741F9-E2E3-4C28-8331-F22BF96E6E95"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"11.6.10","matchCriteriaId":"4DF47DD3-57E7-40B1-BE2A-9041A083597B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.6","matchCriteriaId":"5D8490E0-F40D-479C-ADF9-6A8A6D1B4C31"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.6","matchCriteriaId":"A0143A98-2A68-45AE-9DC6-6053113DD4F2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.1","matchCriteriaId":"9361A997-0735-41EB-B251-605E0174E602"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.1","matchCriteriaId":"6DFB4A63-4FE4-4499-8834-E6BCE8E9EF24"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/03/04/security-release-gitlab-11-dot-8-dot-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/55653","source":"cve@mitre.org","tags":["Exploit","Vendor Advisory"]},{"url":"https://about.gitlab.com/2019/03/04/security-release-gitlab-11-dot-8-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/55653","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-9222","sourceIdentifier":"cve@mitre.org","published":"2019-04-17T17:29:01.227","lastModified":"2026-06-17T02:43:23.110","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Insecure Permissions."},{"lang":"es","value":"Se detecto un problema en GitLab Community and Enterprise Edition anterior a versión 11.6.10, versión 11.7.x anterior a 11.7.6 y versión 11.8.x anterior a 11.8.1. Presenta permisos no seguros."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.2}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:P","baseScore":5.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-22"},{"lang":"en","value":"CWE-732"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"11.6.10","matchCriteriaId":"13C741F9-E2E3-4C28-8331-F22BF96E6E95"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"11.6.10","matchCriteriaId":"4DF47DD3-57E7-40B1-BE2A-9041A083597B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.6","matchCriteriaId":"5D8490E0-F40D-479C-ADF9-6A8A6D1B4C31"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.6","matchCriteriaId":"A0143A98-2A68-45AE-9DC6-6053113DD4F2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.1","matchCriteriaId":"9361A997-0735-41EB-B251-605E0174E602"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.1","matchCriteriaId":"6DFB4A63-4FE4-4499-8834-E6BCE8E9EF24"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/03/04/security-release-gitlab-11-dot-8-dot-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/56348","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/2019/03/04/security-release-gitlab-11-dot-8-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/56348","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-9223","sourceIdentifier":"cve@mitre.org","published":"2019-04-17T17:29:01.320","lastModified":"2026-06-17T02:43:23.223","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Information Exposure."},{"lang":"es","value":"Se descubrió un problema en GitLab Community y Enterprise Edition anterior a la versión 11.6.10, 11.7.x anterior a la versión 11.7.6 y versión 11.8.x anterior a la versión11.8.1. Permite la exposición de la información."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-209"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"11.6.10","matchCriteriaId":"13C741F9-E2E3-4C28-8331-F22BF96E6E95"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"11.6.10","matchCriteriaId":"4DF47DD3-57E7-40B1-BE2A-9041A083597B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.6","matchCriteriaId":"5D8490E0-F40D-479C-ADF9-6A8A6D1B4C31"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.6","matchCriteriaId":"A0143A98-2A68-45AE-9DC6-6053113DD4F2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.1","matchCriteriaId":"9361A997-0735-41EB-B251-605E0174E602"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.1","matchCriteriaId":"6DFB4A63-4FE4-4499-8834-E6BCE8E9EF24"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/03/04/security-release-gitlab-11-dot-8-dot-1-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Product","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/50334","source":"cve@mitre.org","tags":["Exploit","Vendor Advisory"]},{"url":"https://about.gitlab.com/2019/03/04/security-release-gitlab-11-dot-8-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Product","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/50334","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-9224","sourceIdentifier":"cve@mitre.org","published":"2019-04-17T17:29:01.380","lastModified":"2026-06-17T02:43:23.333","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control (issue 4 of 5)."},{"lang":"es","value":"Se descubrió un problema en GitLab Community and Enterprise Edition antes de 11.6.10, 11.7.x antes de 11.7.6 y 11.8.x antes de 11.8.1. Tiene control de acceso incorrecto (problema 4 de 5)."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"11.6.10","matchCriteriaId":"13C741F9-E2E3-4C28-8331-F22BF96E6E95"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"11.6.10","matchCriteriaId":"4DF47DD3-57E7-40B1-BE2A-9041A083597B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.6","matchCriteriaId":"5D8490E0-F40D-479C-ADF9-6A8A6D1B4C31"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.6","matchCriteriaId":"A0143A98-2A68-45AE-9DC6-6053113DD4F2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.1","matchCriteriaId":"9361A997-0735-41EB-B251-605E0174E602"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.1","matchCriteriaId":"6DFB4A63-4FE4-4499-8834-E6BCE8E9EF24"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/03/04/security-release-gitlab-11-dot-8-dot-1-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Product","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/54789","source":"cve@mitre.org","tags":["Exploit","Vendor Advisory"]},{"url":"https://about.gitlab.com/2019/03/04/security-release-gitlab-11-dot-8-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Product","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/54789","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-9225","sourceIdentifier":"cve@mitre.org","published":"2019-04-17T17:29:01.460","lastModified":"2026-06-17T02:43:23.443","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control (issue 5 of 5)."},{"lang":"es","value":"Se descubrió un problema en GitLab Community and Enterprise Edition antes de 11.6.10, 11.7.x antes de 11.7.6 y 11.8.x antes de 11.8.1. Tiene control de acceso incorrecto (problema 5 de 5)."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-200"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"11.6.10","matchCriteriaId":"13C741F9-E2E3-4C28-8331-F22BF96E6E95"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"11.6.10","matchCriteriaId":"4DF47DD3-57E7-40B1-BE2A-9041A083597B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.6","matchCriteriaId":"5D8490E0-F40D-479C-ADF9-6A8A6D1B4C31"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.6","matchCriteriaId":"A0143A98-2A68-45AE-9DC6-6053113DD4F2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.1","matchCriteriaId":"9361A997-0735-41EB-B251-605E0174E602"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.1","matchCriteriaId":"6DFB4A63-4FE4-4499-8834-E6BCE8E9EF24"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/03/04/security-release-gitlab-11-dot-8-dot-1-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Product","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/54680","source":"cve@mitre.org","tags":["Exploit","Vendor Advisory"]},{"url":"https://about.gitlab.com/2019/03/04/security-release-gitlab-11-dot-8-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Product","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/54680","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-9756","sourceIdentifier":"cve@mitre.org","published":"2019-04-17T17:29:01.537","lastModified":"2026-06-17T02:44:17.680","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 10.x (starting from 10.8) and 11.x before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control, a different vulnerability than CVE-2019-9732."},{"lang":"es","value":"Se descubrió un problema en GitLab Community and Enterprise Edition versión 10.x (a partir de 10.8) y versión 11.x anterior a 11.6.10, versión 11.7.x anterior a 11.7.6 y versión  11.8.x anterior a 11.8.1. tiene un control de acceso, una vulnerabilidad diferente a la CVE-2019-9732."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-639"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.8.0","versionEndIncluding":"10.8.7","matchCriteriaId":"DCCDE6A4-EF92-4BCD-9C85-80EFE625B6B9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.8.0","versionEndIncluding":"10.8.7","matchCriteriaId":"51AEAE6C-AE4E-4570-B710-059A0E3358A7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"11.6.10","matchCriteriaId":"2CAC5A61-410C-4D6E-9CBC-21A02567CF7C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"11.6.10","matchCriteriaId":"43020A15-B3E3-46CD-A6D4-E75B121CAAD0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.1","matchCriteriaId":"9361A997-0735-41EB-B251-605E0174E602"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.1","matchCriteriaId":"6DFB4A63-4FE4-4499-8834-E6BCE8E9EF24"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/03/04/security-release-gitlab-11-dot-8-dot-1-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Product","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/54243","source":"cve@mitre.org","tags":["Exploit","Vendor Advisory"]},{"url":"https://about.gitlab.com/2019/03/04/security-release-gitlab-11-dot-8-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Product","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/54243","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-9890","sourceIdentifier":"cve@mitre.org","published":"2019-04-17T17:29:01.600","lastModified":"2026-06-17T02:44:47.740","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 10.x and 11.x before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Insecure Permissions."},{"lang":"es","value":"Se descubrió un problema en GitLab Community and Enterprise Edition 10.xy 11.x antes de 11.6.10, 11.7.x antes de 11.7.6 y 11.8.x antes de 11.8.1. Tiene permisos inseguros."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":5.2}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:N","baseScore":6.4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.0.0","versionEndExcluding":"11.6.10","matchCriteriaId":"FB11191D-ADCA-49CC-A767-A5218047A79B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.0.0","versionEndExcluding":"11.6.10","matchCriteriaId":"AAB862DA-CED4-44D4-BDB8-65899D9A6031"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.6","matchCriteriaId":"5D8490E0-F40D-479C-ADF9-6A8A6D1B4C31"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.6","matchCriteriaId":"A0143A98-2A68-45AE-9DC6-6053113DD4F2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.1","matchCriteriaId":"9361A997-0735-41EB-B251-605E0174E602"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.1","matchCriteriaId":"6DFB4A63-4FE4-4499-8834-E6BCE8E9EF24"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/03/04/security-release-gitlab-11-dot-8-dot-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/2019/03/04/security-release-gitlab-11-dot-8-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-18643","sourceIdentifier":"cve@mitre.org","published":"2019-04-25T21:29:00.230","lastModified":"2026-06-17T01:47:37.457","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab CE & EE 11.2 and later and before 11.5.0-rc12, 11.4.6, and 11.3.10 have Persistent XSS."},{"lang":"es","value":"GitLab CE & EE versiones posteriores a 11.2 y anteriores a 11.5.0-rc12, 11.4.6 y 11.3.10 tienen Cross-site scripting (XSS) persistente."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndIncluding":"11.2.0","matchCriteriaId":"C9A82A38-6C58-4A31-A1D5-3BFEAFBBB561"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndIncluding":"11.2.0","matchCriteriaId":"B62D1EE9-2102-473B-B4FE-1AC7E0BA766B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"11.3.10","matchCriteriaId":"1042EE83-B2CE-4D93-9626-D6AD9DFBEB94"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"11.3.10","matchCriteriaId":"5C5C32AE-87CD-4D3A-ABBF-817C80D4F428"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.6","matchCriteriaId":"924582FB-788D-4F9B-83E4-2A4BA0C2B324"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.6","matchCriteriaId":"8114049D-F534-4B9D-8268-3A78E4FEDCE8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.4.7","versionEndIncluding":"11.4.9","matchCriteriaId":"C45F8A7E-51C7-4025-A89D-A4988B6129CA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.4.7","versionEndIncluding":"11.4.9","matchCriteriaId":"23FF1E49-4108-4A87-B6DB-24A06EE38FC8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.5.0:-:*:*:community:*:*:*","matchCriteriaId":"525B6378-9CAA-4D92-8E93-B721E7849852"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.5.0:-:*:*:enterprise:*:*:*","matchCriteriaId":"19C42890-83FC-4954-8F1E-22EDA5E24E47"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.5.0:rc1:*:*:community:*:*:*","matchCriteriaId":"2771AED4-EF3A-4B69-AE53-722F24DEC0F7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.5.0:rc1:*:*:enterprise:*:*:*","matchCriteriaId":"CF1946E5-A778-4417-BC8A-13F5DF2F17FD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.5.0:rc10:*:*:community:*:*:*","matchCriteriaId":"901C4CD3-7096-4AD4-AF2B-B7F904F845F1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.5.0:rc10:*:*:enterprise:*:*:*","matchCriteriaId":"EC0D36DB-200D-45D8-80BB-2EB55367AC2F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.5.0:rc11:*:*:community:*:*:*","matchCriteriaId":"A2E38E49-90CD-451F-A7DF-19E502F1D4AA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.5.0:rc11:*:*:enterprise:*:*:*","matchCriteriaId":"B2CA2C1D-B7F3-47A4-83B6-5C5467C9EDC5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.5.0:rc2:*:*:community:*:*:*","matchCriteriaId":"98AD6AE7-FF89-4E11-AD5E-A6D3D20789CF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.5.0:rc2:*:*:enterprise:*:*:*","matchCriteriaId":"A3757C6F-2802-4FDE-88BA-E3B6507A107D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.5.0:rc3:*:*:community:*:*:*","matchCriteriaId":"44EB9698-6CDA-4BE5-8D85-096CC997F55C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.5.0:rc3:*:*:enterprise:*:*:*","matchCriteriaId":"144EBEE1-625F-4C06-B3CB-9018F6AFABBC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.5.0:rc4:*:*:community:*:*:*","matchCriteriaId":"531DB1D7-C42F-4E6F-868E-3FF480546E74"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.5.0:rc4:*:*:enterprise:*:*:*","matchCriteriaId":"2037B0C0-9AA7-41C0-9DD8-A6A8464A9DA3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.5.0:rc5:*:*:community:*:*:*","matchCriteriaId":"576B8B78-2CB7-417A-8AF0-B95446A023B4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.5.0:rc5:*:*:enterprise:*:*:*","matchCriteriaId":"3F2403AB-0172-4947-A0BA-453B56FFE9D5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.5.0:rc6:*:*:community:*:*:*","matchCriteriaId":"F9B3A25E-2C28-4DB6-9062-C70E23702EEE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.5.0:rc6:*:*:enterprise:*:*:*","matchCriteriaId":"51D42658-0268-40D7-9758-C6128C26AFA4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.5.0:rc7:*:*:community:*:*:*","matchCriteriaId":"3512110A-B085-48DD-9B12-014C6FF52E19"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.5.0:rc7:*:*:enterprise:*:*:*","matchCriteriaId":"5CCBBB31-EA36-408E-A3EA-81B19C022382"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.5.0:rc8:*:*:community:*:*:*","matchCriteriaId":"A7DDE6C4-278B-4EB7-9986-EEDEC7227B2D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.5.0:rc8:*:*:enterprise:*:*:*","matchCriteriaId":"D056FF6E-A733-430E-9DD2-E1C05745C06E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.5.0:rc9:*:*:community:*:*:*","matchCriteriaId":"2D479F97-2C00-44C3-88F3-5829DA3D559E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.5.0:rc9:*:*:enterprise:*:*:*","matchCriteriaId":"1BE4FF0C-CC41-4D99-9174-DEF5025063F9"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/11/19/critical-security-release-gitlab-11-dot-4-dot-6-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/53385","source":"cve@mitre.org","tags":["Patch","Vendor Advisory"]},{"url":"https://about.gitlab.com/2018/11/19/critical-security-release-gitlab-11-dot-4-dot-6-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/53385","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-19359","sourceIdentifier":"cve@mitre.org","published":"2019-04-25T21:29:00.353","lastModified":"2026-06-17T01:49:11.800","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab Community and Enterprise Edition 8.9 and later and before 11.5.0-rc12, 11.4.6, and 11.3.10 has Incorrect Access Control."},{"lang":"es","value":"GitLab Community y Enterprise Edition versiones posteriores a 8.9 y anteriores a 11.5.0-rc12, 11.4.6, y 11.3.10 tienen Control de Acceso Incorrecto."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"11.3.10","matchCriteriaId":"1042EE83-B2CE-4D93-9626-D6AD9DFBEB94"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"11.3.10","matchCriteriaId":"5C5C32AE-87CD-4D3A-ABBF-817C80D4F428"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.6","matchCriteriaId":"924582FB-788D-4F9B-83E4-2A4BA0C2B324"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.6","matchCriteriaId":"8114049D-F534-4B9D-8268-3A78E4FEDCE8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.4.7","versionEndIncluding":"11.4.9","matchCriteriaId":"C45F8A7E-51C7-4025-A89D-A4988B6129CA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.4.7","versionEndIncluding":"11.4.9","matchCriteriaId":"23FF1E49-4108-4A87-B6DB-24A06EE38FC8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.5.0:-:*:*:community:*:*:*","matchCriteriaId":"525B6378-9CAA-4D92-8E93-B721E7849852"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.5.0:-:*:*:enterprise:*:*:*","matchCriteriaId":"19C42890-83FC-4954-8F1E-22EDA5E24E47"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.5.0:rc1:*:*:community:*:*:*","matchCriteriaId":"2771AED4-EF3A-4B69-AE53-722F24DEC0F7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.5.0:rc1:*:*:enterprise:*:*:*","matchCriteriaId":"CF1946E5-A778-4417-BC8A-13F5DF2F17FD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.5.0:rc10:*:*:community:*:*:*","matchCriteriaId":"901C4CD3-7096-4AD4-AF2B-B7F904F845F1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.5.0:rc10:*:*:enterprise:*:*:*","matchCriteriaId":"EC0D36DB-200D-45D8-80BB-2EB55367AC2F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.5.0:rc11:*:*:community:*:*:*","matchCriteriaId":"A2E38E49-90CD-451F-A7DF-19E502F1D4AA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.5.0:rc11:*:*:enterprise:*:*:*","matchCriteriaId":"B2CA2C1D-B7F3-47A4-83B6-5C5467C9EDC5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.5.0:rc2:*:*:community:*:*:*","matchCriteriaId":"98AD6AE7-FF89-4E11-AD5E-A6D3D20789CF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.5.0:rc2:*:*:enterprise:*:*:*","matchCriteriaId":"A3757C6F-2802-4FDE-88BA-E3B6507A107D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.5.0:rc3:*:*:community:*:*:*","matchCriteriaId":"44EB9698-6CDA-4BE5-8D85-096CC997F55C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.5.0:rc3:*:*:enterprise:*:*:*","matchCriteriaId":"144EBEE1-625F-4C06-B3CB-9018F6AFABBC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.5.0:rc4:*:*:community:*:*:*","matchCriteriaId":"531DB1D7-C42F-4E6F-868E-3FF480546E74"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.5.0:rc4:*:*:enterprise:*:*:*","matchCriteriaId":"2037B0C0-9AA7-41C0-9DD8-A6A8464A9DA3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.5.0:rc5:*:*:community:*:*:*","matchCriteriaId":"576B8B78-2CB7-417A-8AF0-B95446A023B4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.5.0:rc5:*:*:enterprise:*:*:*","matchCriteriaId":"3F2403AB-0172-4947-A0BA-453B56FFE9D5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.5.0:rc6:*:*:community:*:*:*","matchCriteriaId":"F9B3A25E-2C28-4DB6-9062-C70E23702EEE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.5.0:rc6:*:*:enterprise:*:*:*","matchCriteriaId":"51D42658-0268-40D7-9758-C6128C26AFA4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.5.0:rc7:*:*:community:*:*:*","matchCriteriaId":"3512110A-B085-48DD-9B12-014C6FF52E19"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.5.0:rc7:*:*:enterprise:*:*:*","matchCriteriaId":"5CCBBB31-EA36-408E-A3EA-81B19C022382"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.5.0:rc8:*:*:community:*:*:*","matchCriteriaId":"A7DDE6C4-278B-4EB7-9986-EEDEC7227B2D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.5.0:rc8:*:*:enterprise:*:*:*","matchCriteriaId":"D056FF6E-A733-430E-9DD2-E1C05745C06E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.5.0:rc9:*:*:community:*:*:*","matchCriteriaId":"2D479F97-2C00-44C3-88F3-5829DA3D559E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.5.0:rc9:*:*:enterprise:*:*:*","matchCriteriaId":"1BE4FF0C-CC41-4D99-9174-DEF5025063F9"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/11/19/critical-security-release-gitlab-11-dot-4-dot-6-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/54189","source":"cve@mitre.org","tags":["Exploit","Patch"]},{"url":"https://about.gitlab.com/2018/11/19/critical-security-release-gitlab-11-dot-4-dot-6-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/54189","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Patch"]}]}},{"cve":{"id":"CVE-2019-11000","sourceIdentifier":"cve@mitre.org","published":"2019-05-10T20:29:00.367","lastModified":"2026-06-17T02:12:05.630","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Enterprise Edition before 11.7.11, 11.8.x before 11.8.7, and 11.9.x before 11.9.7. It allows Information Disclosure."},{"lang":"es","value":"Se descubrió un problema en GitLab Enterprise Edition antes de la versión 11.7.11, 11.8.x anterior a la versión 11.8.7, y 11.9.x anterior a 11.9.7. Permite la Divulgación de Información."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"11.7.11","matchCriteriaId":"DEE24F9D-6623-4D3A-AB86-FE99EAA1678C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.7","matchCriteriaId":"50DBAC10-BAC1-44E8-922E-F8C8670A224D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.9.0","versionEndExcluding":"11.9.7","matchCriteriaId":"6D980BD2-E0C2-4471-BCCF-1DFF4239B36C"}]}]}],"references":[{"url":"http://www.securityfocus.com/bid/108301","source":"cve@mitre.org","tags":["Broken Link","Third Party Advisory","VDB Entry"]},{"url":"https://about.gitlab.com/2019/04/10/critical-security-release-gitlab-11-dot-9-dot-7-released/","source":"cve@mitre.org","tags":["Broken Link","Release Notes","Third Party Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes"]},{"url":"http://www.securityfocus.com/bid/108301","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","VDB Entry"]},{"url":"https://about.gitlab.com/2019/04/10/critical-security-release-gitlab-11-dot-9-dot-7-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Release Notes","Third Party Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"]}]}},{"cve":{"id":"CVE-2019-10640","sourceIdentifier":"cve@mitre.org","published":"2019-05-15T19:29:00.257","lastModified":"2026-06-17T02:11:25.520","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.7.10, 11.8.x before 11.8.6, and 11.9.x before 11.9.4. A regex input validation issue for the .gitlab-ci.yml refs value allows Uncontrolled Resource Consumption."},{"lang":"es","value":"Se encontró un problema en GitLab Community and Enterprise Edition anterior11.7.10, 11.8.x anterior 11.8.6, and 11.9.x anterior 11.9.4.Un problema de validación de entrada de expresiones regulares para el valor de refs .gitlab-ci.yml permite el consumo de recursos no controlados."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-77"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"11.7.10","matchCriteriaId":"3BC16B2C-A133-46BA-BD16-9FDE2116E1E2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"11.7.10","matchCriteriaId":"5AC36F07-61F6-4611-827F-B1C915E29ECD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.6","matchCriteriaId":"ECECA9C3-55A4-4AAF-8555-0E1A1FBA88CF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.6","matchCriteriaId":"CAADC30C-E08D-4165-B0A4-B55234E45651"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.9.0","versionEndExcluding":"11.9.4","matchCriteriaId":"F90B9033-D2FE-4FEE-BCE0-654981548A1B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.9.0","versionEndExcluding":"11.9.4","matchCriteriaId":"FAA7C06F-4DF8-4113-BC6F-B582DFE5BD34"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/04/01/security-release-gitlab-11-dot-9-dot-4-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/49665","source":"cve@mitre.org","tags":["Exploit","Vendor Advisory"]},{"url":"https://about.gitlab.com/2019/04/01/security-release-gitlab-11-dot-9-dot-4-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/49665","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-10108","sourceIdentifier":"cve@mitre.org","published":"2019-05-15T20:29:00.243","lastModified":"2026-06-17T02:10:15.230","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An Incorrect Access Control (issue 1 of 2) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. It allowed non-members of a private project/group to add and read labels."},{"lang":"es","value":"Un control de acceso incorrecto ( problema 1 de 2) fue descubierto en GitLab Community and Enterprise Edition anterior 11.7.8, 11.8.x anterior 11.8.4, and 11.9.x anterior 11.9.2, esto permitió a los no miembros de un grupo o proyecto privado añadir y leer etiquetas."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.5}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:N","baseScore":5.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-639"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"11.7.8","matchCriteriaId":"6512499B-A054-44FD-B233-18FDB4352149"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"11.7.8","matchCriteriaId":"5F337BCF-E927-4F9A-B578-8D3BF4BF1BA0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.4","matchCriteriaId":"75395889-A145-4027-B09A-C79558A6FCBE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.4","matchCriteriaId":"5BEABDC6-7DCC-4C95-8CD7-8F834F2EF5FD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.9.0","versionEndExcluding":"11.9.2","matchCriteriaId":"54A0F503-7F38-401F-AC54-E5E10CFC1B1D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.9.0","versionEndExcluding":"11.9.2","matchCriteriaId":"B6F651B7-7BAD-4247-9E27-BA0FC363C718"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/04/01/security-release-gitlab-11-dot-9-dot-4-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/56985","source":"cve@mitre.org","tags":["Exploit","Vendor Advisory"]},{"url":"https://about.gitlab.com/2019/04/01/security-release-gitlab-11-dot-9-dot-4-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/56985","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-10109","sourceIdentifier":"cve@mitre.org","published":"2019-05-15T20:29:00.367","lastModified":"2026-06-17T02:10:15.360","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An Information Exposure issue (issue 1 of 2) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. EXIF geolocation data were not removed from images when uploaded to GitLab. As a result, anyone with access to the uploaded image could obtain its geolocation, device, and software version data (if present)."},{"lang":"es","value":"Se descubrió un problema de exposición a la información ( problema 1 de 2) en GitLab Community and Enterprise Edition antes de 11.7.8, 11.8.x antes de 11.8.4 y 11.9.x antes de 11.9.2. Los datos de geolocalización EXIF no se eliminaron de las imágenes cuando se cargaron en GitLab. Como resultado, cualquier persona con acceso a la imagen cargada podría obtener sus datos de geolocalización, dispositivo y versión de software (si está presente)"}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-200"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"11.7.8","matchCriteriaId":"6512499B-A054-44FD-B233-18FDB4352149"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"11.7.8","matchCriteriaId":"5F337BCF-E927-4F9A-B578-8D3BF4BF1BA0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.4","matchCriteriaId":"75395889-A145-4027-B09A-C79558A6FCBE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.4","matchCriteriaId":"5BEABDC6-7DCC-4C95-8CD7-8F834F2EF5FD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.9.0","versionEndExcluding":"11.9.2","matchCriteriaId":"54A0F503-7F38-401F-AC54-E5E10CFC1B1D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.9.0","versionEndExcluding":"11.9.2","matchCriteriaId":"B6F651B7-7BAD-4247-9E27-BA0FC363C718"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/04/01/security-release-gitlab-11-dot-9-dot-4-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/54220","source":"cve@mitre.org","tags":["Exploit","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/55469","source":"cve@mitre.org","tags":["Exploit","Vendor Advisory"]},{"url":"https://about.gitlab.com/2019/04/01/security-release-gitlab-11-dot-9-dot-4-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/54220","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/55469","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-10110","sourceIdentifier":"cve@mitre.org","published":"2019-05-15T20:29:00.523","lastModified":"2026-06-17T02:10:15.500","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An Insecure Permissions issue (issue 1 of 3) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. The \"move issue\" feature may allow a user to create projects under any namespace on any GitLab instance on which they hold credentials."},{"lang":"es","value":"Se detecto un problema de permisos no seguros en GitLab Community and Enterprise Edition anterior 11.7.8, 11.8.x anterior 11.8.4, y anterior 11.9.2. La función \"move issue\" puede permitir a un usuario crear proyectos bajo cualquier espacio de nombres en cualquier instancia de GitLab en el que tienen credenciales."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-732"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"11.7.8","matchCriteriaId":"6512499B-A054-44FD-B233-18FDB4352149"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"11.7.8","matchCriteriaId":"5F337BCF-E927-4F9A-B578-8D3BF4BF1BA0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.4","matchCriteriaId":"75395889-A145-4027-B09A-C79558A6FCBE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.4","matchCriteriaId":"5BEABDC6-7DCC-4C95-8CD7-8F834F2EF5FD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.9.0","versionEndExcluding":"11.9.2","matchCriteriaId":"54A0F503-7F38-401F-AC54-E5E10CFC1B1D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.9.0","versionEndExcluding":"11.9.2","matchCriteriaId":"B6F651B7-7BAD-4247-9E27-BA0FC363C718"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/04/01/security-release-gitlab-11-dot-9-dot-4-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/56865","source":"cve@mitre.org","tags":["Exploit","Vendor Advisory"]},{"url":"https://about.gitlab.com/2019/04/01/security-release-gitlab-11-dot-9-dot-4-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/56865","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-10111","sourceIdentifier":"cve@mitre.org","published":"2019-05-15T20:29:00.650","lastModified":"2026-06-17T02:10:15.633","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. It allows persistent XSS in the merge request \"resolve conflicts\" page."},{"lang":"es","value":"Se descubrió un problermaff en GitLab Community and Enterprise Edition anterior a la versión  11.7.8, versión 11.8.x anterior a la 11.8.4 y versión 11.9.x anterior a la 11.9.2. Permite XSS continuo en la página de solicitud de fusión \"resolve conflicts\"."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"11.7.8","matchCriteriaId":"6512499B-A054-44FD-B233-18FDB4352149"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"11.7.8","matchCriteriaId":"5F337BCF-E927-4F9A-B578-8D3BF4BF1BA0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.4","matchCriteriaId":"75395889-A145-4027-B09A-C79558A6FCBE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.4","matchCriteriaId":"5BEABDC6-7DCC-4C95-8CD7-8F834F2EF5FD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.9.0","versionEndExcluding":"11.9.2","matchCriteriaId":"54A0F503-7F38-401F-AC54-E5E10CFC1B1D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.9.0","versionEndExcluding":"11.9.2","matchCriteriaId":"B6F651B7-7BAD-4247-9E27-BA0FC363C718"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/04/01/security-release-gitlab-11-dot-9-dot-4-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/56927","source":"cve@mitre.org","tags":["Exploit","Vendor Advisory"]},{"url":"https://about.gitlab.com/2019/04/01/security-release-gitlab-11-dot-9-dot-4-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/56927","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-10113","sourceIdentifier":"cve@mitre.org","published":"2019-05-16T15:29:00.740","lastModified":"2026-06-17T02:10:15.890","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. Making concurrent GET /api/v4/projects/<id>/languages requests may allow Uncontrolled Resource Consumption."},{"lang":"es","value":"Fue encontrado un problema en GitLab Community and Enterprise Edition anterior de la versión 11.7.8, versión 11.8.x anterior de 11.8.4 y versión 11.9.x anterior de 11.9.2. El  realizar solicitudes concurrentes GET/api/v4/projects//languages   puede permitir el Consumo de recursos no controlado."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-400"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"11.7.8","matchCriteriaId":"6512499B-A054-44FD-B233-18FDB4352149"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"11.7.8","matchCriteriaId":"5F337BCF-E927-4F9A-B578-8D3BF4BF1BA0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.4","matchCriteriaId":"75395889-A145-4027-B09A-C79558A6FCBE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.4","matchCriteriaId":"5BEABDC6-7DCC-4C95-8CD7-8F834F2EF5FD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.9.0","versionEndExcluding":"11.9.2","matchCriteriaId":"54A0F503-7F38-401F-AC54-E5E10CFC1B1D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.9.0","versionEndExcluding":"11.9.2","matchCriteriaId":"B6F651B7-7BAD-4247-9E27-BA0FC363C718"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/04/01/security-release-gitlab-11-dot-9-dot-4-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/54977","source":"cve@mitre.org","tags":["Exploit","Vendor Advisory"]},{"url":"https://about.gitlab.com/2019/04/01/security-release-gitlab-11-dot-9-dot-4-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/54977","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-10114","sourceIdentifier":"cve@mitre.org","published":"2019-05-16T15:29:00.850","lastModified":"2026-06-17T02:10:16.013","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An Information Exposure issue (issue 2 of 2) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. During the OAuth authentication process, the application attempts to validate a parameter in an insecure way, potentially exposing data."},{"lang":"es","value":"Fue encontrado un problema de exposición de información (problema 2 de 2) en GitLab Community and Enterprise Edition anterior de la versión 11.7.8, versión 11.8.x anterior de 11.8.4 y versión 11.9.x anterior de 11.9.2. Durante el proceso de autorización de OAuth, la aplicación intenta comprobar un parámetro de forma no segura, exponiendo potencialmente los datos."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-203"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"11.7.8","matchCriteriaId":"6512499B-A054-44FD-B233-18FDB4352149"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"11.7.8","matchCriteriaId":"5F337BCF-E927-4F9A-B578-8D3BF4BF1BA0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.4","matchCriteriaId":"75395889-A145-4027-B09A-C79558A6FCBE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.4","matchCriteriaId":"5BEABDC6-7DCC-4C95-8CD7-8F834F2EF5FD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.9.0","versionEndExcluding":"11.9.2","matchCriteriaId":"54A0F503-7F38-401F-AC54-E5E10CFC1B1D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.9.0","versionEndExcluding":"11.9.2","matchCriteriaId":"B6F651B7-7BAD-4247-9E27-BA0FC363C718"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/04/01/security-release-gitlab-11-dot-9-dot-4-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ee/issues/9729","source":"cve@mitre.org","tags":["Exploit","Vendor Advisory"]},{"url":"https://about.gitlab.com/2019/04/01/security-release-gitlab-11-dot-9-dot-4-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ee/issues/9729","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-10115","sourceIdentifier":"cve@mitre.org","published":"2019-05-16T15:29:00.990","lastModified":"2026-06-17T02:10:16.140","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An Insecure Permissions issue (issue 2 of 3) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. The GitLab Releases feature could allow guest users access to private information like release details and code information."},{"lang":"es","value":"Fue encontrado un problema de permisos no seguros (problema 2 de 3) en GitLab Community and Enterprise Edition anterior de la versión 11.7.8, versión 11.8.x anterior de 11.8.4 y versión 11.9.x anterior de 11.9.2. La función  GitLab Releases podría permitir a los usuarios invitados acceder a información privada como detalles de versiones e información de código."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-732"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"11.7.8","matchCriteriaId":"6512499B-A054-44FD-B233-18FDB4352149"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"11.7.8","matchCriteriaId":"5F337BCF-E927-4F9A-B578-8D3BF4BF1BA0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.4","matchCriteriaId":"75395889-A145-4027-B09A-C79558A6FCBE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.4","matchCriteriaId":"5BEABDC6-7DCC-4C95-8CD7-8F834F2EF5FD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.9.0","versionEndExcluding":"11.9.2","matchCriteriaId":"54A0F503-7F38-401F-AC54-E5E10CFC1B1D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.9.0","versionEndExcluding":"11.9.2","matchCriteriaId":"B6F651B7-7BAD-4247-9E27-BA0FC363C718"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/04/01/security-release-gitlab-11-dot-9-dot-4-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/56402","source":"cve@mitre.org","tags":["Exploit","Vendor Advisory"]},{"url":"https://about.gitlab.com/2019/04/01/security-release-gitlab-11-dot-9-dot-4-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/56402","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-10116","sourceIdentifier":"cve@mitre.org","published":"2019-05-16T15:29:01.130","lastModified":"2026-06-17T02:10:16.270","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An Insecure Permissions issue (issue 3 of 3) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. Guests of a project were allowed to see Related Branches created for an issue."},{"lang":"es","value":"Se detectó un problema de permisos no seguros (número 3 de 3) en GitLab Community and Enterprise Edition versión anterior a 11.7.8,  versión 11.8.x anterior a 11.8.4 y versión 11.9.x anterior a 11.9.2. A los invitados de un proyecto se les permitió ver Branches relacionadas creadas para un problema."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-732"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"11.7.8","matchCriteriaId":"6512499B-A054-44FD-B233-18FDB4352149"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"11.7.8","matchCriteriaId":"5F337BCF-E927-4F9A-B578-8D3BF4BF1BA0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.4","matchCriteriaId":"75395889-A145-4027-B09A-C79558A6FCBE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.4","matchCriteriaId":"5BEABDC6-7DCC-4C95-8CD7-8F834F2EF5FD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.9.0","versionEndExcluding":"11.9.2","matchCriteriaId":"54A0F503-7F38-401F-AC54-E5E10CFC1B1D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.9.0","versionEndExcluding":"11.9.2","matchCriteriaId":"B6F651B7-7BAD-4247-9E27-BA0FC363C718"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/04/01/security-release-gitlab-11-dot-9-dot-4-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/56224","source":"cve@mitre.org","tags":["Broken Link"]},{"url":"https://about.gitlab.com/2019/04/01/security-release-gitlab-11-dot-9-dot-4-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/56224","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2019-10117","sourceIdentifier":"cve@mitre.org","published":"2019-05-16T15:29:01.257","lastModified":"2026-06-17T02:10:16.397","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An Open Redirect issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. A redirect is triggered after successful authentication within the Oauth/:GeoAuthController for the secondary Geo node."},{"lang":"es","value":"Fue encontrado un problema de Redireccionamiento abierto en GitLab Community and Enterprise Edition anterior de la versión 11.7.8, versión 11.8.x anterior de 11.8.4 y versión 11.9.x anterior de 11.9.2. Es activada una redirección después de una autorización con éxito  dentro de Oauth/:GeoAuthController para el nodo secundario  Geo."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:N","baseScore":5.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-601"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"11.7.8","matchCriteriaId":"6512499B-A054-44FD-B233-18FDB4352149"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"11.7.8","matchCriteriaId":"5F337BCF-E927-4F9A-B578-8D3BF4BF1BA0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.4","matchCriteriaId":"75395889-A145-4027-B09A-C79558A6FCBE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.4","matchCriteriaId":"5BEABDC6-7DCC-4C95-8CD7-8F834F2EF5FD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.9.0","versionEndExcluding":"11.9.2","matchCriteriaId":"54A0F503-7F38-401F-AC54-E5E10CFC1B1D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.9.0","versionEndExcluding":"11.9.2","matchCriteriaId":"B6F651B7-7BAD-4247-9E27-BA0FC363C718"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/04/01/security-release-gitlab-11-dot-9-dot-4-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ee/issues/9731","source":"cve@mitre.org","tags":["Exploit","Vendor Advisory"]},{"url":"https://about.gitlab.com/2019/04/01/security-release-gitlab-11-dot-9-dot-4-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ee/issues/9731","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-10112","sourceIdentifier":"cve@mitre.org","published":"2019-05-16T16:29:02.243","lastModified":"2026-06-17T02:10:15.760","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. The construction of the HMAC key was insecurely derived."},{"lang":"es","value":"Fue encontrado un problema en GitLab Community and Enterprise Edition anterior de la versión 11.7.8, versión 11.8.x anterior de 11.8.4 y versión 11.9.x anterior de 11.9.2. La construcción de la clave HMAC fue derivada inseguramente."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-326"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"11.7.8","matchCriteriaId":"6512499B-A054-44FD-B233-18FDB4352149"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"11.7.8","matchCriteriaId":"5F337BCF-E927-4F9A-B578-8D3BF4BF1BA0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.4","matchCriteriaId":"75395889-A145-4027-B09A-C79558A6FCBE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.4","matchCriteriaId":"5BEABDC6-7DCC-4C95-8CD7-8F834F2EF5FD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.9.0","versionEndExcluding":"11.9.2","matchCriteriaId":"54A0F503-7F38-401F-AC54-E5E10CFC1B1D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.9.0","versionEndExcluding":"11.9.2","matchCriteriaId":"B6F651B7-7BAD-4247-9E27-BA0FC363C718"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/04/01/security-release-gitlab-11-dot-9-dot-4-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ee/issues/9730","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory"]},{"url":"https://about.gitlab.com/2019/04/01/security-release-gitlab-11-dot-9-dot-4-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ee/issues/9730","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2018-19585","sourceIdentifier":"cve@mitre.org","published":"2019-05-17T16:29:00.547","lastModified":"2026-06-17T01:49:33.583","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab CE/EE versions 8.18 up to 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1 have CRLF Injection in Project Mirroring when using the Git protocol."},{"lang":"es","value":"En GitLab CE/EE en versiones desde 8.18 hasta 11.x anteriores a 11.3.11, 11.4.x anteriores a 11.4.8 y 11.5.x anteriores de 11.5.1, tienen inyección de CRLF en Project Mirroring cuando se utiliza el protocolo Git."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-93"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.18.0","versionEndExcluding":"11.3.11","matchCriteriaId":"9FF933E9-B7F7-4DE8-80DD-AE1B4972EB85"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.18.0","versionEndExcluding":"11.3.11","matchCriteriaId":"AC7CFA1D-DE73-4A1A-8B2B-5835BD12CADD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.8","matchCriteriaId":"0856E99E-FEE4-4FFB-BB6F-3F28E062617E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.8","matchCriteriaId":"9BD01839-392A-450C-BC58-B56FE387A19F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.1","matchCriteriaId":"5EC4D9F2-9926-42EF-9CDA-90C3551D02C8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.1","matchCriteriaId":"58C8B864-1771-4938-B4E7-8BBFE2706A46"}]}]}],"references":[{"url":"http://packetstormsecurity.com/files/160516/GitLab-11.4.7-Remote-Code-Execution.html","source":"cve@mitre.org"},{"url":"http://packetstormsecurity.com/files/160699/GitLab-11.4.7-Remote-Code-Execution.html","source":"cve@mitre.org"},{"url":"https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"http://packetstormsecurity.com/files/160516/GitLab-11.4.7-Remote-Code-Execution.html","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://packetstormsecurity.com/files/160699/GitLab-11.4.7-Remote-Code-Execution.html","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-20500","sourceIdentifier":"cve@mitre.org","published":"2019-05-17T16:29:00.640","lastModified":"2026-06-17T01:52:58.853","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An insecure permissions issue was discovered in GitLab Community and Enterprise Edition 9.4 and later but before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. The runner registration token in the CI/CD settings could not be reset. This was a security risk if one of the maintainers leaves the group and they know the token."},{"lang":"es","value":"Fue descubierto un problema con los permisos inseguros en GitLab Community and Enterprise Edition 9.4 y versiones superiores, anteriores a 11.4.13, 11.5.x anteriores a 11.5.6 y 11.6.x anteriores a 11.6.1. El Runner Registration Token en la configuración de CI/CD no se pudo restablecer. Esto fue un riesgo de seguridad si uno de los mantenedores deja el grupo y ellos conocen el token."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-732"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"9.4.0","versionEndExcluding":"11.4.13","matchCriteriaId":"2D22FA16-5F1D-4FBA-8DB3-E2AE4476DDFA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"9.4.0","versionEndExcluding":"11.4.13","matchCriteriaId":"54B3C2DA-1CEE-4DFD-B2AA-F98BE7D9447E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.6","matchCriteriaId":"555DAC6F-1C9E-4D4E-9100-35DDFD320F51"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.6","matchCriteriaId":"584CB55D-C412-4C8A-91A6-B0FB0632D4DF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.1","matchCriteriaId":"BF95CB5A-17FF-413D-BD1E-6D4470E5A7F8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.1","matchCriteriaId":"7B939578-9F4C-4EB0-8FCC-5A9F64109788"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/12/31/security-release-gitlab-11-dot-6-dot-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/2018/12/31/security-release-gitlab-11-dot-6-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-5883","sourceIdentifier":"cve@mitre.org","published":"2019-05-17T16:29:03.547","lastModified":"2026-06-17T02:38:22.800","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An Incorrect Access Control issue was discovered in GitLab Community and Enterprise Edition 6.0 and later but before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. The issue comments feature could allow a user to comment on an issue which they shouldn't be allowed to."},{"lang":"es","value":"Fue descubierto un problema de Control de Acceso Incorrecto en GitLab Community y Enterprise Edition 6.0 y superior, pero antes de 11.3.11, 11.4.x antes de 11.4.8 y 11.5.x antes de 11.5.1. La función de comentarios defectuosa podría admitirle a un usuario comentar sobre un problema que no se le debería admitir."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":5.2}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:N","baseScore":6.4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"6.0.0","versionEndExcluding":"11.3.11","matchCriteriaId":"6E30517E-6BC0-4491-A5E5-0923944121DA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"6.0.0","versionEndExcluding":"11.3.11","matchCriteriaId":"CA11B7E3-982A-443B-BE41-F8CA61597D95"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.8","matchCriteriaId":"0856E99E-FEE4-4FFB-BB6F-3F28E062617E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.8","matchCriteriaId":"9BD01839-392A-450C-BC58-B56FE387A19F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.1","matchCriteriaId":"5EC4D9F2-9926-42EF-9CDA-90C3551D02C8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.1","matchCriteriaId":"58C8B864-1771-4938-B4E7-8BBFE2706A46"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-6781","sourceIdentifier":"cve@mitre.org","published":"2019-05-17T16:29:05.797","lastModified":"2026-06-17T02:39:40.053","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An Improper Input Validation issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It was possible to use the profile name to inject a potentially malicious link into notification emails."},{"lang":"es","value":"Se descubrió un problema de validación de entrada incorrecta en GitLab Community and Enterprise Edition antes de 11.5.8, 11.6.x antes de 11.6.6 y 11.7.x antes de 11.7.1. Fue posible usar el nombre del perfil para inyectar un enlace potencialmente malicioso en los correos electrónicos de notificación."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-601"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.10","matchCriteriaId":"F9D0E111-E5B9-424E-9AED-5454C6B35C68"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.10","matchCriteriaId":"4722475B-87B9-4925-9376-1E5EE5B7EF9A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.8","matchCriteriaId":"0EEB5737-D927-4402-BC6F-632B5A50E399"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.8","matchCriteriaId":"FB9B65A4-C7B6-4256-B981-8F7507F7A51B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.3","matchCriteriaId":"D59D368F-5161-44BA-9FA5-C813331F4A8E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.3","matchCriteriaId":"E02EB0FA-634F-4D73-A07B-79EEF3390D46"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/22076","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/22076","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-6787","sourceIdentifier":"cve@mitre.org","published":"2019-05-17T16:29:05.860","lastModified":"2026-06-17T02:39:40.767","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An Incorrect Access Control issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. The GitLab API allowed project Maintainers and Owners to view the trigger tokens of other project users."},{"lang":"es","value":"Se descubrió un problema de control de acceso incorrecto en GitLab Community and Enterprise Edition antes de 11.5.8, 11.6.x antes de 11.6.6 y 11.7.x antes de 11.7.1. La API de GitLab permitió a los mantenedores y propietarios del proyecto ver los tokens de activación de otros usuarios del proyecto."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.12.0","versionEndExcluding":"11.5.8","matchCriteriaId":"22493E0B-31B0-4DD2-B084-6D928939FA51"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.12.0","versionEndExcluding":"11.5.8","matchCriteriaId":"19CE5719-37C9-4B45-AE1B-628C15C203E7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.6","matchCriteriaId":"794CA42E-5409-455B-956C-21BC431E0B98"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.6","matchCriteriaId":"35A01A1A-A0F1-4952-B15A-A898FD185B3F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.1","matchCriteriaId":"3BAE4B6C-8F1F-4C42-ADF9-A9CBD3895C68"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.1","matchCriteriaId":"3A67FE77-4048-41B8-8734-CA62393ED632"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-6790","sourceIdentifier":"cve@mitre.org","published":"2019-05-17T16:29:05.940","lastModified":"2026-06-17T02:39:41.193","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An Incorrect Access Control (issue 2 of 3) issue was discovered in GitLab Community and Enterprise Edition 8.14 and later but before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. Guest users were able to view the list of a group's merge requests."},{"lang":"es","value":"Se detectó un problema de control de acceso incorrecto (problema 2 de 3) en GitLab Community and Enterprise Edition 8.14 y versiones posteriores, pero antes de 11.5.8, 11.6.x antes de 11.6.6 y 11.7.x antes de 11.7.1. Los usuarios invitados pudieron ver la lista de solicitudes de combinación de un grupo."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.14.0","versionEndExcluding":"11.5.8","matchCriteriaId":"7E1816E5-ED12-4F21-8B1E-C5F4E720C8F4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.14.0","versionEndExcluding":"11.5.8","matchCriteriaId":"5F1AC428-E804-49AB-B7A6-91F96F227A4B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.6","matchCriteriaId":"794CA42E-5409-455B-956C-21BC431E0B98"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.6","matchCriteriaId":"35A01A1A-A0F1-4952-B15A-A898FD185B3F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.1","matchCriteriaId":"3BAE4B6C-8F1F-4C42-ADF9-A9CBD3895C68"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.1","matchCriteriaId":"3A67FE77-4048-41B8-8734-CA62393ED632"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/51328","source":"cve@mitre.org"},{"url":"https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/51328","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2019-6797","sourceIdentifier":"cve@mitre.org","published":"2019-05-17T16:29:06.017","lastModified":"2026-06-17T02:39:41.990","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An information disclosure issue was discovered in GitLab Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. The GitHub token used in CI/CD for External Repos was being leaked to project maintainers in the UI."},{"lang":"es","value":"Se descubrió un problema de divulgación de información en GitLab Enterprise Edition antes de 11.5.8, 11.6.x antes de 11.6.6 y 11.7.x antes de 11.7.1. El token de GitHub utilizado en CI/CD para reposiciones externas se estaba filtrando a los mantenedores del proyecto en la interfaz de usuario."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"11.5.8","matchCriteriaId":"5CAB52EA-9EE4-424C-80D8-0987AEDE045E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.6","matchCriteriaId":"35A01A1A-A0F1-4952-B15A-A898FD185B3F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.1","matchCriteriaId":"3A67FE77-4048-41B8-8734-CA62393ED632"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-7353","sourceIdentifier":"cve@mitre.org","published":"2019-05-17T17:29:00.920","lastModified":"2026-06-17T02:40:30.633","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An Incorrect Access Control issue was discovered in GitLab Community and Enterprise Edition 11.7.x before 11.7.4. GitLab Releases were vulnerable to an authorization issue that allowed users to view confidential issue and merge request titles of other projects."},{"lang":"es","value":"Se descubrió un problema de control de acceso incorrecto en GitLab Community y Enterprise Edition 11.7.x antes de 11.7.4. Los lanzamientos de GitLab eran vulnerables a un problema de autorización que permitía a los usuarios ver los temas confidenciales y fusionar títulos de solicitud de otros proyectos."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":5.2}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:N","baseScore":6.4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-200"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.4","matchCriteriaId":"F4DDAC5E-2629-49E7-B534-E1B35A102E5B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.4","matchCriteriaId":"1A63BC61-F6C2-49B7-9BF1-3AB162396416"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/02/05/critical-security-release-gitlab-11-dot-7-dot-4-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/56568","source":"cve@mitre.org"},{"url":"https://about.gitlab.com/2019/02/05/critical-security-release-gitlab-11-dot-7-dot-4-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/56568","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2019-7549","sourceIdentifier":"cve@mitre.org","published":"2019-05-29T16:29:01.107","lastModified":"2026-06-17T02:40:41.117","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 10.x and 11.x before 11.5.10, 11.6.x before 11.6.8, and 11.7.x before 11.7.3. It has Incorrect Access Control. The GitLab pipelines feature is vulnerable to authorization issues that allow unauthorized users to view job information."},{"lang":"es","value":"Se detecto un problema en GitLab Community and Enterprise Edition versiones 10.x y 11.x en versiones anteriores a la 11.5.10, versión 11.6.x en versiones anteriores a la 11.6.8, y versión 11.7.x en versiones anteriores a la 11.7.3. Presenta un control de acceso incorrecto. La función pipelines de GitLab es vulnerable a problemas de autorización que permiten a usuarios no autorizados ver información sobre el trabajo."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.0.0","versionEndExcluding":"11.5.10","matchCriteriaId":"6D822ABE-9658-4E0B-9DF8-9660380A6636"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.0.0","versionEndExcluding":"11.5.10","matchCriteriaId":"E73AC3DE-3F90-4485-AFA2-67488B81477F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.8","matchCriteriaId":"0EEB5737-D927-4402-BC6F-632B5A50E399"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.8","matchCriteriaId":"FB9B65A4-C7B6-4256-B981-8F7507F7A51B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.3","matchCriteriaId":"D59D368F-5161-44BA-9FA5-C813331F4A8E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.3","matchCriteriaId":"E02EB0FA-634F-4D73-A07B-79EEF3390D46"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/54358","source":"cve@mitre.org"},{"url":"https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/54358","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2019-9218","sourceIdentifier":"cve@mitre.org","published":"2019-05-29T16:29:01.217","lastModified":"2026-06-17T02:43:22.660","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control (issue 1 of 5)."},{"lang":"es","value":"Fue encontrado un problema en GitLab Community and Enterprise Edition versión anterior de 11.6.10,  versión 11.7.x anterior de 11.7.6 y  versión 11.8.x anterior de 11.8.1. Tiene control de acceso incorrecto (problema 1 de 5)."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"11.6.10","matchCriteriaId":"13C741F9-E2E3-4C28-8331-F22BF96E6E95"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"11.6.10","matchCriteriaId":"4DF47DD3-57E7-40B1-BE2A-9041A083597B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.6","matchCriteriaId":"5D8490E0-F40D-479C-ADF9-6A8A6D1B4C31"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.6","matchCriteriaId":"A0143A98-2A68-45AE-9DC6-6053113DD4F2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.1","matchCriteriaId":"9361A997-0735-41EB-B251-605E0174E602"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.1","matchCriteriaId":"6DFB4A63-4FE4-4499-8834-E6BCE8E9EF24"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-9221","sourceIdentifier":"cve@mitre.org","published":"2019-05-29T17:29:00.460","lastModified":"2026-06-17T02:43:23.000","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control (issue 3 of 5)."},{"lang":"es","value":"Fue encontrado un problema en GitLab Community and Enterprise Edition anterior a la versión 11.6.10, versión 11.7.x anteriores a 11.7.6 y versión 11.8.x anteriores a 11.8.1. Presenta un control de acceso incorrecto (problema 3 de 5)."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:N/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-20"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"11.6.10","matchCriteriaId":"13C741F9-E2E3-4C28-8331-F22BF96E6E95"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"11.6.10","matchCriteriaId":"4DF47DD3-57E7-40B1-BE2A-9041A083597B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.6","matchCriteriaId":"5D8490E0-F40D-479C-ADF9-6A8A6D1B4C31"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.6","matchCriteriaId":"A0143A98-2A68-45AE-9DC6-6053113DD4F2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.1","matchCriteriaId":"9361A997-0735-41EB-B251-605E0174E602"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.1","matchCriteriaId":"6DFB4A63-4FE4-4499-8834-E6BCE8E9EF24"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/03/04/security-release-gitlab-11-dot-8-dot-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/2019/03/04/security-release-gitlab-11-dot-8-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-9485","sourceIdentifier":"cve@mitre.org","published":"2019-05-29T17:29:00.507","lastModified":"2026-06-17T02:43:48.057","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Insecure Permissions."},{"lang":"es","value":"Fue encontrado un problema en GitLab Community and Enterprise Edition anteriores a la versión 11.6.10, versión 11.7.x anteriores a 11.7.6 y versión 11.8.x anteriores a 11.8.1. Presenta permisos no seguros."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"11.6.10","matchCriteriaId":"13C741F9-E2E3-4C28-8331-F22BF96E6E95"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"11.6.10","matchCriteriaId":"4DF47DD3-57E7-40B1-BE2A-9041A083597B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.6","matchCriteriaId":"5D8490E0-F40D-479C-ADF9-6A8A6D1B4C31"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.6","matchCriteriaId":"A0143A98-2A68-45AE-9DC6-6053113DD4F2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.1","matchCriteriaId":"9361A997-0735-41EB-B251-605E0174E602"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.1","matchCriteriaId":"6DFB4A63-4FE4-4499-8834-E6BCE8E9EF24"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/03/04/security-release-gitlab-11-dot-8-dot-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/2019/03/04/security-release-gitlab-11-dot-8-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-9732","sourceIdentifier":"cve@mitre.org","published":"2019-05-29T17:29:00.570","lastModified":"2026-06-17T02:44:14.903","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 10.x (starting from 10.8) and 11.x before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control."},{"lang":"es","value":"Fue encontrado un problema en GitLab Community and Enterprise Edition versión 10.x (a partir de 10.8) y versión 11.x anteriores a 11.6.10, versión 11.7.x anteriores a 11.7.6 y versión 11.8.x anteriores a 11.8.1. Presenta un control de acceso incorrecto."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.8.0","versionEndIncluding":"10.8.7","matchCriteriaId":"DCCDE6A4-EF92-4BCD-9C85-80EFE625B6B9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.8.0","versionEndIncluding":"10.8.7","matchCriteriaId":"51AEAE6C-AE4E-4570-B710-059A0E3358A7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"11.6.10","matchCriteriaId":"2CAC5A61-410C-4D6E-9CBC-21A02567CF7C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"11.6.10","matchCriteriaId":"43020A15-B3E3-46CD-A6D4-E75B121CAAD0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.6","matchCriteriaId":"5D8490E0-F40D-479C-ADF9-6A8A6D1B4C31"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.6","matchCriteriaId":"A0143A98-2A68-45AE-9DC6-6053113DD4F2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.1","matchCriteriaId":"9361A997-0735-41EB-B251-605E0174E602"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.1","matchCriteriaId":"6DFB4A63-4FE4-4499-8834-E6BCE8E9EF24"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/03/14/gitlab-11-8-2-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/2019/03/14/gitlab-11-8-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-9866","sourceIdentifier":"cve@mitre.org","published":"2019-05-29T17:29:00.757","lastModified":"2026-06-17T02:44:45.253","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.7.7 and 11.8.x before 11.8.3. It allows Information Disclosure."},{"lang":"es","value":"Fue encontrado un problema en GitLab Community and Enterprise Edition versión 11.x anterior a 11.7.7 y versión 11.8.x anterior a 11.8.3. Esta permite la divulgación de información."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-200"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"11.7.7","matchCriteriaId":"21911EF1-44E5-46DC-A05B-43FD26B39FAE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"11.7.7","matchCriteriaId":"2D492CF4-C75A-419E-A12A-19876CBE6D78"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.3","matchCriteriaId":"1377F234-C1C6-4EF6-B0C6-4FD91B31E445"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.3","matchCriteriaId":"E7488AFF-1A58-4159-B0FA-96C6E9280F6A"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/03/20/critical-security-release-gitlab-11-dot-8-dot-3-released/","source":"cve@mitre.org"},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/59003","source":"cve@mitre.org"},{"url":"https://about.gitlab.com/2019/03/20/critical-security-release-gitlab-11-dot-8-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/59003","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2018-19493","sourceIdentifier":"cve@mitre.org","published":"2019-07-10T15:15:11.320","lastModified":"2026-06-17T01:49:23.017","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is a persistent XSS vulnerability in the environment pages due to a lack of input validation and output encoding."},{"lang":"es","value":"Se descubrió un problema en Community and Enterprise Edition versiones 11.x anteriores a 11.3.11, versiones 11.4.x anteriores a 11.4.8 y versiones 11.5.x anteriores a 11.5.1 de GitLab. Se presenta una vulnerabilidad de tipo XSS persistente en las páginas de entorno debido a la falta de comprobación de entrada y codificación de salida."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"11.3.11","matchCriteriaId":"E3539E8B-0449-45C0-82B4-4E9B9F6FB5E0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"11.3.11","matchCriteriaId":"8D2F80CC-CF39-4CCD-96F9-A5427E7357AA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.8","matchCriteriaId":"0856E99E-FEE4-4FFB-BB6F-3F28E062617E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.8","matchCriteriaId":"9BD01839-392A-450C-BC58-B56FE387A19F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.1","matchCriteriaId":"5EC4D9F2-9926-42EF-9CDA-90C3551D02C8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.1","matchCriteriaId":"58C8B864-1771-4938-B4E7-8BBFE2706A46"}]}]}],"references":[{"url":"http://www.securityfocus.com/bid/109122","source":"cve@mitre.org","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/53037","source":"cve@mitre.org","tags":["Issue Tracking","Vendor Advisory"]},{"url":"http://www.securityfocus.com/bid/109122","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/53037","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-19494","sourceIdentifier":"cve@mitre.org","published":"2019-07-10T15:15:11.913","lastModified":"2026-06-17T01:49:23.143","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an incorrect access vulnerability that allows an unauthorized user to view private group names."},{"lang":"es","value":"Se detectó un problema en Community and Enterprise Edition versiones 11.x anteriores a 11.3.11, versiones 11.4.x anteriores a 11.4.8 y versiones 11.5.x anteriores a 11.5.1 de GitLab. Hay una vulnerabilidad de acceso incorrecta que permite a un usuario no autorizado visualizar nombres de grupos privados."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-284"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"11.3.11","matchCriteriaId":"E3539E8B-0449-45C0-82B4-4E9B9F6FB5E0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"11.3.11","matchCriteriaId":"8D2F80CC-CF39-4CCD-96F9-A5427E7357AA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.8","matchCriteriaId":"0856E99E-FEE4-4FFB-BB6F-3F28E062617E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.8","matchCriteriaId":"9BD01839-392A-450C-BC58-B56FE387A19F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.1","matchCriteriaId":"5EC4D9F2-9926-42EF-9CDA-90C3551D02C8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.1","matchCriteriaId":"58C8B864-1771-4938-B4E7-8BBFE2706A46"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/51262","source":"cve@mitre.org","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/51262","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-19495","sourceIdentifier":"cve@mitre.org","published":"2019-07-10T15:15:11.993","lastModified":"2026-06-17T01:49:23.270","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an SSRF vulnerability in the Prometheus integration."},{"lang":"es","value":"Se detectó un problema en Community and Enterprise Edition versiones anteriores a 11.3.11, versiones 11.4.x anteriores a 11.4.8 y versiones 11.5.x anteriores a 11.5.1 de GitLab. Se presenta una vulnerabilidad de tipo SSRF en la integración de Prometheus."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"11.3.11","matchCriteriaId":"521ED397-31E8-4281-921F-AAD0CC4365DD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"11.3.11","matchCriteriaId":"0B731B70-E24D-4905-8548-CDC172E3562E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.8","matchCriteriaId":"0856E99E-FEE4-4FFB-BB6F-3F28E062617E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.8","matchCriteriaId":"9BD01839-392A-450C-BC58-B56FE387A19F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.1","matchCriteriaId":"5EC4D9F2-9926-42EF-9CDA-90C3551D02C8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.1","matchCriteriaId":"58C8B864-1771-4938-B4E7-8BBFE2706A46"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ee/issues/8167","source":"cve@mitre.org","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ee/issues/8167","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-19496","sourceIdentifier":"cve@mitre.org","published":"2019-07-10T15:15:12.057","lastModified":"2026-06-17T01:49:23.397","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 10.x and 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an incorrect access control vulnerability that permits a user with insufficient privileges to promote a project milestone to a group milestone."},{"lang":"es","value":"Se descubrió un problema en Community and Enterprise Edition versiones 10.x y versiones 11.x anteriores a 11.3.11, versiones 11.4.x anteriores a 11.4.8 y versiones 11.5.x anteriores a 11.5.1 de GitLab. Hay una vulnerabilidad de control de acceso incorrecta que le permite a un usuario con pocos privilegios promover un hito de proyecto a un hito de grupo."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-284"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.0.0","versionEndExcluding":"11.3.11","matchCriteriaId":"D15D7F07-D745-4FEF-B4BA-855578EEEE1E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.0.0","versionEndExcluding":"11.3.11","matchCriteriaId":"F7A5A219-BCF3-42CE-BC52-A55ABE3455A0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.8","matchCriteriaId":"0856E99E-FEE4-4FFB-BB6F-3F28E062617E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.8","matchCriteriaId":"9BD01839-392A-450C-BC58-B56FE387A19F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.1","matchCriteriaId":"5EC4D9F2-9926-42EF-9CDA-90C3551D02C8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.1","matchCriteriaId":"58C8B864-1771-4938-B4E7-8BBFE2706A46"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/51301","source":"cve@mitre.org","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/51301","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-19577","sourceIdentifier":"cve@mitre.org","published":"2019-07-10T15:15:12.133","lastModified":"2026-06-17T01:49:32.570","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Gitlab CE/EE, versions 8.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an incorrect access control vulnerability that displays to an unauthorized user the title and namespace of a confidential issue."},{"lang":"es","value":"CE/EE, versiones 8.6 hasta 11.x anteriores a 11.3.11, versiones 11.4 anteriores a 11.4.8 y versiones 11.5 anteriores a 11.5.1 de Gitlab, son susceptibles a una vulnerabilidad de control de acceso incorrecta que muestra a un usuario no autorizado el título y el espacio de nombres de un problema confidencial"}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-284"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.6.0","versionEndExcluding":"11.3.11","matchCriteriaId":"577271D7-03AB-4E93-931C-1CA38784A1D6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.6.0","versionEndExcluding":"11.3.11","matchCriteriaId":"E7AED1C2-2DC6-4E7C-8E5C-4B3A229501FF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.8","matchCriteriaId":"0856E99E-FEE4-4FFB-BB6F-3F28E062617E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.8","matchCriteriaId":"9BD01839-392A-450C-BC58-B56FE387A19F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.1","matchCriteriaId":"5EC4D9F2-9926-42EF-9CDA-90C3551D02C8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.1","matchCriteriaId":"58C8B864-1771-4938-B4E7-8BBFE2706A46"}]}]}],"references":[{"url":"http://www.securityfocus.com/bid/109179","source":"cve@mitre.org","tags":["Broken Link","Third Party Advisory","VDB Entry"]},{"url":"https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/","source":"cve@mitre.org","tags":["Broken Link","Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/52444","source":"cve@mitre.org","tags":["Issue Tracking","Vendor Advisory"]},{"url":"http://www.securityfocus.com/bid/109179","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","VDB Entry"]},{"url":"https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/52444","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-19569","sourceIdentifier":"cve@mitre.org","published":"2019-07-10T16:15:10.570","lastModified":"2026-06-17T01:49:31.510","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab CE/EE, versions 8.8 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an authorization vulnerability that allows access to the web-UI as a user using a Personal Access Token of any scope."},{"lang":"es","value":"CE/EE, versiones 8.8 hasta 11.x y anteriores a 11.3.11, versiones 11.4 anteriores a 11.4.8, y versiones 11.5 anteriores a 11.5.1 de GitLab, son vulnerables a una vulnerabilidad de autorización que permite el acceso a la interfaz de usuario web como usuario mediante un Token de Acceso Personal de cualquier ámbito."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-285"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.8.0","versionEndExcluding":"11.3.11","matchCriteriaId":"FB4AA63B-421F-4B3E-8A64-8C186D654809"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.8.0","versionEndExcluding":"11.3.11","matchCriteriaId":"F000A41A-4BF5-4DD2-AEDC-25C6C94E549E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.8","matchCriteriaId":"0856E99E-FEE4-4FFB-BB6F-3F28E062617E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.8","matchCriteriaId":"9BD01839-392A-450C-BC58-B56FE387A19F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.1","matchCriteriaId":"5EC4D9F2-9926-42EF-9CDA-90C3551D02C8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.1","matchCriteriaId":"58C8B864-1771-4938-B4E7-8BBFE2706A46"}]}]}],"references":[{"url":"http://www.securityfocus.com/bid/109118","source":"cve@mitre.org","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/50319","source":"cve@mitre.org","tags":["Issue Tracking","Vendor Advisory"]},{"url":"http://www.securityfocus.com/bid/109118","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/50319","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-19570","sourceIdentifier":"cve@mitre.org","published":"2019-07-10T16:15:10.663","lastModified":"2026-06-17T01:49:31.637","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab CE/EE, versions 11.3 before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an XSS vulnerability in Markdown fields via unrecognized HTML tags."},{"lang":"es","value":"CE/EE, versiones 11.3 anteriores a 11.3.11, versiones 11.4 anteriores a 11.4.8, y versiones 11.5 anteriores a 11.5.1 de GitLab, son vulnerables a una vulnerabilidad de tipo XSS en los campos Markdown por medio de etiquetas HTML no reconocidas."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"11.3.11","matchCriteriaId":"A0E9E860-E37E-4152-B093-40428D90BF2C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"11.3.11","matchCriteriaId":"7C940B6D-6FA7-48BA-A40F-1B1C4577375A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.8","matchCriteriaId":"0856E99E-FEE4-4FFB-BB6F-3F28E062617E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.8","matchCriteriaId":"9BD01839-392A-450C-BC58-B56FE387A19F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.1","matchCriteriaId":"5EC4D9F2-9926-42EF-9CDA-90C3551D02C8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.1","matchCriteriaId":"58C8B864-1771-4938-B4E7-8BBFE2706A46"}]}]}],"references":[{"url":"http://www.securityfocus.com/bid/109169","source":"cve@mitre.org","tags":["Broken Link","Third Party Advisory","VDB Entry"]},{"url":"https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/","source":"cve@mitre.org","tags":["Broken Link","Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/52392","source":"cve@mitre.org","tags":["Issue Tracking","Vendor Advisory"]},{"url":"http://www.securityfocus.com/bid/109169","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","VDB Entry"]},{"url":"https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/52392","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-19572","sourceIdentifier":"cve@mitre.org","published":"2019-07-10T16:15:10.727","lastModified":"2026-06-17T01:49:31.900","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab CE 8.17 and later and EE 8.3 and later have a symlink time-of-check-to-time-of-use race condition that would allow unauthorized access to files in the GitLab Pages chroot environment. This is fixed in versions 11.5.1, 11.4.8, and 11.3.11."},{"lang":"es","value":"CE versión 8.17 y posteriores y EE versión 8.3 y posteriores de GitLab, presenta una condición de carrera de tiempo de comprobación en el tiempo de uso de un symlink que permitiría el acceso no autorizado a archivos en el entorno chroot de Páginas de GitLab. Esto se corrige en las versiones 11.5.1, 11.4.8 y 11.3.11."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-362"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.3.0","versionEndExcluding":"11.3.11","matchCriteriaId":"5D6E45AC-253B-4640-A132-593ED43D568D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.17.0","versionEndExcluding":"11.3.11","matchCriteriaId":"1FF57625-FF1B-46C7-8466-8E5E67DB182F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.3.12","versionEndExcluding":"11.4.8","matchCriteriaId":"A91DFAF8-1E22-4014-8BB6-36B94AD602B4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.3.12","versionEndExcluding":"11.4.8","matchCriteriaId":"CF981E94-E464-4B6D-AD65-96A996B9D349"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.4.9","versionEndExcluding":"11.5.1","matchCriteriaId":"037C5DD5-1873-4190-8453-BBB5EB554936"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.4.9","versionEndExcluding":"11.5.1","matchCriteriaId":"2E02F482-3D21-48AE-BE15-381B8AC7246F"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-pages/issues/98","source":"cve@mitre.org","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-pages/issues/98","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-19573","sourceIdentifier":"cve@mitre.org","published":"2019-07-10T16:15:10.807","lastModified":"2026-06-17T01:49:32.033","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab CE/EE, versions 10.3 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an XSS vulnerability in Markdown fields via Mermaid."},{"lang":"es","value":"CE/EE, versiones 10.3 hasta 11.x y anteriores a 11.3.11, versiones 11.4 y anteriores a 11.4.8 y versiones 11.5 anteriores a 11.5.1 de GitLab, son vulnerables a una vulnerabilidad de tipo XSS en los campos Markdown por medio de Mermaid."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"11.3.11","matchCriteriaId":"E3539E8B-0449-45C0-82B4-4E9B9F6FB5E0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"11.3.11","matchCriteriaId":"8D2F80CC-CF39-4CCD-96F9-A5427E7357AA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.8","matchCriteriaId":"0856E99E-FEE4-4FFB-BB6F-3F28E062617E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.8","matchCriteriaId":"9BD01839-392A-450C-BC58-B56FE387A19F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.1","matchCriteriaId":"5EC4D9F2-9926-42EF-9CDA-90C3551D02C8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.1","matchCriteriaId":"58C8B864-1771-4938-B4E7-8BBFE2706A46"}]}]}],"references":[{"url":"http://www.securityfocus.com/bid/109164","source":"cve@mitre.org","tags":["Broken Link","Third Party Advisory","VDB Entry"]},{"url":"https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/","source":"cve@mitre.org","tags":["Broken Link","Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/45906","source":"cve@mitre.org","tags":["Issue Tracking","Vendor Advisory"]},{"url":"http://www.securityfocus.com/bid/109164","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","VDB Entry"]},{"url":"https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/45906","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-19574","sourceIdentifier":"cve@mitre.org","published":"2019-07-10T16:15:10.867","lastModified":"2026-06-17T01:49:32.163","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab CE/EE, versions 7.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an XSS vulnerability in the OAuth authorization page."},{"lang":"es","value":"CE/EE, versiones 7.6 hasta 11.x y anteriores a 11.3.11, versiones 11.4 anteriores a 11.4.8, y versiones 11.5 anteriores a 11.5.1 de GitLab, son vulnerables a una vulnerabilidad de tipo XSS en la página de autorización OAuth."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"7.6.0","versionEndExcluding":"11.3.11","matchCriteriaId":"9C7EC0D0-D5E4-455D-9A2C-BC40B63F8915"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"7.6.0","versionEndExcluding":"11.3.11","matchCriteriaId":"8EA7C1F3-4E83-42D5-AEAC-EE70E7973B76"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.8","matchCriteriaId":"0856E99E-FEE4-4FFB-BB6F-3F28E062617E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.8","matchCriteriaId":"9BD01839-392A-450C-BC58-B56FE387A19F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.1","matchCriteriaId":"5EC4D9F2-9926-42EF-9CDA-90C3551D02C8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.1","matchCriteriaId":"58C8B864-1771-4938-B4E7-8BBFE2706A46"}]}]}],"references":[{"url":"http://www.securityfocus.com/bid/109163","source":"cve@mitre.org","tags":["Broken Link","Third Party Advisory","VDB Entry"]},{"url":"https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/","source":"cve@mitre.org","tags":["Broken Link","Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/42057","source":"cve@mitre.org","tags":["Issue Tracking","Vendor Advisory"]},{"url":"http://www.securityfocus.com/bid/109163","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","VDB Entry"]},{"url":"https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/42057","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-19575","sourceIdentifier":"cve@mitre.org","published":"2019-07-10T16:15:10.930","lastModified":"2026-06-17T01:49:32.297","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab CE/EE, versions 10.1 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an insecure direct object reference issue that allows a user to make comments on a locked issue."},{"lang":"es","value":"CE/EE, versiones 10.1 hasta 11.x y anteriores a 11.3.11, versiones 11.4 anteriores a 11.4.8, y versiones 11.5 anteriores a 11.5.1 de GitLab, son vulnerables a un problema de referencia de objeto directo no seguro que permite al usuario realizar comentarios sobre un problema bloqueado."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-639"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.1.0","versionEndExcluding":"11.3.11","matchCriteriaId":"C2DE278B-A993-4C20-B784-E456A89DAED7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.1.0","versionEndExcluding":"11.3.11","matchCriteriaId":"54A0DEF6-2685-492F-BA3F-59C87E15B264"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.8","matchCriteriaId":"0856E99E-FEE4-4FFB-BB6F-3F28E062617E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.8","matchCriteriaId":"9BD01839-392A-450C-BC58-B56FE387A19F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.1","matchCriteriaId":"5EC4D9F2-9926-42EF-9CDA-90C3551D02C8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.1","matchCriteriaId":"58C8B864-1771-4938-B4E7-8BBFE2706A46"}]}]}],"references":[{"url":"http://www.securityfocus.com/bid/109121","source":"cve@mitre.org","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/52523","source":"cve@mitre.org","tags":["Issue Tracking","Vendor Advisory"]},{"url":"http://www.securityfocus.com/bid/109121","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/52523","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-19576","sourceIdentifier":"cve@mitre.org","published":"2019-07-10T16:15:11.007","lastModified":"2026-06-17T01:49:32.433","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab CE/EE, versions 8.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an access control issue that allows a Guest user to make changes to or delete their own comments on an issue, after the issue was made Confidential."},{"lang":"es","value":"CE/EE, versiones 8.6 hasta 11.x y anteriores a 11.3.11, versiones 11.4 anteriores a 11.4.8, y versiones 11.5 anteriores a 11.5.1 de GitLab, son vulnerables a un problema de control de acceso que permite a un usuario Guest realizar cambios o eliminar sus propios comentarios sobre un problema, después de que el problema se haya hecho Confidencial."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.2}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:P","baseScore":6.4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-284"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.6.0","versionEndExcluding":"11.3.11","matchCriteriaId":"577271D7-03AB-4E93-931C-1CA38784A1D6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.6.0","versionEndExcluding":"11.3.11","matchCriteriaId":"E7AED1C2-2DC6-4E7C-8E5C-4B3A229501FF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.8","matchCriteriaId":"0856E99E-FEE4-4FFB-BB6F-3F28E062617E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.8","matchCriteriaId":"9BD01839-392A-450C-BC58-B56FE387A19F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.1","matchCriteriaId":"5EC4D9F2-9926-42EF-9CDA-90C3551D02C8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.1","matchCriteriaId":"58C8B864-1771-4938-B4E7-8BBFE2706A46"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/51238","source":"cve@mitre.org","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/51238","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-19571","sourceIdentifier":"cve@mitre.org","published":"2019-07-10T17:15:11.490","lastModified":"2026-06-17T01:49:31.767","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab CE/EE, versions 8.18 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an SSRF vulnerability in webhooks."},{"lang":"es","value":"CE/EE, versiones 8.18 hasta 11.x anteriores a 11.3.11, versiones 11.4 anteriores a 11.4.8 y versiones 11.5 anteriores a 11.5.1 de GitLab, son susceptibles a una vulnerabilidad de tipo SSRF en los webhooks."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","baseScore":7.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":4.0}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.18.0","versionEndExcluding":"11.3.11","matchCriteriaId":"9FF933E9-B7F7-4DE8-80DD-AE1B4972EB85"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.18.0","versionEndExcluding":"11.3.11","matchCriteriaId":"AC7CFA1D-DE73-4A1A-8B2B-5835BD12CADD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.8","matchCriteriaId":"0856E99E-FEE4-4FFB-BB6F-3F28E062617E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.8","matchCriteriaId":"9BD01839-392A-450C-BC58-B56FE387A19F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.1","matchCriteriaId":"5EC4D9F2-9926-42EF-9CDA-90C3551D02C8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.1","matchCriteriaId":"58C8B864-1771-4938-B4E7-8BBFE2706A46"}]}]}],"references":[{"url":"http://packetstormsecurity.com/files/160516/GitLab-11.4.7-Remote-Code-Execution.html","source":"cve@mitre.org","tags":["Third Party Advisory","VDB Entry"]},{"url":"http://packetstormsecurity.com/files/160699/GitLab-11.4.7-Remote-Code-Execution.html","source":"cve@mitre.org","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/","source":"cve@mitre.org","tags":["Broken Link","Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/53242","source":"cve@mitre.org","tags":["Issue Tracking","Vendor Advisory"]},{"url":"http://packetstormsecurity.com/files/160516/GitLab-11.4.7-Remote-Code-Execution.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"]},{"url":"http://packetstormsecurity.com/files/160699/GitLab-11.4.7-Remote-Code-Execution.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/53242","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-19578","sourceIdentifier":"cve@mitre.org","published":"2019-07-10T17:15:11.570","lastModified":"2026-06-17T01:49:32.700","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab EE, version 11.5 before 11.5.1, is vulnerable to an insecure object reference issue that permits a user with Reporter privileges to view the Jaeger Tracing Operations page."},{"lang":"es","value":"EE de GitLab, versiones 11.5 anteriores a 11.5.1, es vulnerable a un problema de referencia de objeto no seguro lo que permite a un usuario con privilegios Reporter visualizar la página de Jaeger Tracing Operations ."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-285"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.1","matchCriteriaId":"58C8B864-1771-4938-B4E7-8BBFE2706A46"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/54228","source":"cve@mitre.org","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/54228","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-19579","sourceIdentifier":"cve@mitre.org","published":"2019-07-10T17:15:11.647","lastModified":"2026-06-17T01:49:32.827","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab EE version 11.5 is vulnerable to a persistent XSS vulnerability in the Operations page. This is fixed in 11.5.1."},{"lang":"es","value":"EE versión 11.5 de GitLab, es susceptible a una vulnerabilidad de tipo XSS persistente en la página Operations. Esto se corrige en versión 11.5.1."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.1","matchCriteriaId":"58C8B864-1771-4938-B4E7-8BBFE2706A46"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/53917","source":"cve@mitre.org","tags":["Exploit","Vendor Advisory"]},{"url":"https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/53917","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-19580","sourceIdentifier":"cve@mitre.org","published":"2019-07-10T17:15:11.710","lastModified":"2026-06-17T01:49:32.950","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"All versions of GitLab prior to 11.5.1, 11.4.8, and 11.3.11 do not send an email to the old email address when an email address change is made."},{"lang":"es","value":"GitLab versiones anteriores a 11.5.1, 11.4.8 y 11.3.11, no envían un correo electrónico a la dirección de correo electrónico anterior cuando es realizado un cambio de dirección de correo electrónico."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-20"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"11.3.11","matchCriteriaId":"521ED397-31E8-4281-921F-AAD0CC4365DD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"11.3.11","matchCriteriaId":"0B731B70-E24D-4905-8548-CDC172E3562E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.3.12","versionEndExcluding":"11.4.8","matchCriteriaId":"A91DFAF8-1E22-4014-8BB6-36B94AD602B4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.3.12","versionEndExcluding":"11.4.8","matchCriteriaId":"CF981E94-E464-4B6D-AD65-96A996B9D349"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.4.9","versionEndExcluding":"11.5.1","matchCriteriaId":"037C5DD5-1873-4190-8453-BBB5EB554936"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.4.9","versionEndExcluding":"11.5.1","matchCriteriaId":"2E02F482-3D21-48AE-BE15-381B8AC7246F"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/39809","source":"cve@mitre.org","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/39809","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-19581","sourceIdentifier":"cve@mitre.org","published":"2019-07-10T17:15:11.787","lastModified":"2026-06-17T01:49:33.077","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab EE, versions 8.3 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, is vulnerable to an insecure object reference vulnerability that allows a Guest user to set the weight of an issue they create."},{"lang":"es","value":"EE, versiones 8.3 hasta 11.x anteriores a 11.3.11, versiones 11.4 anteriores a 11.4.8 y versiones 11.5 anteriores a 11.5.1 de GitLab, es susceptible a una vulnerabilidad de referencia de objeto no segura que permite a un usuario Guest establecer el peso de un problema que han diseñado."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-285"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.3.0","versionEndExcluding":"11.3.11","matchCriteriaId":"5D6E45AC-253B-4640-A132-593ED43D568D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.8","matchCriteriaId":"9BD01839-392A-450C-BC58-B56FE387A19F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.1","matchCriteriaId":"58C8B864-1771-4938-B4E7-8BBFE2706A46"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ee/issues/7696","source":"cve@mitre.org","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ee/issues/7696","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-19582","sourceIdentifier":"cve@mitre.org","published":"2019-07-10T17:15:11.850","lastModified":"2026-06-17T01:49:33.203","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab EE, versions 11.4 before 11.4.8 and 11.5 before 11.5.1, is affected by an insecure direct object reference vulnerability that permits an unauthorized user to publish the draft merge request comments of another user."},{"lang":"es","value":"EE, versiones 11.4 anteriores a 11.4.8 y versiones 11.5 anteriores a 11.5.1 de GitLab, esta afectado por una vulnerabilidad de referencia de objeto directo no segura que permite a un usuario no autorizado publicar los comentarios de una petición de fusión preliminar de otro usuario."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-639"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.8","matchCriteriaId":"9BD01839-392A-450C-BC58-B56FE387A19F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.1","matchCriteriaId":"58C8B864-1771-4938-B4E7-8BBFE2706A46"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ee/issues/8180","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ee/issues/8180","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-19583","sourceIdentifier":"cve@mitre.org","published":"2019-07-10T17:15:11.927","lastModified":"2026-06-17T01:49:33.327","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab CE/EE, versions 8.0 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, would log access tokens in the Workhorse logs, permitting administrators with access to the logs to see another user's token."},{"lang":"es","value":"CE/EE, versiones 8.0 hasta 11.x anteriores a 11.3.11, versiones 11.4 anteriores a 11.4.8, y versiones 11.5 anteriores a 11.5.1 de GitLab, registraría tokens de acceso en los registros Workhorse, permitiendo a los administradores con acceso a los registros visualizar otros tokens de usuario."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-532"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.0.0","versionEndExcluding":"11.3.11","matchCriteriaId":"F78D0259-0106-46CC-9FD8-821944C18135"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.0.0","versionEndExcluding":"11.3.11","matchCriteriaId":"E22CA2FE-3F91-47E9-89B6-4A8B9AFB940B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.8","matchCriteriaId":"0856E99E-FEE4-4FFB-BB6F-3F28E062617E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.8","matchCriteriaId":"9BD01839-392A-450C-BC58-B56FE387A19F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.1","matchCriteriaId":"5EC4D9F2-9926-42EF-9CDA-90C3551D02C8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.1","matchCriteriaId":"58C8B864-1771-4938-B4E7-8BBFE2706A46"}]}]}],"references":[{"url":"http://www.securityfocus.com/bid/109166","source":"cve@mitre.org","tags":["Broken Link","Third Party Advisory","VDB Entry"]},{"url":"https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/","source":"cve@mitre.org","tags":["Broken Link","Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-workhorse/issues/182","source":"cve@mitre.org","tags":["Issue Tracking","Vendor Advisory"]},{"url":"http://www.securityfocus.com/bid/109166","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","VDB Entry"]},{"url":"https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-workhorse/issues/182","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-19584","sourceIdentifier":"cve@mitre.org","published":"2019-07-10T17:15:12.007","lastModified":"2026-06-17T01:49:33.460","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab EE, versions 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, is vulnerable to an insecure direct object reference vulnerability that allows authenticated, but unauthorized, users to view members and milestone details of private groups."},{"lang":"es","value":"EE, versiones 11.x y anteriores a 11.3.11, versiones 11.4 y anteriores a 11.4.8 y versiones 11.5 anteriores a 11.5.1 de GitLab , es susceptible a una vulnerabilidad de referencia de objeto directo no seguro que permite a los usuarios identificados, pero no autorizados, visualizar detalles de miembros y de hitos de grupos privados."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-639"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"11.3.11","matchCriteriaId":"8D2F80CC-CF39-4CCD-96F9-A5427E7357AA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.8","matchCriteriaId":"9BD01839-392A-450C-BC58-B56FE387A19F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.1","matchCriteriaId":"58C8B864-1771-4938-B4E7-8BBFE2706A46"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/52522","source":"cve@mitre.org","tags":["Exploit","Vendor Advisory"]},{"url":"https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/52522","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-14943","sourceIdentifier":"cve@mitre.org","published":"2019-08-29T12:15:11.000","lastModified":"2026-06-17T02:19:22.153","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.1.4. It uses Hard-coded Credentials."},{"lang":"es","value":"Se detectó un problema en GitLab Community and Enterprise Edition versiones 12.0 hasta 12.1.4. Utiliza Credenciales Embebidas."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-798"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.0","versionEndIncluding":"12.1.4","matchCriteriaId":"535BE5CB-FBFB-464E-BEE9-F7DEEAA0DB08"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.0","versionEndIncluding":"12.1.4","matchCriteriaId":"57FE5EB4-A998-4FE8-A501-A6C22FF9444C"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/08/12/critical-security-release-gitlab-12-dot-1-dot-6-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/omnibus-gitlab/issues/4530","source":"cve@mitre.org","tags":["Broken Link"]},{"url":"https://about.gitlab.com/2019/08/12/critical-security-release-gitlab-12-dot-1-dot-6-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/omnibus-gitlab/issues/4530","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2019-5461","sourceIdentifier":"support@hackerone.com","published":"2019-09-09T17:15:14.003","lastModified":"2026-06-17T02:37:43.797","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An input validation problem was discovered in the GitHub service integration which could result in an attacker being able to make arbitrary POST requests in a GitLab instance's internal network. This vulnerability was addressed in 12.1.2, 12.0.4, and 11.11.6."},{"lang":"es","value":"Se descubrió un problema de comprobación de entrada en la integración del servicio GitHub que podría resultar en que un atacante pueda realizar peticiones POST arbitrarias en la red interna de una instancia de GitLab. Esta vulnerabilidad se abordó en las versiones 12.1.2, 12.0.4 y 11.11.6."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"n/a","product":"GitLab Community Edition","versions":[{"version":"Fix Versions: 12.1.2, 12.0.4, and 11.11.6","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":3.5,"baseSeverity":"LOW","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"support@hackerone.com","type":"Secondary","description":[{"lang":"en","value":"CWE-20"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-20"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.11.0","versionEndExcluding":"11.11.7","matchCriteriaId":"33FB67D6-7874-4224-A89C-BFD3080796DA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.11.0","versionEndExcluding":"11.11.7","matchCriteriaId":"0ABDFAF2-C1E3-4416-8E67-1CF2ABA29FEF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.0.0","versionEndExcluding":"12.0.4","matchCriteriaId":"62DEEA13-4D2C-436B-9780-983FC707DDF6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.0.0","versionEndExcluding":"12.0.4","matchCriteriaId":"595B584B-2A5C-44F6-AC4C-51ACF913C6C5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.2","matchCriteriaId":"99659BEC-15D0-4E75-BEBE-727FC32D9B35"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.2","matchCriteriaId":"D12A3A81-4A4F-441A-A820-F2D19B1A5C89"}]}]}],"references":[{"url":"https://gitlab.com//gitlab-org/gitlab-ce/issues/54649","source":"support@hackerone.com","tags":["Exploit","Vendor Advisory"]},{"url":"https://hackerone.com/reports/446593","source":"support@hackerone.com","tags":["Third Party Advisory"]},{"url":"https://about.gitlab.com/2019/07/29/security-release-gitlab-12-dot-1-dot-2-released/","source":"nvd@nist.gov","tags":["Vendor Advisory"]},{"url":"https://gitlab.com//gitlab-org/gitlab-ce/issues/54649","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]},{"url":"https://hackerone.com/reports/446593","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2019-5463","sourceIdentifier":"support@hackerone.com","published":"2019-09-09T18:15:10.467","lastModified":"2026-06-17T02:37:44.010","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An authorization issue was discovered in the GitLab CE/EE CI badge images endpoint which could result in disclosure of the build status. This vulnerability was addressed in 12.1.2, 12.0.4, and 11.11.6."},{"lang":"es","value":"Se detectó un problema de autorización en el end point de las imágenes de insignia CI de GitLab CE/EE, lo que podría resultar en la divulgación del estado de la compilación. Esta vulnerabilidad se abordó en las versiones 12.1.2, 12.0.4 y 11.11.6."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"n/a","product":"GitLab CE/EE","versions":[{"version":"Affects all previous GitLab CE/EE versions. Fixed in 12.1.2, 12.0.4, and 11.11.6","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"support@hackerone.com","type":"Secondary","description":[{"lang":"en","value":"CWE-200"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-200"},{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.11.0","versionEndExcluding":"11.11.7","matchCriteriaId":"33FB67D6-7874-4224-A89C-BFD3080796DA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.11.0","versionEndExcluding":"11.11.7","matchCriteriaId":"0ABDFAF2-C1E3-4416-8E67-1CF2ABA29FEF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.0.0","versionEndExcluding":"12.0.4","matchCriteriaId":"62DEEA13-4D2C-436B-9780-983FC707DDF6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.0.0","versionEndExcluding":"12.0.4","matchCriteriaId":"595B584B-2A5C-44F6-AC4C-51ACF913C6C5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.2","matchCriteriaId":"99659BEC-15D0-4E75-BEBE-727FC32D9B35"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.2","matchCriteriaId":"D12A3A81-4A4F-441A-A820-F2D19B1A5C89"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/56407","source":"support@hackerone.com","tags":["Third Party Advisory"]},{"url":"https://hackerone.com/reports/477222","source":"support@hackerone.com","tags":["Exploit","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/56407","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://hackerone.com/reports/477222","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2019-5467","sourceIdentifier":"support@hackerone.com","published":"2019-09-09T18:15:10.560","lastModified":"2026-06-17T02:37:44.417","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An input validation and output encoding issue was discovered in the GitLab CE/EE wiki pages feature which could result in a persistent XSS. This vulnerability was addressed in 12.1.2, 12.0.4, and 11.11.6."},{"lang":"es","value":"Se detectó un problema de comprobación de entrada y codificación de salida en la funcionalidad de páginas wiki de GitLab CE/EE que podría resultar en un ataque de tipo XSS persistente. Esta vulnerabilidad se abordó en las versiones 12.1.2, 12.0.4 y 11.11.6."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"n/a","product":"GitLab CE/EE","versions":[{"version":"Affects GitLab CE/EE 11.10 and later. Fixed in 12.1.2, 12.0.4, and 11.11.6","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"support@hackerone.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.11.2","versionEndExcluding":"11.11.7","matchCriteriaId":"63B7F0CE-098B-4AE1-9A21-FB9CA5D45BC5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.11.2","versionEndExcluding":"11.11.7","matchCriteriaId":"C7CD94EC-B0A8-4F35-AF36-835942CFDC30"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.0.0","versionEndExcluding":"12.0.4","matchCriteriaId":"62DEEA13-4D2C-436B-9780-983FC707DDF6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.0.0","versionEndExcluding":"12.0.4","matchCriteriaId":"595B584B-2A5C-44F6-AC4C-51ACF913C6C5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.2","matchCriteriaId":"99659BEC-15D0-4E75-BEBE-727FC32D9B35"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.2","matchCriteriaId":"D12A3A81-4A4F-441A-A820-F2D19B1A5C89"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/60143","source":"support@hackerone.com","tags":["Exploit","Issue Tracking","Third Party Advisory"]},{"url":"https://hackerone.com/reports/526325","source":"support@hackerone.com","tags":["Exploit","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/60143","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Third Party Advisory"]},{"url":"https://hackerone.com/reports/526325","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2019-5471","sourceIdentifier":"support@hackerone.com","published":"2019-09-09T18:15:10.653","lastModified":"2026-06-17T02:37:44.840","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An input validation and output encoding issue was discovered in the GitLab email notification feature which could result in a persistent XSS. This was addressed in GitLab 12.1.2, 12.0.4, and 11.11.6."},{"lang":"es","value":"Se detectó un problema de comprobación de entrada y codificación de salida en la funcionalidad de notificación de correo electrónico de GitLab lo que podría resultar un ataque XSS persistente. Esto se abordó en GitLab versiones 12.1.2, 12.0.4 y 11.11.6."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"n/a","product":"GitLab","versions":[{"version":"Fixed versions 12.1.2, 12.0.4, and 11.11.6","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"support@hackerone.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.11.0","versionEndExcluding":"11.11.7","matchCriteriaId":"33FB67D6-7874-4224-A89C-BFD3080796DA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.11.0","versionEndExcluding":"11.11.7","matchCriteriaId":"0ABDFAF2-C1E3-4416-8E67-1CF2ABA29FEF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.0.0","versionEndExcluding":"12.0.4","matchCriteriaId":"62DEEA13-4D2C-436B-9780-983FC707DDF6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.0.0","versionEndExcluding":"12.0.4","matchCriteriaId":"595B584B-2A5C-44F6-AC4C-51ACF913C6C5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.2","matchCriteriaId":"99659BEC-15D0-4E75-BEBE-727FC32D9B35"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.2","matchCriteriaId":"D12A3A81-4A4F-441A-A820-F2D19B1A5C89"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab-ee/issues/11515","source":"support@hackerone.com","tags":["Exploit","Vendor Advisory"]},{"url":"https://hackerone.com/reports/496973","source":"support@hackerone.com","tags":["Exploit","Third Party Advisory"]},{"url":"https://about.gitlab.com/2019/07/29/security-release-gitlab-12-dot-1-dot-2-released/","source":"nvd@nist.gov","tags":["Broken Link","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ee/issues/11515","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]},{"url":"https://hackerone.com/reports/496973","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2019-5473","sourceIdentifier":"support@hackerone.com","published":"2019-09-09T18:15:10.747","lastModified":"2026-06-17T02:37:45.057","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An authentication issue was discovered in GitLab that allowed a bypass of email verification. This was addressed in GitLab 12.1.2 and 12.0.4."},{"lang":"es","value":"Se detectó un problema de autenticación en GitLab, que permitió omitir la comprobación por correo electrónico. Esto se abordó en GitLab versiones 12.1.2 y 12.0.4."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"n/a","product":"gitlab.com","versions":[{"version":"Fixed versions 12.1.2 and 12.0.4","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"support@hackerone.com","type":"Secondary","description":[{"lang":"en","value":"CWE-288"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-287"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:12.0.4:*:*:*:enterprise:*:*:*","matchCriteriaId":"57472C8A-29AA-4FCC-88C8-F4863EAACEC5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:12.1.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"E242EE20-A4E6-4411-8804-8FD6DA362C0B"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab-ee/issues/11643","source":"support@hackerone.com","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/565883","source":"support@hackerone.com","tags":["Exploit","Issue Tracking","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ee/issues/11643","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/565883","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2019-11544","sourceIdentifier":"cve@mitre.org","published":"2019-09-09T19:15:10.487","lastModified":"2026-06-17T02:13:08.440","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 8.x, 9.x, 10.x, and 11.x before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. It allows Information Disclosure. Non-member users who subscribe to notifications of an internal project with issue and repository restrictions will receive emails about restricted events."},{"lang":"es","value":"Se detectó un problema en GitLab Community and Enterprise Edition versiones 8.x, 9.x, 10.x y versiones 11.x anteriores a 11.8.9, versiones 11.9.x anteriores a 11.9.10 y versiones 11.10.x anteriores a 11.10.2. Permite la divulgación de información. Usuarios no miembros que se suscriban a notificaciones de un proyecto interno con restricciones de problemas y repositorio recibirán correos electrónicos sobre eventos restringidos."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.1.0","versionEndIncluding":"8.17.8","matchCriteriaId":"32357D13-B64E-4F67-B717-462A47DE6215"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.1.0","versionEndIncluding":"8.17.8","matchCriteriaId":"C3B97072-2693-4D21-8EEF-063FD0491A79"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"9.0.0","versionEndIncluding":"9.3.7","matchCriteriaId":"A855DD8E-C4FD-4C93-9EC9-D2CEE9A36DE8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"9.0.0","versionEndIncluding":"9.3.7","matchCriteriaId":"17EBDEFE-775B-4D7D-87CE-F3001276A385"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.0.0","versionEndIncluding":"10.8.7","matchCriteriaId":"90A2B0E7-9793-4CAB-B715-7000A0361C31"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.0.0","versionEndIncluding":"10.8.7","matchCriteriaId":"6F0E5540-3274-4ADF-8028-E3A4AD176661"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"11.8.9","matchCriteriaId":"237924B7-D373-40B6-BD51-25A5516B2144"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"11.8.9","matchCriteriaId":"5901A255-870F-4104-989B-CDE9E5DF519B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.9.0","versionEndExcluding":"11.9.10","matchCriteriaId":"FE126900-2E77-4CF7-B0BE-5A065106D01C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.9.0","versionEndExcluding":"11.9.10","matchCriteriaId":"B6AF88DF-B327-459A-AD0D-E664423929D2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.10.0","versionEndIncluding":"11.10.2","matchCriteriaId":"216B9EC5-A9E6-407F-A794-85E7E7EAAC64"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.10.0","versionEndExcluding":"11.10.2","matchCriteriaId":"1C74096E-1CBF-42FA-89B7-B1EC374967A8"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/04/29/security-release-gitlab-11-dot-10-dot-2-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/58372","source":"cve@mitre.org","tags":["Exploit","Vendor Advisory"]},{"url":"https://about.gitlab.com/2019/04/29/security-release-gitlab-11-dot-10-dot-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/58372","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-11545","sourceIdentifier":"cve@mitre.org","published":"2019-09-09T19:15:10.677","lastModified":"2026-06-17T02:13:08.570","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community Edition 11.9.x before 11.9.10 and 11.10.x before 11.10.2. It allows Information Disclosure. When an issue is moved to a private project, the private project namespace is leaked to unauthorized users with access to the original issue."},{"lang":"es","value":"Se detectó un problema en GitLab Community Edition versiones 11.9.x anteriores a 11.9.10 y versiones 11.10.x anteriores a 11.10.2. Permite la divulgación de información. Cuando un problema es movido hacia un proyecto privado, el espacio de nombres del proyecto privado es filtrado para usuarios no autorizados con acceso al problema original."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-200"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.9.0","versionEndExcluding":"11.9.10","matchCriteriaId":"FE126900-2E77-4CF7-B0BE-5A065106D01C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.9.0","versionEndExcluding":"11.9.10","matchCriteriaId":"B6AF88DF-B327-459A-AD0D-E664423929D2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.10.0","versionEndExcluding":"11.10.2","matchCriteriaId":"54B843C2-A346-4030-9A5B-2CCD36AC1668"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.10.0","versionEndExcluding":"11.10.2","matchCriteriaId":"1C74096E-1CBF-42FA-89B7-B1EC374967A8"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/04/29/security-release-gitlab-11-dot-10-dot-2-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/58939","source":"cve@mitre.org","tags":["Exploit","Vendor Advisory"]},{"url":"https://about.gitlab.com/2019/04/29/security-release-gitlab-11-dot-10-dot-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/58939","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-11546","sourceIdentifier":"cve@mitre.org","published":"2019-09-09T19:15:10.770","lastModified":"2026-06-17T02:13:08.693","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. It has a Race Condition which could allow users to approve a merge request multiple times and potentially reach the approval count required to merge."},{"lang":"es","value":"Se detectó un problema en GitLab Community and Enterprise Edition versiones anteriores a 11.8.9, versiones 11.9.x anteriores a 11.9.10 y versiones 11.10.x anteriores a 11.10.2. Presenta una condición de carrera que podría permitir a usuarios aprobar una petición de fusión varias veces y potencialmente alcanzar el conteo de aprobación requerido para fusionarse."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-362"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.6.0","versionEndExcluding":"11.8.9","matchCriteriaId":"FC09FA3E-EA4D-4EBC-987E-C0B885607287"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.6.0","versionEndExcluding":"11.8.9","matchCriteriaId":"5E86754C-F8CA-46AE-9582-DFDF7877B640"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.9.0","versionEndExcluding":"11.9.10","matchCriteriaId":"FE126900-2E77-4CF7-B0BE-5A065106D01C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.9.0","versionEndExcluding":"11.9.10","matchCriteriaId":"B6AF88DF-B327-459A-AD0D-E664423929D2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.10.0","versionEndExcluding":"11.10.2","matchCriteriaId":"54B843C2-A346-4030-9A5B-2CCD36AC1668"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.10.0","versionEndExcluding":"11.10.2","matchCriteriaId":"1C74096E-1CBF-42FA-89B7-B1EC374967A8"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/04/29/security-release-gitlab-11-dot-10-dot-2-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ee/issues/10357","source":"cve@mitre.org","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://about.gitlab.com/2019/04/29/security-release-gitlab-11-dot-10-dot-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ee/issues/10357","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-11547","sourceIdentifier":"cve@mitre.org","published":"2019-09-09T19:15:10.847","lastModified":"2026-06-17T02:13:08.830","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. It has Improper Encoding or Escaping of Output. The branch name on new merge request notification emails isn't escaped, which could potentially lead to XSS issues."},{"lang":"es","value":"Se detectó un problema en GitLab Community and Enterprise Edition versiones anteriores a 11.8.9, versiones 11.9.x anteriores a 11.9.10 y versiones 11.10.x anteriores a 11.10.2. Presenta una Codificación Incorrecta o un Escape de Salida. El nombre de la derivación en los nuevos correos electrónicos de notificación de petición de fusión no se escapa, lo que podría conllevar potencialmente a problemas de tipo XSS."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"},{"lang":"en","value":"CWE-116"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"6.0.0","versionEndExcluding":"11.8.9","matchCriteriaId":"D8825D7D-2A32-479C-BA5E-E5FD48CD3B01"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"6.0.0","versionEndExcluding":"11.8.9","matchCriteriaId":"F5377DEE-0714-414D-8484-41A2DB2E12EC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.9.0","versionEndExcluding":"11.9.10","matchCriteriaId":"FE126900-2E77-4CF7-B0BE-5A065106D01C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.9.0","versionEndExcluding":"11.9.10","matchCriteriaId":"B6AF88DF-B327-459A-AD0D-E664423929D2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.10.0","versionEndExcluding":"11.10.2","matchCriteriaId":"54B843C2-A346-4030-9A5B-2CCD36AC1668"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.10.0","versionEndExcluding":"11.10.2","matchCriteriaId":"1C74096E-1CBF-42FA-89B7-B1EC374967A8"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/04/29/security-release-gitlab-11-dot-10-dot-2-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ee/issues/11515","source":"cve@mitre.org","tags":["Exploit","Vendor Advisory"]},{"url":"https://about.gitlab.com/2019/04/29/security-release-gitlab-11-dot-10-dot-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ee/issues/11515","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-11548","sourceIdentifier":"cve@mitre.org","published":"2019-09-09T19:15:10.940","lastModified":"2026-06-17T02:13:08.953","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9. It has Incorrect Access Control. Unprivileged members of a project are able to post comments on confidential issues through an authorization issue in the note endpoint."},{"lang":"es","value":"Se detectó un problema en GitLab Community and Enterprise Edition versiones anteriores a 11.8.9. Presenta un Control de Acceso Incorrecto. Los miembros no privilegiados de un proyecto pueden publicar comentarios sobre problemas confidenciales por medio de un problema de autorización en el end point de note."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"5.4.0","versionEndExcluding":"11.8.9","matchCriteriaId":"3F947E28-E1C1-4C29-97CA-FE13DA736D37"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"5.4.0","versionEndExcluding":"11.8.9","matchCriteriaId":"9FC1B252-249A-4C8E-A107-6A498BFF8D63"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/04/29/security-release-gitlab-11-dot-10-dot-2-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/58505","source":"cve@mitre.org","tags":["Exploit","Vendor Advisory"]},{"url":"https://about.gitlab.com/2019/04/29/security-release-gitlab-11-dot-10-dot-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/58505","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-11549","sourceIdentifier":"cve@mitre.org","published":"2019-09-09T19:15:11.033","lastModified":"2026-06-17T02:13:09.083","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. Gitaly has allows an information disclosure issue where HTTP/GIT credentials are included in logs on connection errors."},{"lang":"es","value":"Se detectó un problema en GitLab Community and Enterprise Edition versiones 9.x, 10.x y versiones 11.x anteriores a 11.8.9, versiones 11.9.x anteriores a 11.9.10 y versiones 11.10.x anteriores a 11.10.2. Gitaly permite un problema de divulgación de información en el que las credenciales HTTP/GIT son incluidas en los registros de errores de conexión."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-532"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"9.0.0","versionEndIncluding":"9.3.7","matchCriteriaId":"A855DD8E-C4FD-4C93-9EC9-D2CEE9A36DE8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"9.0.0","versionEndIncluding":"9.3.7","matchCriteriaId":"17EBDEFE-775B-4D7D-87CE-F3001276A385"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.0.0","versionEndIncluding":"10.8.7","matchCriteriaId":"90A2B0E7-9793-4CAB-B715-7000A0361C31"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.0.0","versionEndIncluding":"10.8.7","matchCriteriaId":"6F0E5540-3274-4ADF-8028-E3A4AD176661"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"11.8.9","matchCriteriaId":"237924B7-D373-40B6-BD51-25A5516B2144"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"11.8.9","matchCriteriaId":"5901A255-870F-4104-989B-CDE9E5DF519B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.9.0","versionEndExcluding":"11.9.10","matchCriteriaId":"FE126900-2E77-4CF7-B0BE-5A065106D01C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.9.0","versionEndExcluding":"11.9.10","matchCriteriaId":"B6AF88DF-B327-459A-AD0D-E664423929D2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.10.0","versionEndExcluding":"11.10.2","matchCriteriaId":"54B843C2-A346-4030-9A5B-2CCD36AC1668"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.10.0","versionEndExcluding":"11.10.2","matchCriteriaId":"1C74096E-1CBF-42FA-89B7-B1EC374967A8"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/04/29/security-release-gitlab-11-dot-10-dot-2-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/57779","source":"cve@mitre.org","tags":["Exploit","Vendor Advisory"]},{"url":"https://about.gitlab.com/2019/04/29/security-release-gitlab-11-dot-10-dot-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/57779","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-11605","sourceIdentifier":"cve@mitre.org","published":"2019-09-09T19:15:11.097","lastModified":"2026-06-17T02:13:15.463","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 11.8.x before 11.8.10, 11.9.x before 11.9.11, and 11.10.x before 11.10.3. It allows Information Disclosure. A small number of GitLab API endpoints would disclose project information when using a read_user scoped token."},{"lang":"es","value":"Se detectó un problema en GitLab Community and Enterprise Edition versiones 11.8.x anteriores a 11.8.10, versiones 11.9.x anteriores a 11.9.11 y versiones 11.10.x anteriores a 11.10.3. Permite una Divulgación de Información. Una pequeña cantidad de end points de la API de GitLab revelaría información del proyecto cuando se usa un token del ámbito de read_user."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-200"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.10","matchCriteriaId":"6E02C202-94E2-4891-8EF5-F797888B0DD6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.8.10","matchCriteriaId":"6FFB0F91-850B-4815-AFE0-83DF929242F6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.9.0","versionEndExcluding":"11.9.11","matchCriteriaId":"9DE772A9-B3E0-463A-8CC0-CC98901FF0A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.9.0","versionEndExcluding":"11.9.11","matchCriteriaId":"D0D06882-CCAD-4482-B2F3-5D8ADAA41675"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.10.0","versionEndExcluding":"11.10.3","matchCriteriaId":"A3A92ACD-AB3D-49C6-A27A-4877DB086BD0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.10.0","versionEndExcluding":"11.10.3","matchCriteriaId":"43C02516-9A8F-4639-A26F-2421F7AFB4A6"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/04/30/security-release-gitlab-11-dot-10-dot-3-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/2019/04/30/security-release-gitlab-11-dot-10-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-6782","sourceIdentifier":"cve@mitre.org","published":"2019-09-09T20:15:11.167","lastModified":"2026-06-17T02:39:40.170","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Information Disclosure (issue 1 of 6). An authorization issue allows the contributed project information of a private profile to be viewed."},{"lang":"es","value":"Se detectó un problema en GitLab Community and Enterprise Edition versiones anteriores a 11.5.8, versiones 11.6.x anteriores a 11.6.6 y versiones 11.7.x anteriores a 11.7.1. Permite la divulgación de información (problema 1 de 6). Un problema de autorización permite que sea visualizada la información del proyecto aportada desde un perfil privado."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"11.5.8","matchCriteriaId":"58063C72-498E-47E4-8B09-93D2C346D6D0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"11.5.8","matchCriteriaId":"BC425BDD-E447-4513-B278-B9760262A2F4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.6","matchCriteriaId":"794CA42E-5409-455B-956C-21BC431E0B98"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.6","matchCriteriaId":"35A01A1A-A0F1-4952-B15A-A898FD185B3F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.1","matchCriteriaId":"3BAE4B6C-8F1F-4C42-ADF9-A9CBD3895C68"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.1","matchCriteriaId":"3A67FE77-4048-41B8-8734-CA62393ED632"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/52677","source":"cve@mitre.org","tags":["Exploit","Issue Tracking","Third Party Advisory"]},{"url":"https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/52677","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2019-6783","sourceIdentifier":"cve@mitre.org","published":"2019-09-09T20:15:11.277","lastModified":"2026-06-17T02:39:40.280","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. GitLab Pages contains a directory traversal vulnerability that could lead to remote command execution."},{"lang":"es","value":"Se descubrió  un problema en GitLab Community and Enterprise Edition versiones anteriores a 11.5.8, versiones 11.6.x anteriores a 11.6.6 y versiones 11.7.x anteriores a 11.7.1. GitLab Pages contiene una vulnerabilidad de salto de directorio que podría conllevar a la ejecución de comandos remota."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-22"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.3.0","versionEndExcluding":"11.5.8","matchCriteriaId":"C04EEB2B-1F3C-4442-B472-AB43FBCA8F52"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.17.0","versionEndExcluding":"11.5.8","matchCriteriaId":"B1E8310C-BC10-4926-862B-DBBB0460F5CF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.6","matchCriteriaId":"794CA42E-5409-455B-956C-21BC431E0B98"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.6","matchCriteriaId":"35A01A1A-A0F1-4952-B15A-A898FD185B3F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.1","matchCriteriaId":"3BAE4B6C-8F1F-4C42-ADF9-A9CBD3895C68"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.1","matchCriteriaId":"3A67FE77-4048-41B8-8734-CA62393ED632"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/55827","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory"]},{"url":"https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/55827","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2019-6784","sourceIdentifier":"cve@mitre.org","published":"2019-09-09T20:15:11.370","lastModified":"2026-06-17T02:39:40.393","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows XSS (issue 1 of 2). Markdown fields contain a lack of input validation and output encoding when processing KaTeX that results in a persistent XSS."},{"lang":"es","value":"Se detectó un problema en GitLab Community and Enterprise Edition versiones anteriores a 11.5.8, versiones 11.6.x anteriores a 11.6.6 y versiones 11.7.x anteriores a 11.7.1. Esta permite un ataque de tipo XSS (problema 1 de 2). Los campos Markdown  contienen una falta de comprobación de entrada y codificación de salida cuando se procesa KaTeX lo que resulta en un XSS persistente."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"11.5.8","matchCriteriaId":"3505D02B-D60F-4E91-AB07-F704D04BEDF4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"11.5.8","matchCriteriaId":"5CAB52EA-9EE4-424C-80D8-0987AEDE045E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.6","matchCriteriaId":"794CA42E-5409-455B-956C-21BC431E0B98"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.6","matchCriteriaId":"35A01A1A-A0F1-4952-B15A-A898FD185B3F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.1","matchCriteriaId":"3BAE4B6C-8F1F-4C42-ADF9-A9CBD3895C68"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.1","matchCriteriaId":"3A67FE77-4048-41B8-8734-CA62393ED632"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/54416","source":"cve@mitre.org","tags":["Exploit","Issue Tracking","Third Party Advisory"]},{"url":"https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/54416","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2019-6785","sourceIdentifier":"cve@mitre.org","published":"2019-09-09T20:15:11.480","lastModified":"2026-06-17T02:39:40.510","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Denial of Service. Inputting an overly long string into a Markdown field could cause a denial of service."},{"lang":"es","value":"Se descubrió un problema en GitLab Community and Enterprise Edition versiones anteriores a 11.5.8, versiones 11.6.x anteriores a 11.6.6 y versiones 11.7.x versiones anteriores a 11.7.1. Permite una Denegación de Servicio. Introduciendo una cadena demasiado larga en un campo Markdown podría causar una denegación de servicio."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:N/A:P","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"7.4.0","versionEndExcluding":"11.5.8","matchCriteriaId":"F99DD578-237E-4654-9DD3-84DE88622327"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"7.4.0","versionEndExcluding":"11.5.8","matchCriteriaId":"78E5D5D2-0716-4354-8988-6F8E7AF4BBB3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.6","matchCriteriaId":"794CA42E-5409-455B-956C-21BC431E0B98"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.6","matchCriteriaId":"35A01A1A-A0F1-4952-B15A-A898FD185B3F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.1","matchCriteriaId":"3BAE4B6C-8F1F-4C42-ADF9-A9CBD3895C68"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.1","matchCriteriaId":"3A67FE77-4048-41B8-8734-CA62393ED632"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/52212","source":"cve@mitre.org","tags":["Exploit","Issue Tracking","Third Party Advisory"]},{"url":"https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/52212","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2019-6786","sourceIdentifier":"cve@mitre.org","published":"2019-09-09T20:15:11.587","lastModified":"2026-06-17T02:39:40.627","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control (issue 1 of 3). The contents of an LFS object can be accessed by an unauthorized user, if the file size and OID are known."},{"lang":"es","value":"Se descubrió un problema en GitLab Community and Enterprise Edition versiones anteriores a 11.5.8, versiones 11.6.x anteriores a 11.6.6 y versiones 11.7.x anteriores a 11.7.1. Presenta un Control de Acceso Incorrecto (problema 1 de 3). El contenido de un objeto LFS puede ser accedido por un usuario no autorizado, si se conoce el tamaño del archivo y el OID."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.16.0","versionEndExcluding":"11.5.8","matchCriteriaId":"A50E8534-8C18-4CCB-BB4A-6C0F3ACA0724"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.16.0","versionEndExcluding":"11.5.8","matchCriteriaId":"13B77850-1187-471B-9664-D0A73A93ECF5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.6","matchCriteriaId":"794CA42E-5409-455B-956C-21BC431E0B98"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.6","matchCriteriaId":"35A01A1A-A0F1-4952-B15A-A898FD185B3F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.1","matchCriteriaId":"3BAE4B6C-8F1F-4C42-ADF9-A9CBD3895C68"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.1","matchCriteriaId":"3A67FE77-4048-41B8-8734-CA62393ED632"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-workhorse/issues/197","source":"cve@mitre.org","tags":["Exploit","Issue Tracking","Third Party Advisory"]},{"url":"https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-workhorse/issues/197","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2019-6788","sourceIdentifier":"cve@mitre.org","published":"2019-09-09T20:15:11.697","lastModified":"2026-06-17T02:39:40.957","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Information Disclosure (issue 3 of 6). For installations using GitHub or Bitbucket OAuth integrations, it is possible to use a covert redirect to obtain the user OAuth token for those services."},{"lang":"es","value":"Se descubrió un problema en GitLab Community and Enterprise Edition versiones anteriores a 11.5.8, versiones 11.6.x anteriores a 11.6.6 y versiones 11.7.x anteriores a 11.7.1. Permite la divulgación de información (problema 3 de 6). Para instalaciones que utilizan integraciones GitHub o Bitbucket OAuth, es posible usar un redireccionamiento encubierto para obtener el token OAuth de usuario para esos servicios."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.4.0","versionEndExcluding":"11.5.8","matchCriteriaId":"806D4C17-9E82-4FE2-9B0B-C9D3DE7E9B8D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.4.0","versionEndExcluding":"11.5.8","matchCriteriaId":"766CDC3D-2834-44AB-BE10-F2C9C5C1DE66"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.6","matchCriteriaId":"794CA42E-5409-455B-956C-21BC431E0B98"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.6","matchCriteriaId":"35A01A1A-A0F1-4952-B15A-A898FD185B3F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.1","matchCriteriaId":"3BAE4B6C-8F1F-4C42-ADF9-A9CBD3895C68"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.1","matchCriteriaId":"3A67FE77-4048-41B8-8734-CA62393ED632"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/56663","source":"cve@mitre.org","tags":["Exploit","Issue Tracking","Third Party Advisory"]},{"url":"https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/56663","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2019-6789","sourceIdentifier":"cve@mitre.org","published":"2019-09-09T20:15:11.807","lastModified":"2026-06-17T02:39:41.077","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Information Disclosure (issue 4 of 6). In some cases, users without project permissions will receive emails after a project move. For private projects, this will disclose the new project namespace to an unauthorized user."},{"lang":"es","value":"Se descubrió un problema en GitLab Community and Enterprise Edition versiones anteriores a 11.5.8, versiones 11.6.x anteriores a 11.6.6 y versiones 11.7.x anteriores a 11.7.1. Permite la divulgación de información (problema 4 de 6). En algunos casos, usuarios sin permisos de proyecto recibirán correos electrónicos después de un movimiento de proyecto. Para los proyectos privados, esto revelará el espacio de nombres de un nuevo proyecto a un usuario no autorizado."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-269"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"6.5.0","versionEndExcluding":"11.5.8","matchCriteriaId":"F1AEC997-3D1B-4787-AA1D-1BB895B9CBBF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"6.5.0","versionEndExcluding":"11.5.8","matchCriteriaId":"8CD16FE5-224A-4626-B748-52045F1BB440"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.6","matchCriteriaId":"794CA42E-5409-455B-956C-21BC431E0B98"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.6","matchCriteriaId":"35A01A1A-A0F1-4952-B15A-A898FD185B3F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.1","matchCriteriaId":"3BAE4B6C-8F1F-4C42-ADF9-A9CBD3895C68"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.1","matchCriteriaId":"3A67FE77-4048-41B8-8734-CA62393ED632"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/44558","source":"cve@mitre.org","tags":["Exploit","Issue Tracking","Third Party Advisory"]},{"url":"https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/44558","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2019-6792","sourceIdentifier":"cve@mitre.org","published":"2019-09-09T20:15:12.027","lastModified":"2026-06-17T02:39:41.413","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Path Disclosure. When an error is encountered on project import, the error message will display instance internal information."},{"lang":"es","value":"Se detectó un problema en GitLab Community and Enterprise Edition versiones anteriores a 11.5.8, versiones 11.6.x anteriores a 11.6.6 y versiones 11.7.x anteriores a 11.7.1. Permite una Divulgación de Ruta. Cuando un error es encontrado en la importación del proyecto, el mensaje de error desplegará información interna de la instancia."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-209"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.9.0","versionEndExcluding":"11.5.8","matchCriteriaId":"24D6DCD1-4380-4C02-A431-8BD500B3A5D6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.9.0","versionEndExcluding":"11.5.8","matchCriteriaId":"842FD31B-E10A-44C3-AC3C-DCA9A695977E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.6","matchCriteriaId":"794CA42E-5409-455B-956C-21BC431E0B98"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.6","matchCriteriaId":"35A01A1A-A0F1-4952-B15A-A898FD185B3F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.1","matchCriteriaId":"3BAE4B6C-8F1F-4C42-ADF9-A9CBD3895C68"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.1","matchCriteriaId":"3A67FE77-4048-41B8-8734-CA62393ED632"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/54867","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory"]},{"url":"https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/54867","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2019-6793","sourceIdentifier":"cve@mitre.org","published":"2019-09-09T20:15:12.120","lastModified":"2026-06-17T02:39:41.530","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. The Jira integration feature is vulnerable to an unauthenticated blind SSRF issue."},{"lang":"es","value":"Se detectó un problema en GitLab Enterprise Edition versiones anteriores a 11.5.8, versiones 11.6.x anteriores a 11.6.6 y versiones 11.7.x anteriores a 11.7.1. La funcionalidad de integración de Jira es vulnerable a un problema de tipo SSRF ciego no autenticado."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L","baseScore":7.0,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":2.2,"impactScore":4.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.0.0","versionEndExcluding":"11.5.8","matchCriteriaId":"6D95C1CC-D04B-4C03-8414-8385D20C45BD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.6","matchCriteriaId":"35A01A1A-A0F1-4952-B15A-A898FD185B3F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.1","matchCriteriaId":"3A67FE77-4048-41B8-8734-CA62393ED632"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/50748","source":"cve@mitre.org","tags":["Exploit","Issue Tracking","Third Party Advisory"]},{"url":"https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/50748","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2019-6794","sourceIdentifier":"cve@mitre.org","published":"2019-09-09T20:15:12.197","lastModified":"2026-06-17T02:39:41.647","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Information Disclosure (issue 5 of 6). A project guest user can view the last commit status of the default branch."},{"lang":"es","value":"Se detectó un problema en GitLab Community and Enterprise Edition versiones anteriores a 11.5.8, versiones 11.6.x anteriores a 11.6.6 y versiones 11.7.x anteriores a 11.7.1. Permite la divulgación de información (problema 5 de 6). Un usuario invitado del proyecto puede visualizar el último estado de confirmación de la derivación predeterminada."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-269"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"11.5.8","matchCriteriaId":"3505D02B-D60F-4E91-AB07-F704D04BEDF4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"11.5.8","matchCriteriaId":"5CAB52EA-9EE4-424C-80D8-0987AEDE045E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.6","matchCriteriaId":"794CA42E-5409-455B-956C-21BC431E0B98"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.6","matchCriteriaId":"35A01A1A-A0F1-4952-B15A-A898FD185B3F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.1","matchCriteriaId":"3BAE4B6C-8F1F-4C42-ADF9-A9CBD3895C68"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.1","matchCriteriaId":"3A67FE77-4048-41B8-8734-CA62393ED632"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/54353","source":"cve@mitre.org","tags":["Exploit","Issue Tracking"]},{"url":"https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/54353","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking"]}]}},{"cve":{"id":"CVE-2019-6795","sourceIdentifier":"cve@mitre.org","published":"2019-09-09T20:15:12.277","lastModified":"2026-06-17T02:39:41.757","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Insufficient Visual Distinction of Homoglyphs Presented to a User. IDN homographs and RTLO characters are rendered to unicode, which could be used for social engineering."},{"lang":"es","value":"Se detectó un problema en GitLab Community and Enterprise Edition versiones anteriores a 11.5.8, versiones 11.6.x anteriores a 11.6.6 y versiones 11.7.x anteriores a 11.7.1. Presenta una Distinción Visual Insuficiente de Homoglifos Presentados a un Usuario. Los homógrafos IDN y los caracteres RTLO son renderizados en unicode, lo que podría ser usado para ingeniería social."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.5}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:N","baseScore":5.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"11.5.8","matchCriteriaId":"3505D02B-D60F-4E91-AB07-F704D04BEDF4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"11.5.8","matchCriteriaId":"5CAB52EA-9EE4-424C-80D8-0987AEDE045E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.6","matchCriteriaId":"794CA42E-5409-455B-956C-21BC431E0B98"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.6","matchCriteriaId":"35A01A1A-A0F1-4952-B15A-A898FD185B3F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.1","matchCriteriaId":"3BAE4B6C-8F1F-4C42-ADF9-A9CBD3895C68"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.1","matchCriteriaId":"3A67FE77-4048-41B8-8734-CA62393ED632"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/29365","source":"cve@mitre.org","tags":["Exploit","Issue Tracking","Third Party Advisory"]},{"url":"https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/29365","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2019-6960","sourceIdentifier":"cve@mitre.org","published":"2019-09-09T20:15:12.557","lastModified":"2026-06-17T02:39:49.497","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. Access to the internal wiki is permitted when an external wiki service is enabled."},{"lang":"es","value":"Se detectó un problema en GitLab Community and Enterprise Edition versiones 9.x, 10.x y versiones 11.x anteriores a 11.5.8, versiones 11.6.x anteriores a 11.6.6 y versiones 11.7.x anteriores a 11.7.1. Presenta un Control de Acceso Incorrecto. Se permite el acceso a la wiki interna cuando un servicio wiki externo es habilitado."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"9.3.0","versionEndIncluding":"9.3.7","matchCriteriaId":"2EE1F061-BCF5-4182-8705-DC2D8D584546"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"9.3.0","versionEndIncluding":"9.3.7","matchCriteriaId":"37085F7A-5F2D-4EF5-8877-547C4BE402DE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.0.0","versionEndIncluding":"10.8.7","matchCriteriaId":"90A2B0E7-9793-4CAB-B715-7000A0361C31"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.0.0","versionEndIncluding":"10.8.7","matchCriteriaId":"6F0E5540-3274-4ADF-8028-E3A4AD176661"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"11.5.8","matchCriteriaId":"FAC5BA5A-3493-4495-AD33-97CD61A04C59"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"11.5.8","matchCriteriaId":"B4FF27FC-A5B8-43DE-865C-60F7F2AE7F64"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.6","matchCriteriaId":"794CA42E-5409-455B-956C-21BC431E0B98"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.6","matchCriteriaId":"35A01A1A-A0F1-4952-B15A-A898FD185B3F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.1","matchCriteriaId":"3BAE4B6C-8F1F-4C42-ADF9-A9CBD3895C68"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.1","matchCriteriaId":"3A67FE77-4048-41B8-8734-CA62393ED632"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/54357","source":"cve@mitre.org","tags":["Exploit","Issue Tracking","Third Party Advisory"]},{"url":"https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/54357","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2019-6995","sourceIdentifier":"cve@mitre.org","published":"2019-09-09T20:15:12.637","lastModified":"2026-06-17T02:39:53.523","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 8.x, 9.x, 10.x, and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. Users are able to comment on locked project issues."},{"lang":"es","value":"Se detectó un problema en GitLab Community and Enterprise Edition 8.x, 9.x, 10.xy versiones 11.x anteriores a 11.5.8, versiones 11.6.x anteriores a 11.6.6 y versiones 11.7.x anteriores a 11.7.1. Presenta un Control de Acceso Incorrecto. Los usuarios pueden comentar sobre problemas de proyectos bloqueados."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-281"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.6.0","versionEndIncluding":"8.17.8","matchCriteriaId":"F8C2C23F-40B5-4EA1-BA30-49CC5FFB105C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.6.0","versionEndIncluding":"8.17.8","matchCriteriaId":"F83668B0-4D78-47F4-AE5E-BC590320B6DF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"9.0.0","versionEndIncluding":"9.3.7","matchCriteriaId":"A855DD8E-C4FD-4C93-9EC9-D2CEE9A36DE8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"9.0.0","versionEndIncluding":"9.3.7","matchCriteriaId":"17EBDEFE-775B-4D7D-87CE-F3001276A385"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.0.0","versionEndIncluding":"10.8.7","matchCriteriaId":"90A2B0E7-9793-4CAB-B715-7000A0361C31"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.0.0","versionEndIncluding":"10.8.7","matchCriteriaId":"6F0E5540-3274-4ADF-8028-E3A4AD176661"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"11.5.8","matchCriteriaId":"FAC5BA5A-3493-4495-AD33-97CD61A04C59"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"11.5.8","matchCriteriaId":"B4FF27FC-A5B8-43DE-865C-60F7F2AE7F64"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.6","matchCriteriaId":"794CA42E-5409-455B-956C-21BC431E0B98"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.6","matchCriteriaId":"35A01A1A-A0F1-4952-B15A-A898FD185B3F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.1","matchCriteriaId":"3BAE4B6C-8F1F-4C42-ADF9-A9CBD3895C68"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.1","matchCriteriaId":"3A67FE77-4048-41B8-8734-CA62393ED632"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/55537","source":"cve@mitre.org","tags":["Exploit","Issue Tracking","Third Party Advisory"]},{"url":"https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/55537","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2019-6996","sourceIdentifier":"cve@mitre.org","published":"2019-09-09T20:15:12.697","lastModified":"2026-06-17T02:39:53.647","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Enterprise Edition 10.x (starting in 10.6) and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. The merge request approvers section has an access control issue that permits project maintainers to view membership of private groups."},{"lang":"es","value":"Se detectó un problema en GitLab Enterprise Edition versiones 10.x (a partir de la 10.6) y versiones 11.x anteriores a 11.5.8, versiones 11.6.x anteriores a 11.6.6 y versiones 11.7.x anteriores a 11.7.1. Presenta un Control de Acceso Incorrecto. La sección de aprobadores de peticiones de fusión presenta un problema de control de acceso que permite a los mantenedores del proyecto visualizar el numero de miembros de grupos privados."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-269"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.6.0","versionEndIncluding":"10.8.7","matchCriteriaId":"94907C86-15C5-4560-A1AF-01935D029F8A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.6.0","versionEndIncluding":"10.8.7","matchCriteriaId":"0DF1771E-338F-4653-B333-B79201BBAD04"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"11.5.8","matchCriteriaId":"FAC5BA5A-3493-4495-AD33-97CD61A04C59"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"11.5.8","matchCriteriaId":"B4FF27FC-A5B8-43DE-865C-60F7F2AE7F64"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.6","matchCriteriaId":"794CA42E-5409-455B-956C-21BC431E0B98"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.6","matchCriteriaId":"35A01A1A-A0F1-4952-B15A-A898FD185B3F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.1","matchCriteriaId":"3BAE4B6C-8F1F-4C42-ADF9-A9CBD3895C68"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.1","matchCriteriaId":"3A67FE77-4048-41B8-8734-CA62393ED632"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ee/issues/8187","source":"cve@mitre.org","tags":["Issue Tracking","Third Party Advisory"]},{"url":"https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ee/issues/8187","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2019-6997","sourceIdentifier":"cve@mitre.org","published":"2019-09-09T20:15:12.777","lastModified":"2026-06-17T02:39:53.760","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 10.x (starting in 10.7) and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. System notes contain an access control issue that permits a guest user to view merge request titles."},{"lang":"es","value":"Se detectó un problema en GitLab Community and Enterprise Edition versiones 10.x (a partir de la 10.7) y versiones 11.x anteriores a 11.5.8, versiones 11.6.x anteriores a 11.6.6 y versiones 11.7.x anteriores a 11.7.1. Presenta un Control de Acceso Incorrecto. Las notas del sistema contienen un problema de control de acceso que permite a un usuario invitado visualizar los títulos de las peticiones de fusión."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-269"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.7.0","versionEndIncluding":"10.8.7","matchCriteriaId":"D350954A-23EB-4A2A-A039-A7844839C591"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.7.0","versionEndIncluding":"10.8.7","matchCriteriaId":"C049FE18-A814-4B59-A434-EF1BB2AF6702"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"11.5.8","matchCriteriaId":"FAC5BA5A-3493-4495-AD33-97CD61A04C59"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"11.5.8","matchCriteriaId":"B4FF27FC-A5B8-43DE-865C-60F7F2AE7F64"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.6","matchCriteriaId":"794CA42E-5409-455B-956C-21BC431E0B98"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.6","matchCriteriaId":"35A01A1A-A0F1-4952-B15A-A898FD185B3F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.1","matchCriteriaId":"3BAE4B6C-8F1F-4C42-ADF9-A9CBD3895C68"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.1","matchCriteriaId":"3A67FE77-4048-41B8-8734-CA62393ED632"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/53858","source":"cve@mitre.org","tags":["Exploit","Issue Tracking","Third Party Advisory"]},{"url":"https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/53858","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2019-6791","sourceIdentifier":"cve@mitre.org","published":"2019-09-09T21:15:12.247","lastModified":"2026-06-17T02:39:41.307","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control (issue 3 of 3). When a project with visibility more permissive than the target group is imported, it will retain its prior visibility."},{"lang":"es","value":"Se descubrió un problema en GitLab Community and Enterprise Edition versiones anteriores a 11.5.8, versiones 11.6.x anteriores a 11.6.6 y versiones 11.7.x anteriores a 11.7.1. Este presenta un Control de Acceso Incorrecto (problema 3 de 3). Cuando es importado un proyecto con visibilidad más permisiva que el grupo destino, conservará su visibilidad previa."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-281"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"11.5.8","matchCriteriaId":"3505D02B-D60F-4E91-AB07-F704D04BEDF4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"11.5.8","matchCriteriaId":"5CAB52EA-9EE4-424C-80D8-0987AEDE045E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.6","matchCriteriaId":"794CA42E-5409-455B-956C-21BC431E0B98"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.6","matchCriteriaId":"35A01A1A-A0F1-4952-B15A-A898FD185B3F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.1","matchCriteriaId":"3BAE4B6C-8F1F-4C42-ADF9-A9CBD3895C68"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.1","matchCriteriaId":"3A67FE77-4048-41B8-8734-CA62393ED632"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-7176","sourceIdentifier":"cve@mitre.org","published":"2019-09-09T21:15:12.310","lastModified":"2026-06-17T02:40:13.393","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 8.x (starting in 8.9), 9.x, 10.x, and 11.x before 11.5.9, 11.6.x before 11.6.7, and 11.7.x before 11.7.2. It has Incorrect Access Control. Guest users are able to add reaction emojis on comments to which they have no visibility."},{"lang":"es","value":"Se descubrió un problema en GitLab Community and Enterprise Edition versiones 8.x (a partir de 8.9), 9.x, 10.xy versiones 11.x anteriores a 11.5.9, versiones 11.6.x anteriores a 11.6.7 y versiones 11.7.x anteriores a 11.7 .2. Presenta un Control de Acceso Incorrecto. Los usuarios invitados son capaces de agregar emojis de reacción sobre los comentarios a los que no tienen visibilidad."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":3.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.9.0","versionEndIncluding":"8.17.8","matchCriteriaId":"B536E005-10A9-4565-9869-7224AAF6648E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.9.0","versionEndIncluding":"8.17.8","matchCriteriaId":"F6C96F7D-F00D-46CC-BB02-4D4ABB18EFDE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"9.0.0","versionEndIncluding":"9.5.10","matchCriteriaId":"9B7A2187-0C1C-4B6C-8F1F-5317331A3C0B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"9.0.0","versionEndIncluding":"9.5.10","matchCriteriaId":"6B3402C2-32D0-4B4E-B889-07863D0BAF3B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.0.0","versionEndIncluding":"10.8.6","matchCriteriaId":"CE674BC6-C506-4C78-BFF9-9712287335A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.0.0","versionEndIncluding":"10.8.6","matchCriteriaId":"D40668CD-9579-41E6-A7DD-0781C7A6821D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"11.5.9","matchCriteriaId":"1D057D26-5077-4099-A59E-55DA0511D96B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"11.5.9","matchCriteriaId":"5639D450-3B78-4734-88DF-E2B092BD9FF2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.7","matchCriteriaId":"F874EDD7-9C84-4679-B331-92BC00479C8C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.7","matchCriteriaId":"BED534AF-E1D1-4EBE-8B76-347F917CCD7A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.2","matchCriteriaId":"F59BB2A7-BEF2-469C-B2E1-186F3238B588"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"11.7.2","matchCriteriaId":"407E2D05-7924-4F3B-A91B-DCEDB1E674C3"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/51332","source":"cve@mitre.org","tags":["Exploit","Vendor Advisory"]},{"url":"https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/51332","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-16170","sourceIdentifier":"cve@mitre.org","published":"2019-09-16T12:15:10.987","lastModified":"2026-06-17T02:21:49.023","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Enterprise Edition 11.x and 12.x before 12.0.9, 12.1.x before 12.1.9, and 12.2.x before 12.2.5. It has Incorrect Access Control."},{"lang":"es","value":"Se descubrió un problema en GitLab Enterprise Edition versiones 11.x y versiones 12.x anteriores a 12.0.9, versiones 12.1.x anteriores a 12.1.9 y versiones 12.2.x anteriores a 12.2.5. Posee un Control de Acceso Incorrecto."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":4.2}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:N","baseScore":5.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"12.0.9","matchCriteriaId":"DE9A8400-C2A0-417C-8FDB-CE8D216E31AF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"12.0.9","matchCriteriaId":"440C97F3-4803-419A-94E9-8B6E08F2C825"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.9","matchCriteriaId":"F4354B8E-EA38-456C-A4AA-2BE6E1904DC8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.9","matchCriteriaId":"EDA37C18-D023-4A32-87BC-FC07957F629D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.5","matchCriteriaId":"FCC9C579-7C00-407A-B12C-128E6664F541"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.5","matchCriteriaId":"D688C1C9-15A4-4361-BB16-00D526AE1F09"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/09/10/critical-security-release-gitlab-12-dot-2-dot-5-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/2019/09/10/critical-security-release-gitlab-12-dot-2-dot-5-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-15721","sourceIdentifier":"cve@mitre.org","published":"2019-09-16T17:15:13.387","lastModified":"2026-06-17T02:20:56.687","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 10.8 through 12.2.1. An internal endpoint unintentionally allowed group maintainers to view and edit group runner settings."},{"lang":"es","value":"Se descubrió un problema en GitLab Community and Enterprise Edition versiones 10.8 hasta 12.2.1. Un end point interno permitió involuntariamente a los mantenedores del grupo visualizar y editar la configuración del ejecutor de grupo."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.5}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:N","baseScore":5.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-732"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.8.0","versionEndExcluding":"12.0.8","matchCriteriaId":"C596882A-485A-45C4-A85F-3FC1044B2F11"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.8.0","versionEndExcluding":"12.0.8","matchCriteriaId":"CD31C743-3A9C-4033-BAF8-2421526DCBC6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.8","matchCriteriaId":"BE0BA50B-833E-4F74-95CB-EC8963B0ABCA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.8","matchCriteriaId":"36F29405-3C84-4ECF-96B7-E25D88926B46"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.3","matchCriteriaId":"16FD6BD6-8B76-4053-81C1-E9B00F279113"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.3","matchCriteriaId":"F131A404-4B2B-4F77-981B-A12D8FC7F590"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/08/29/security-release-gitlab-12-dot-2-dot-3-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/61981","source":"cve@mitre.org","tags":["Broken Link"]},{"url":"https://about.gitlab.com/2019/08/29/security-release-gitlab-12-dot-2-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/61981","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2019-15722","sourceIdentifier":"cve@mitre.org","published":"2019-09-16T17:15:13.447","lastModified":"2026-06-17T02:20:56.817","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.2.1. Particular mathematical expressions in GitLab Markdown can exhaust client resources."},{"lang":"es","value":"Se descubrió un problema en GitLab Community and Enterprise Edition versiones 8.15 hasta 12.2.1. Las expresiones matemáticas particulares en GitLab Markdown pueden agotar los recursos del cliente."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.15.0","versionEndExcluding":"12.0.8","matchCriteriaId":"A78EDFFF-DA5D-4A7A-BE4E-C94983CB57C9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.15.0","versionEndExcluding":"12.0.8","matchCriteriaId":"00EEF6D2-797F-4AB5-8043-7E9EF9B0405A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.8","matchCriteriaId":"BE0BA50B-833E-4F74-95CB-EC8963B0ABCA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.8","matchCriteriaId":"36F29405-3C84-4ECF-96B7-E25D88926B46"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.3","matchCriteriaId":"16FD6BD6-8B76-4053-81C1-E9B00F279113"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.3","matchCriteriaId":"F131A404-4B2B-4F77-981B-A12D8FC7F590"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/08/29/security-release-gitlab-12-dot-2-dot-3-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/61410","source":"cve@mitre.org","tags":["Broken Link"]},{"url":"https://about.gitlab.com/2019/08/29/security-release-gitlab-12-dot-2-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/61410","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2019-15723","sourceIdentifier":"cve@mitre.org","published":"2019-09-16T17:15:13.510","lastModified":"2026-06-17T02:20:56.950","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 11.9.x and 11.10.x before 11.10.1. Merge requests created by email could be used to bypass push rules in certain situations."},{"lang":"es","value":"Se descubrió un problema en GitLab Community and Enterprise Edition versiones 11.9.x y versiones 11.10.x anteriores a 11.10.1. Las peticiones de fusión creadas por medio del correo electrónico podrían ser usadas para omitir las reglas de inserción en ciertas situaciones."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.9.4","versionEndExcluding":"11.10.1","matchCriteriaId":"278865F5-8172-4FE7-A60B-BE34B7352D0A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.9.4","versionEndExcluding":"11.10.1","matchCriteriaId":"BD91AE4F-70DA-434B-8B11-C273065E7026"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/08/29/security-release-gitlab-12-dot-2-dot-3-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ee/issues/11302","source":"cve@mitre.org","tags":["Broken Link"]},{"url":"https://about.gitlab.com/2019/08/29/security-release-gitlab-12-dot-2-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ee/issues/11302","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2019-15724","sourceIdentifier":"cve@mitre.org","published":"2019-09-16T17:15:13.573","lastModified":"2026-06-17T02:20:57.080","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 11.10 through 12.2.1. Label descriptions are vulnerable to HTML injection."},{"lang":"es","value":"Se descubrió  un problema en GitLab Community and Enterprise Edition versiones 11.10 hasta 12.2.1. Las descripciones de etiquetas son vulnerables a la inyección HTML."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.10.0","versionEndExcluding":"12.0.8","matchCriteriaId":"C6C5A538-1FD5-491A-9F31-46E8E928A378"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.10.0","versionEndExcluding":"12.0.8","matchCriteriaId":"870ACEDC-866A-46A9-BA58-E33E9BF81134"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.8","matchCriteriaId":"BE0BA50B-833E-4F74-95CB-EC8963B0ABCA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.8","matchCriteriaId":"36F29405-3C84-4ECF-96B7-E25D88926B46"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.3","matchCriteriaId":"16FD6BD6-8B76-4053-81C1-E9B00F279113"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.3","matchCriteriaId":"F131A404-4B2B-4F77-981B-A12D8FC7F590"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/08/29/security-release-gitlab-12-dot-2-dot-3-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/60888","source":"cve@mitre.org","tags":["Broken Link"]},{"url":"https://about.gitlab.com/2019/08/29/security-release-gitlab-12-dot-2-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/60888","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2019-15725","sourceIdentifier":"cve@mitre.org","published":"2019-09-16T17:15:13.637","lastModified":"2026-06-17T02:20:57.227","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1. An IDOR in the epic notes API that could result in disclosure of private milestones, labels, and other information."},{"lang":"es","value":"Se descubrió un problema en GitLab Community and Enterprise Edition versiones 12.0 hasta 12.2.1. Un IDOR en la API de notas épicas que podría resultar en la divulgación de hitos privados, etiquetas y otra información."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-639"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.0.0","versionEndExcluding":"12.0.8","matchCriteriaId":"792A801A-476C-4716-9F81-420D6173DC34"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.0.0","versionEndExcluding":"12.0.8","matchCriteriaId":"B753BB0E-F68E-4876-980F-AB041F2951F5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.8","matchCriteriaId":"BE0BA50B-833E-4F74-95CB-EC8963B0ABCA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.8","matchCriteriaId":"36F29405-3C84-4ECF-96B7-E25D88926B46"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.3","matchCriteriaId":"16FD6BD6-8B76-4053-81C1-E9B00F279113"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.3","matchCriteriaId":"F131A404-4B2B-4F77-981B-A12D8FC7F590"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/08/29/security-release-gitlab-12-dot-2-dot-3-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ee/issues/11431","source":"cve@mitre.org","tags":["Broken Link"]},{"url":"https://about.gitlab.com/2019/08/29/security-release-gitlab-12-dot-2-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ee/issues/11431","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2019-15726","sourceIdentifier":"cve@mitre.org","published":"2019-09-16T17:15:13.697","lastModified":"2026-06-17T02:20:57.360","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition through 12.2.1. Embedded images and media files in markdown could be pointed to an arbitrary server, which would reveal the IP address of clients requesting the file from that server."},{"lang":"es","value":"Se descubrió un problema en GitLab Community and Enterprise Edition versiones hasta 12.2.1. Las imágenes y los archivos multimedia  insertados en Markdown podrían ser apuntados hacia un servidor arbitrario, que revelaría la dirección IP de los clientes que solicitan el archivo desde ese servidor."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"12.0.8","matchCriteriaId":"7E976358-BD88-4E56-9EC1-890DB7DA57B9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"12.0.8","matchCriteriaId":"E39D35BA-555B-4A29-8AC8-59051C1A6FCF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.8","matchCriteriaId":"BE0BA50B-833E-4F74-95CB-EC8963B0ABCA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.8","matchCriteriaId":"36F29405-3C84-4ECF-96B7-E25D88926B46"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.3","matchCriteriaId":"16FD6BD6-8B76-4053-81C1-E9B00F279113"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.3","matchCriteriaId":"F131A404-4B2B-4F77-981B-A12D8FC7F590"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/08/29/security-release-gitlab-12-dot-2-dot-3-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/55115","source":"cve@mitre.org","tags":["Broken Link"]},{"url":"https://about.gitlab.com/2019/08/29/security-release-gitlab-12-dot-2-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/55115","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2019-15727","sourceIdentifier":"cve@mitre.org","published":"2019-09-16T17:15:13.823","lastModified":"2026-06-17T02:20:57.493","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 11.2 through 12.2.1. Insufficient permission checks were being applied when displaying CI results, potentially exposing some CI metrics data to unauthorized users."},{"lang":"es","value":"Se descubrió un problema en GitLab Community and Enterprise Edition versiones 11.2 hasta 12.2.1. Se aplicaron comprobaciones de permisos insuficientes cuando se mostraron los resultados de CI, exponiendo potencialmente algunos datos de métricas de CI a usuarios no autorizados."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-200"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.2.0","versionEndExcluding":"12.0.8","matchCriteriaId":"C0D64621-2E24-4698-B116-0FCC6EE6D30F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.2.0","versionEndExcluding":"12.0.8","matchCriteriaId":"5AC10563-1F00-4CAB-94E0-8464E5DBA517"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.8","matchCriteriaId":"BE0BA50B-833E-4F74-95CB-EC8963B0ABCA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.8","matchCriteriaId":"36F29405-3C84-4ECF-96B7-E25D88926B46"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.3","matchCriteriaId":"16FD6BD6-8B76-4053-81C1-E9B00F279113"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.3","matchCriteriaId":"F131A404-4B2B-4F77-981B-A12D8FC7F590"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/08/29/security-release-gitlab-12-dot-2-dot-3-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ee/issues/11426","source":"cve@mitre.org","tags":["Broken Link"]},{"url":"https://about.gitlab.com/2019/08/29/security-release-gitlab-12-dot-2-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ee/issues/11426","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2019-15728","sourceIdentifier":"cve@mitre.org","published":"2019-09-16T17:15:13.900","lastModified":"2026-06-17T02:20:57.627","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 10.1 through 12.2.1. Protections against SSRF attacks on the Kubernetes integration are insufficient, which could have allowed an attacker to request any local network resource accessible from the GitLab server."},{"lang":"es","value":"Se descubrió  un problema en GitLab Community and Enterprise Edition versiones 10.1 hasta 12.2.1. Las protecciones contra ataques de tipo SSRF en la integración de Kubernetes son insuficientes, lo que podría haber permitido a un atacante solicitar cualquier recurso de red local accesible desde el servidor GitLab."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.1.0","versionEndExcluding":"12.0.8","matchCriteriaId":"69ED47DA-AAEA-4F30-8BED-D578600D0E96"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.1.0","versionEndExcluding":"12.0.8","matchCriteriaId":"6B419121-58BB-44DB-BF37-F8D285F457A3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.8","matchCriteriaId":"BE0BA50B-833E-4F74-95CB-EC8963B0ABCA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.8","matchCriteriaId":"36F29405-3C84-4ECF-96B7-E25D88926B46"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.3","matchCriteriaId":"16FD6BD6-8B76-4053-81C1-E9B00F279113"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.3","matchCriteriaId":"F131A404-4B2B-4F77-981B-A12D8FC7F590"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/08/29/security-release-gitlab-12-dot-2-dot-3-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/61314","source":"cve@mitre.org","tags":["Broken Link"]},{"url":"https://about.gitlab.com/2019/08/29/security-release-gitlab-12-dot-2-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/61314","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2019-15730","sourceIdentifier":"cve@mitre.org","published":"2019-09-16T17:15:13.963","lastModified":"2026-06-17T02:20:57.890","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 8.14 through 12.2.1. The Jira integration contains a SSRF vulnerability as a result of a bypass of the current protection mechanisms against this type of attack, which would allow sending requests to any resources accessible in the local network by the GitLab server."},{"lang":"es","value":"Se descubrió  un problema en GitLab Community and Enterprise Edition versiones 8.14 hasta 12.2.1. La integración de Jira contiene una vulnerabilidad de tipo SSRF como resultado de una omisión de los mecanismos de protección actuales contra este tipo de ataque, lo que permitiría enviar peticiones a cualquier recurso accesible en la red local por parte del servidor de GitLab."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.14.0","versionEndExcluding":"12.0.8","matchCriteriaId":"28AD579F-A464-4003-991C-5AEB8CD146C8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.14.0","versionEndExcluding":"12.0.8","matchCriteriaId":"967DB3A8-EA87-4BEF-B8BA-CE018ED08F65"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.8","matchCriteriaId":"BE0BA50B-833E-4F74-95CB-EC8963B0ABCA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.8","matchCriteriaId":"36F29405-3C84-4ECF-96B7-E25D88926B46"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.3","matchCriteriaId":"16FD6BD6-8B76-4053-81C1-E9B00F279113"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.3","matchCriteriaId":"F131A404-4B2B-4F77-981B-A12D8FC7F590"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/08/29/security-release-gitlab-12-dot-2-dot-3-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/61349","source":"cve@mitre.org","tags":["Broken Link"]},{"url":"https://about.gitlab.com/2019/08/29/security-release-gitlab-12-dot-2-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/61349","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2019-15731","sourceIdentifier":"cve@mitre.org","published":"2019-09-16T17:15:14.073","lastModified":"2026-06-17T02:20:58.027","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1. Non-members were able to comment on merge requests despite the repository being set to allow only project members to do so."},{"lang":"es","value":"Se descubrió un problema en GitLab Community and Enterprise Edition versiones 12.0 hasta 12.2.1. Los no miembros eran capaces de comentar en las peticiones de fusión a pesar de que el repositorio se configuró para permitir que solo los miembros del proyecto lo hagan."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.0.0","versionEndExcluding":"12.0.8","matchCriteriaId":"792A801A-476C-4716-9F81-420D6173DC34"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.0.0","versionEndExcluding":"12.0.8","matchCriteriaId":"B753BB0E-F68E-4876-980F-AB041F2951F5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.8","matchCriteriaId":"BE0BA50B-833E-4F74-95CB-EC8963B0ABCA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.8","matchCriteriaId":"36F29405-3C84-4ECF-96B7-E25D88926B46"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.3","matchCriteriaId":"16FD6BD6-8B76-4053-81C1-E9B00F279113"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.3","matchCriteriaId":"F131A404-4B2B-4F77-981B-A12D8FC7F590"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/08/29/security-release-gitlab-12-dot-2-dot-3-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/60465","source":"cve@mitre.org","tags":["Broken Link"]},{"url":"https://about.gitlab.com/2019/08/29/security-release-gitlab-12-dot-2-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/60465","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2019-15732","sourceIdentifier":"cve@mitre.org","published":"2019-09-16T17:15:14.137","lastModified":"2026-06-17T02:20:58.160","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 12.2 through 12.2.1. The project import API could be used to bypass project visibility restrictions."},{"lang":"es","value":"Se descubrió un problema en GitLab Community and Enterprise Edition versiones 12.2 hasta 12.2.1. La API de importación de proyectos podría ser usada para omitir las restricciones de visibilidad del proyecto."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.3","matchCriteriaId":"16FD6BD6-8B76-4053-81C1-E9B00F279113"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.3","matchCriteriaId":"F131A404-4B2B-4F77-981B-A12D8FC7F590"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/08/29/security-release-gitlab-12-dot-2-dot-3-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/57015","source":"cve@mitre.org","tags":["Broken Link"]},{"url":"https://about.gitlab.com/2019/08/29/security-release-gitlab-12-dot-2-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/57015","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2019-15733","sourceIdentifier":"cve@mitre.org","published":"2019-09-16T17:15:14.213","lastModified":"2026-06-17T02:20:58.310","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 7.12 through 12.2.1. The specified default branch name could be exposed to unauthorized users."},{"lang":"es","value":"Se descubrió  un problema en GitLab Community and Enterprise Edition versiones 7.12 hasta 12.2.1. El nombre predeterminado de la derivación especificada podría estar expuesto a usuarios no autorizados."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-200"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"7.12.0","versionEndExcluding":"12.0.8","matchCriteriaId":"E0658F99-CE3C-4866-87B7-15F914CD2294"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"7.12.0","versionEndExcluding":"12.0.8","matchCriteriaId":"7D1A2E27-5904-4FF1-BF0A-BE21EC00B729"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.8","matchCriteriaId":"BE0BA50B-833E-4F74-95CB-EC8963B0ABCA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.8","matchCriteriaId":"36F29405-3C84-4ECF-96B7-E25D88926B46"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.3","matchCriteriaId":"16FD6BD6-8B76-4053-81C1-E9B00F279113"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.3","matchCriteriaId":"F131A404-4B2B-4F77-981B-A12D8FC7F590"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/08/29/security-release-gitlab-12-dot-2-dot-3-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/61210","source":"cve@mitre.org","tags":["Broken Link"]},{"url":"https://about.gitlab.com/2019/08/29/security-release-gitlab-12-dot-2-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/61210","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2019-15734","sourceIdentifier":"cve@mitre.org","published":"2019-09-16T18:15:11.610","lastModified":"2026-06-17T02:20:58.447","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 8.6 through 12.2.1. Under very specific conditions, commit titles and team member comments could become viewable to users who did not have permission to access these."},{"lang":"es","value":"Se descubrió un problema en GitLab Community and Enterprise Edition versiones 8.6 hasta 12.2.1. Bajo condiciones muy específicas, los títulos de commit y los comentarios de los miembros del equipo podrían ser visualizables para usuarios que no tenían permiso para acceder a ellos."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-200"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.6.0","versionEndExcluding":"12.0.8","matchCriteriaId":"2425BB75-C189-4C9C-8CD0-E8D3BEBDAD73"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.6.0","versionEndExcluding":"12.0.8","matchCriteriaId":"87F78D8A-516D-4716-B367-1521B4712AAD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.8","matchCriteriaId":"BE0BA50B-833E-4F74-95CB-EC8963B0ABCA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.8","matchCriteriaId":"36F29405-3C84-4ECF-96B7-E25D88926B46"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.3","matchCriteriaId":"16FD6BD6-8B76-4053-81C1-E9B00F279113"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.3","matchCriteriaId":"F131A404-4B2B-4F77-981B-A12D8FC7F590"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/08/29/security-release-gitlab-12-dot-2-dot-3-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/64711","source":"cve@mitre.org","tags":["Broken Link"]},{"url":"https://about.gitlab.com/2019/08/29/security-release-gitlab-12-dot-2-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/64711","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2019-15736","sourceIdentifier":"cve@mitre.org","published":"2019-09-16T18:15:11.707","lastModified":"2026-06-17T02:20:58.573","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition through 12.2.1. Under certain circumstances, CI pipelines could potentially be used in a denial of service attack."},{"lang":"es","value":"Se detectó un problema en GitLab Community and Enterprise Edition versiones hasta 12.2.1. Bajo ciertas circunstancias, las pipelines de CI podrían ser usadas potencialmente en un ataque de denegación de servicio."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"12.0.8","matchCriteriaId":"7E976358-BD88-4E56-9EC1-890DB7DA57B9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"12.0.8","matchCriteriaId":"E39D35BA-555B-4A29-8AC8-59051C1A6FCF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.8","matchCriteriaId":"BE0BA50B-833E-4F74-95CB-EC8963B0ABCA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.8","matchCriteriaId":"36F29405-3C84-4ECF-96B7-E25D88926B46"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.3","matchCriteriaId":"16FD6BD6-8B76-4053-81C1-E9B00F279113"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.3","matchCriteriaId":"F131A404-4B2B-4F77-981B-A12D8FC7F590"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/08/29/security-release-gitlab-12-dot-2-dot-3-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/51401","source":"cve@mitre.org","tags":["Broken Link"]},{"url":"https://about.gitlab.com/2019/08/29/security-release-gitlab-12-dot-2-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/51401","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2019-15737","sourceIdentifier":"cve@mitre.org","published":"2019-09-16T18:15:11.767","lastModified":"2026-06-17T02:20:58.703","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition through 12.2.1. Certain account actions needed improved authentication and session management."},{"lang":"es","value":"Se detectó un problema en GitLab Community and Enterprise Edition versiones hasta 12.2.1. Determinadas acciones de la cuenta necesitaban autenticación mejorada y administración de sesión."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":2.5}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:N","baseScore":6.4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"12.0.8","matchCriteriaId":"7E976358-BD88-4E56-9EC1-890DB7DA57B9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"12.0.8","matchCriteriaId":"E39D35BA-555B-4A29-8AC8-59051C1A6FCF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.8","matchCriteriaId":"BE0BA50B-833E-4F74-95CB-EC8963B0ABCA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.8","matchCriteriaId":"36F29405-3C84-4ECF-96B7-E25D88926B46"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.3","matchCriteriaId":"16FD6BD6-8B76-4053-81C1-E9B00F279113"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.3","matchCriteriaId":"F131A404-4B2B-4F77-981B-A12D8FC7F590"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/08/29/security-release-gitlab-12-dot-2-dot-3-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/42733","source":"cve@mitre.org","tags":["Broken Link"]},{"url":"https://about.gitlab.com/2019/08/29/security-release-gitlab-12-dot-2-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/42733","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2019-15738","sourceIdentifier":"cve@mitre.org","published":"2019-09-16T18:15:11.860","lastModified":"2026-06-17T02:20:58.840","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1. Under certain conditions, merge request IDs were being disclosed via email."},{"lang":"es","value":"Se descubrió un problema en GitLab Community and Enterprise Edition versiones 12.0 hasta 12.2.1. Bajo ciertas condiciones, los ID de petición de fusión estaban siendo divulgados por medio del correo electrónico."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-200"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.0.0","versionEndExcluding":"12.0.8","matchCriteriaId":"792A801A-476C-4716-9F81-420D6173DC34"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.0.0","versionEndExcluding":"12.0.8","matchCriteriaId":"B753BB0E-F68E-4876-980F-AB041F2951F5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.8","matchCriteriaId":"BE0BA50B-833E-4F74-95CB-EC8963B0ABCA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.8","matchCriteriaId":"36F29405-3C84-4ECF-96B7-E25D88926B46"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.3","matchCriteriaId":"16FD6BD6-8B76-4053-81C1-E9B00F279113"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.3","matchCriteriaId":"F131A404-4B2B-4F77-981B-A12D8FC7F590"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/08/29/security-release-gitlab-12-dot-2-dot-3-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/63124","source":"cve@mitre.org","tags":["Broken Link"]},{"url":"https://about.gitlab.com/2019/08/29/security-release-gitlab-12-dot-2-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/63124","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2019-15739","sourceIdentifier":"cve@mitre.org","published":"2019-09-16T18:15:11.907","lastModified":"2026-06-17T02:20:58.970","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 8.1 through 12.2.1. Certain areas displaying Markdown were not properly sanitizing some XSS payloads."},{"lang":"es","value":"Se detectó un problema en GitLab Community and Enterprise Edition versiones 8.1 hasta 12.2.1. En ciertas áreas que muestran Markdown no fueron saneadas apropiadamente algunas cargas útiles de XSS."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.1.0","versionEndExcluding":"12.0.8","matchCriteriaId":"17859121-1EB7-49CE-A4C8-66A0501A0BC9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.1.0","versionEndExcluding":"12.0.8","matchCriteriaId":"B3A9DA92-7129-408B-BB76-C348DCEE8BAD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.8","matchCriteriaId":"BE0BA50B-833E-4F74-95CB-EC8963B0ABCA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.8","matchCriteriaId":"36F29405-3C84-4ECF-96B7-E25D88926B46"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.3","matchCriteriaId":"16FD6BD6-8B76-4053-81C1-E9B00F279113"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.3","matchCriteriaId":"F131A404-4B2B-4F77-981B-A12D8FC7F590"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/08/29/security-release-gitlab-12-dot-2-dot-3-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/64033","source":"cve@mitre.org","tags":["Broken Link"]},{"url":"https://about.gitlab.com/2019/08/29/security-release-gitlab-12-dot-2-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/64033","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2019-15740","sourceIdentifier":"cve@mitre.org","published":"2019-09-16T18:15:11.970","lastModified":"2026-06-17T02:20:59.097","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 7.9 through 12.2.1. EXIF Geolocation data was not being removed from certain image uploads."},{"lang":"es","value":"Se detectó un problema en GitLab Community and Enterprise Edition versiones 7.9 hasta 12.2.1. Los datos de geolocalización de EXIF no estaban siendo eliminados desde ciertas cargas de imágenes."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-200"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"7.9.0","versionEndExcluding":"12.0.8","matchCriteriaId":"EEFCE418-275A-4FDE-A0F3-0AD3533C1195"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"7.9.0","versionEndExcluding":"12.0.8","matchCriteriaId":"45397D81-D45E-40EF-B5EA-96ADD59990DE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.8","matchCriteriaId":"BE0BA50B-833E-4F74-95CB-EC8963B0ABCA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.8","matchCriteriaId":"36F29405-3C84-4ECF-96B7-E25D88926B46"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.3","matchCriteriaId":"16FD6BD6-8B76-4053-81C1-E9B00F279113"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.3","matchCriteriaId":"F131A404-4B2B-4F77-981B-A12D8FC7F590"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/08/29/security-release-gitlab-12-dot-2-dot-3-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/61390","source":"cve@mitre.org","tags":["Broken Link"]},{"url":"https://about.gitlab.com/2019/08/29/security-release-gitlab-12-dot-2-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/61390","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2019-15729","sourceIdentifier":"cve@mitre.org","published":"2019-09-17T15:15:13.130","lastModified":"2026-06-17T02:20:57.757","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 8.18 through 12.2.1. An internal endpoint unintentionally disclosed information about the last pipeline that ran for a merge request."},{"lang":"es","value":"Se detectó un problema en GitLab Community and Enterprise Edition versiones 8.18 hasta 12.2.1. Un end point interno divulgó involuntariamente información sobre la última pipeline que se ejecutó para una petición de fusión."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"9.0.0","versionEndExcluding":"12.0.8","matchCriteriaId":"9612C4F1-E0E6-42E1-907D-53D8C8F6F538"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"9.0.0","versionEndExcluding":"12.0.8","matchCriteriaId":"A9493212-99EE-4FBB-9AF4-9BBCBDA65AE9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.8","matchCriteriaId":"BE0BA50B-833E-4F74-95CB-EC8963B0ABCA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.8","matchCriteriaId":"36F29405-3C84-4ECF-96B7-E25D88926B46"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.3","matchCriteriaId":"16FD6BD6-8B76-4053-81C1-E9B00F279113"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.3","matchCriteriaId":"F131A404-4B2B-4F77-981B-A12D8FC7F590"}]}]}],"references":[{"url":"https://about.gitlab.com/2019/08/29/security-release-gitlab-12-dot-2-dot-3-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/62073","source":"cve@mitre.org","tags":["Broken Link"]},{"url":"https://about.gitlab.com/2019/08/29/security-release-gitlab-12-dot-2-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/62073","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2019-15593","sourceIdentifier":"support@hackerone.com","published":"2019-11-22T22:15:11.000","lastModified":"2026-06-17T02:20:42.503","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab 12.2.3 contains a security vulnerability that allows a user to affect the availability of the service through a Denial of Service attack in Issue Comments."},{"lang":"es","value":"GitLab versión 12.2.3, contiene una vulnerabilidad de seguridad que permite a un usuario afectar la disponibilidad del servicio por medio de un ataque de Denegación de Servicio en los Comentarios de Problemas."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"n/a","product":"GitLab","versions":[{"version":"12.2.3","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:N/A:P","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"support@hackerone.com","type":"Secondary","description":[{"lang":"en","value":"CWE-400"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:12.2.3:*:*:*:community:*:*:*","matchCriteriaId":"D397FADD-F7E3-4BB7-8637-1FCCBB3BDAD7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:12.2.3:*:*:*:enterprise:*:*:*","matchCriteriaId":"0558A94A-F995-41C2-8946-BEFD318A1A7C"}]}]}],"references":[{"url":"https://hackerone.com/reports/557154","source":"support@hackerone.com","tags":["Exploit","Patch","Third Party Advisory"]},{"url":"https://hackerone.com/reports/557154","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Patch","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2019-18460","sourceIdentifier":"cve@mitre.org","published":"2019-11-26T15:15:12.127","lastModified":"2026-06-17T02:25:03.510","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.4 in the Comments Search feature provided by the Elasticsearch integration. It has Incorrect Access Control."},{"lang":"es","value":"Se detectó un problema en GitLab Community and Enterprise Edition versiones 8.15 hasta 12.4, en la funcionalidad Comments Search provista por la integración de Elasticsearch. Posee un Control de Acceso Incorrecto."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-200"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.15.0","versionEndIncluding":"12.4.0","matchCriteriaId":"4DD6F6A1-A060-47C9-AF2F-CA5D31F84EE7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.15.0","versionEndIncluding":"12.4.0","matchCriteriaId":"546DD7A9-0FA4-4BCB-A00A-B4CB53899997"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/2019/10/30/security-release-gitlab-12-dot-4-dot-1-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/2019/10/30/security-release-gitlab-12-dot-4-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-18461","sourceIdentifier":"cve@mitre.org","published":"2019-11-26T15:15:12.190","lastModified":"2026-06-17T02:25:03.660","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 11.3 through 12.3 when a sub group epic is added to a public group. It has Incorrect Access Control."},{"lang":"es","value":"Se detectó un problema en GitLab Community and Enterprise Edition versiones 11.3 hasta 12.3, cuando es agregado un subgrupo epic a un grupo público. Posee un Control de Acceso Incorrecto."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-200"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.3.0","versionEndIncluding":"12.3.0","matchCriteriaId":"2D0BCB74-190F-4C0D-AA3A-6E5C3A23DF10"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.3.0","versionEndIncluding":"12.3.0","matchCriteriaId":"90464CCD-2A87-424D-860C-2F61104DB303"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/2019/10/30/security-release-gitlab-12-dot-4-dot-1-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/2019/10/30/security-release-gitlab-12-dot-4-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-18462","sourceIdentifier":"cve@mitre.org","published":"2019-11-26T15:15:12.550","lastModified":"2026-06-17T02:25:03.793","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 11.3 through 12.4. It has Insecure Permissions."},{"lang":"es","value":"Se detectó un problema en GitLab Community and Enterprise Edition versiones 11.3 hasta 12.4. Posee Permisos No Seguros."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-732"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.3.0","versionEndIncluding":"12.4.0","matchCriteriaId":"B13A4C00-BD11-4CA2-922D-25190BAE549F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.3.0","versionEndIncluding":"12.4.0","matchCriteriaId":"2A50FD7B-35AC-4CCE-AC79-B9D92B5C76C0"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/2019/10/30/security-release-gitlab-12-dot-4-dot-1-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/2019/10/30/security-release-gitlab-12-dot-4-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-18463","sourceIdentifier":"cve@mitre.org","published":"2019-11-26T15:15:12.627","lastModified":"2026-06-17T02:25:03.940","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition through 12.4. It has Insecure Permissions (issue 4 of 4)."},{"lang":"es","value":"Se detectó un problema en GitLab Community and Enterprise Edition versiones hasta 12.4. Posee Permisos No Seguros (problema 4 de 4)."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-732"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndIncluding":"12.4.0","matchCriteriaId":"53A65E13-4DB7-4C1C-9F74-E6FD429EA66F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndIncluding":"12.4.0","matchCriteriaId":"588F1550-06A0-4430-8BDA-28FFEFADBDFF"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/2019/10/30/security-release-gitlab-12-dot-4-dot-1-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/2019/10/30/security-release-gitlab-12-dot-4-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-18457","sourceIdentifier":"cve@mitre.org","published":"2019-11-26T16:15:13.477","lastModified":"2026-06-17T02:25:03.010","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 11.8 through 12.4 when handling Security tokens.. It has Insecure Permissions."},{"lang":"es","value":"Se detectó un problema en GitLab Community and Enterprise Edition versiones 11.8 hasta 12.4, cuando maneja tokens de Seguridad. Posee Permisos No Seguros."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-281"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.8.0","versionEndIncluding":"12.4.0","matchCriteriaId":"02B6D3BD-4CAB-4D9B-9874-140D888EB8D3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.8.0","versionEndIncluding":"12.4.0","matchCriteriaId":"285770EC-A5D0-451B-9686-0D76BF42A76A"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/2019/10/30/security-release-gitlab-12-dot-4-dot-1-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/2019/10/30/security-release-gitlab-12-dot-4-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-18458","sourceIdentifier":"cve@mitre.org","published":"2019-11-26T16:15:13.557","lastModified":"2026-06-17T02:25:03.177","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition through 12.4. It has Insecure Permissions (issue 2 of 4)."},{"lang":"es","value":"Se detectó un problema en GitLab Community and Enterprise Edition versiones hasta 12.4. Posee Permisos No Seguros (problema 2 de 4)."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N","baseScore":2.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-281"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.5.0","versionEndIncluding":"12.4.0","matchCriteriaId":"30CCB1A9-E982-499C-A072-63DC3B2E43A2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.5.0","versionEndIncluding":"12.4.0","matchCriteriaId":"79899138-AD73-49DA-B02A-753491AE7DDC"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/2019/10/30/security-release-gitlab-12-dot-4-dot-1-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/2019/10/30/security-release-gitlab-12-dot-4-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-18459","sourceIdentifier":"cve@mitre.org","published":"2019-11-26T16:15:13.620","lastModified":"2026-06-17T02:25:03.343","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 11.3 to 12.3 in the protected environments feature. It has Insecure Permissions (issue 3 of 4)."},{"lang":"es","value":"Se detectó un problema en GitLab Community and Enterprise Edition versiones 11.3 hasta 12.3, en la funcionalidad protected environments. Posee Permisos No Seguros (problema 3 de 4)."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-732"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.3.0","versionEndIncluding":"12.3.0","matchCriteriaId":"2D0BCB74-190F-4C0D-AA3A-6E5C3A23DF10"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.3.0","versionEndIncluding":"12.3.0","matchCriteriaId":"90464CCD-2A87-424D-860C-2F61104DB303"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/2019/10/30/security-release-gitlab-12-dot-4-dot-1-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/2019/10/30/security-release-gitlab-12-dot-4-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-18446","sourceIdentifier":"cve@mitre.org","published":"2019-11-26T17:15:11.970","lastModified":"2026-06-17T02:25:01.403","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.4. It has Insecure Permissions (issue 1 of 2)."},{"lang":"es","value":"Se detectó un problema en GitLab Community and Enterprise Edition versiones 8.15 hasta 12.4. Posee Permisos No Seguros (problema 1 de 2)."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:P","baseScore":5.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-732"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.15.0","versionEndIncluding":"12.4.0","matchCriteriaId":"4DD6F6A1-A060-47C9-AF2F-CA5D31F84EE7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.15.0","versionEndIncluding":"12.4.0","matchCriteriaId":"546DD7A9-0FA4-4BCB-A00A-B4CB53899997"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/2019/10/30/security-release-gitlab-12-dot-4-dot-1-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/2019/10/30/security-release-gitlab-12-dot-4-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-18447","sourceIdentifier":"cve@mitre.org","published":"2019-11-26T17:15:12.030","lastModified":"2026-06-17T02:25:01.527","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 12.4. It has Insecure Permissions."},{"lang":"es","value":"Se detectó un problema en GitLab Community and Enterprise Edition versiones anteriores a 12.4. Posee Permisos No Seguros."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-732"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndIncluding":"12.4.0","matchCriteriaId":"53A65E13-4DB7-4C1C-9F74-E6FD429EA66F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndIncluding":"12.4.0","matchCriteriaId":"588F1550-06A0-4430-8BDA-28FFEFADBDFF"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/2019/10/30/security-release-gitlab-12-dot-4-dot-1-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/2019/10/30/security-release-gitlab-12-dot-4-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-18448","sourceIdentifier":"cve@mitre.org","published":"2019-11-26T17:15:12.093","lastModified":"2026-06-17T02:25:01.653","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 12.4. It has Incorrect Access Control."},{"lang":"es","value":"Se detectó un problema en GitLab Community and Enterprise Edition versiones anteriores a 12.4. Posee un Control de Acceso Incorrecto."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndIncluding":"12.4.0","matchCriteriaId":"53A65E13-4DB7-4C1C-9F74-E6FD429EA66F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndIncluding":"12.4.0","matchCriteriaId":"588F1550-06A0-4430-8BDA-28FFEFADBDFF"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/2019/10/30/security-release-gitlab-12-dot-4-dot-1-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/2019/10/30/security-release-gitlab-12-dot-4-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-18449","sourceIdentifier":"cve@mitre.org","published":"2019-11-26T17:15:12.157","lastModified":"2026-06-17T02:25:01.783","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 12.4 in the autocomplete feature. It has Insecure Permissions (issue 2 of 2)."},{"lang":"es","value":"Se detectó un problema en GitLab Community and Enterprise Edition versiones anteriores a 12.4, en la funcionalidad autocomplete. Posee Permisos No Seguros (problema 2 de 2)."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-732"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndIncluding":"12.4.0","matchCriteriaId":"53A65E13-4DB7-4C1C-9F74-E6FD429EA66F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndIncluding":"12.4.0","matchCriteriaId":"588F1550-06A0-4430-8BDA-28FFEFADBDFF"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/2019/10/30/security-release-gitlab-12-dot-4-dot-1-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/2019/10/30/security-release-gitlab-12-dot-4-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-18450","sourceIdentifier":"cve@mitre.org","published":"2019-11-26T17:15:12.233","lastModified":"2026-06-17T02:25:01.923","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 12.4 in the Project labels feature. It has Insecure Permissions."},{"lang":"es","value":"Se detectó un problema en GitLab Community and Enterprise Edition versiones anteriores a 12.4, en la funcionalidad Project labels. Posee Permisos No Seguros."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-732"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndIncluding":"12.4.0","matchCriteriaId":"53A65E13-4DB7-4C1C-9F74-E6FD429EA66F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndIncluding":"12.4.0","matchCriteriaId":"588F1550-06A0-4430-8BDA-28FFEFADBDFF"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/2019/10/30/security-release-gitlab-12-dot-4-dot-1-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/2019/10/30/security-release-gitlab-12-dot-4-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-18451","sourceIdentifier":"cve@mitre.org","published":"2019-11-26T17:15:12.297","lastModified":"2026-06-17T02:25:02.077","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 10.7.4 through 12.4 in the InternalRedirect filtering feature. It has an Open Redirect."},{"lang":"es","value":"Se detectó un problema en GitLab Community and Enterprise Edition versiones 10.7.4 hasta 12.4, en la funcionalidad InternalRedirect filtering. Posee un Redireccionamiento Abierto."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:N","baseScore":5.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-601"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.7.4","versionEndIncluding":"12.4.0","matchCriteriaId":"4DDA8E41-7AB1-4352-8782-29734435C258"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.7.4","versionEndIncluding":"12.4.0","matchCriteriaId":"BFC4FC2F-350B-4651-935A-8859CD2CF5B2"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/2019/10/30/security-release-gitlab-12-dot-4-dot-1-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/2019/10/30/security-release-gitlab-12-dot-4-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-18452","sourceIdentifier":"cve@mitre.org","published":"2019-11-26T17:15:12.360","lastModified":"2026-06-17T02:25:02.230","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 11.3 through 12.4 when moving an issue to a public project from a private one. It has Insecure Permissions."},{"lang":"es","value":"Se detectó un problema en GitLab Community and Enterprise Edition versiones 11.3 hasta 12.4, cuando se mueve un problema a un proyecto público desde uno privado. Posee Permisos No Seguros."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-732"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.3.0","versionEndIncluding":"12.4.0","matchCriteriaId":"B13A4C00-BD11-4CA2-922D-25190BAE549F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.3.0","versionEndIncluding":"12.4.0","matchCriteriaId":"2A50FD7B-35AC-4CCE-AC79-B9D92B5C76C0"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/2019/10/30/security-release-gitlab-12-dot-4-dot-1-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/2019/10/30/security-release-gitlab-12-dot-4-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-18453","sourceIdentifier":"cve@mitre.org","published":"2019-11-26T17:15:12.437","lastModified":"2026-06-17T02:25:02.373","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 11.6 through 12.4 in the add comments via email feature. It has Insecure Permissions."},{"lang":"es","value":"Se detectó un problema en GitLab Community and Enterprise Edition versiones 11.6 hasta 12.4, en la funcionalidad add comments via email. Posee Permisos No Seguros."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-732"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.6.0","versionEndIncluding":"12.4.0","matchCriteriaId":"B6D286A1-EF63-4EE0-A0BE-9A36AAF6D929"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.6.0","versionEndIncluding":"12.4.0","matchCriteriaId":"C83EE995-32AD-49A5-8CC6-D805E2BFCC14"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/2019/10/30/security-release-gitlab-12-dot-4-dot-1-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/2019/10/30/security-release-gitlab-12-dot-4-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-18454","sourceIdentifier":"cve@mitre.org","published":"2019-11-26T17:15:12.500","lastModified":"2026-06-17T02:25:02.530","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 10.5 through 12.4 in link validation for RDoc wiki pages feature. It has XSS."},{"lang":"es","value":"Se detectó un problema en GitLab Community and Enterprise Edition versiones 10.5 hasta 12.4, en la comprobación de enlaces para la funcionalidad de páginas RDoc wiki. Presenta una vulnerabilidad de tipo XSS."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.5.0","versionEndIncluding":"12.4.0","matchCriteriaId":"30CCB1A9-E982-499C-A072-63DC3B2E43A2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.5.0","versionEndIncluding":"12.4.0","matchCriteriaId":"79899138-AD73-49DA-B02A-753491AE7DDC"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/2019/10/30/security-release-gitlab-12-dot-4-dot-1-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/2019/10/30/security-release-gitlab-12-dot-4-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-18455","sourceIdentifier":"cve@mitre.org","published":"2019-11-26T17:15:12.577","lastModified":"2026-06-17T02:25:02.683","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 11 through 12.4 when building Nested GraphQL queries. It has a large or infinite loop."},{"lang":"es","value":"Se detectó un problema en GitLab Community and Enterprise Edition versiones 11 hasta 12.4, cuando se construyen consultas GraphQL anidadas. Posee un bucle grande o infinito."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-835"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.0.0","versionEndIncluding":"12.4.0","matchCriteriaId":"FE622E8B-815B-4659-A8EB-2C02222D456F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.0.0","versionEndIncluding":"12.4.0","matchCriteriaId":"547CED31-F9C7-46B3-B84D-284369C7433C"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/2019/10/30/security-release-gitlab-12-dot-4-dot-1-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/2019/10/30/security-release-gitlab-12-dot-4-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-18456","sourceIdentifier":"cve@mitre.org","published":"2019-11-26T17:15:12.673","lastModified":"2026-06-17T02:25:02.840","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 8.17 through 12.4 in the Search feature provided by Elasticsearch integration.. It has Insecure Permissions (issue 1 of 4)."},{"lang":"es","value":"Se detectó un problema en GitLab Community and Enterprise Edition versiones 8.17 hasta 12.4, en la funcionalidad Search provista por la integración de Elasticsearch. Posee Permisos No Seguros (problema 1 de 4)."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-732"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.17.0","versionEndIncluding":"12.4.0","matchCriteriaId":"77DEC9E8-6038-47B0-8B27-7DC9AE23BEAB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.17.0","versionEndIncluding":"12.4.0","matchCriteriaId":"AB180EF0-6EB0-4B5D-8078-13C429C6B7A0"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/2019/10/30/security-release-gitlab-12-dot-4-dot-1-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/2019/10/30/security-release-gitlab-12-dot-4-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-15575","sourceIdentifier":"support@hackerone.com","published":"2019-12-18T21:15:11.600","lastModified":"2026-06-17T02:20:40.387","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A command injection exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to inject commands via the API through the blobs scope."},{"lang":"es","value":"Se presenta una inyección de comando en GitLab CE/EE versiones anteriores a v12.3.2, versiones anteriores a v12.2.6, versiones anteriores a v12.1.12, que permitió a un atacante inyectar comandos mediante la API por medio del ámbito blobs."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"n/a","product":"GitLab CE/EE","versions":[{"version":"12.3.2, 12.2.6, and 12.1.12","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"support@hackerone.com","type":"Secondary","description":[{"lang":"en","value":"CWE-77"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-77"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"12.1.12","matchCriteriaId":"E0B15B71-88A5-4565-9F28-FED3637D26E9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"12.1.12","matchCriteriaId":"EDD47A7D-F6FD-46A5-BE34-882BADBED556"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.6","matchCriteriaId":"ABCEAA2E-75C8-426B-8EAA-52D3F78FB2A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.6","matchCriteriaId":"AF5AC653-CE12-4759-B07A-04C20B9EBA7B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.3.0","versionEndExcluding":"12.3.2","matchCriteriaId":"5BB337AA-1FBB-4BEF-9652-F462CEC4BE71"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.3.0","versionEndExcluding":"12.3.2","matchCriteriaId":"DB3CF71C-AD05-4866-9629-0DB7E92775C2"}]}]}],"references":[{"url":"https://hackerone.com/reports/682442","source":"support@hackerone.com","tags":["Exploit","Issue Tracking","Third Party Advisory"]},{"url":"https://hackerone.com/reports/682442","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2019-15576","sourceIdentifier":"support@hackerone.com","published":"2019-12-18T21:15:11.770","lastModified":"2026-06-17T02:20:40.507","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to view private system notes from a GraphQL endpoint."},{"lang":"es","value":"Se presenta una vulnerabilidad de divulgación de información en GitLab CE/EE versiones anteriores a v12.3.2, versiones anteriores a v12.2.6, versiones anteriores a v12.1.12, que permitió a un atacante visualizar notas privadas del sistema desde un endpoint GraphQL."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"n/a","product":"GitLab CE/EE","versions":[{"version":"12.3.2, 12.2.6, and 12.1.12","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"support@hackerone.com","type":"Secondary","description":[{"lang":"en","value":"CWE-200"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"12.1.12","matchCriteriaId":"E0B15B71-88A5-4565-9F28-FED3637D26E9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"12.1.12","matchCriteriaId":"EDD47A7D-F6FD-46A5-BE34-882BADBED556"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.6","matchCriteriaId":"ABCEAA2E-75C8-426B-8EAA-52D3F78FB2A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.6","matchCriteriaId":"AF5AC653-CE12-4759-B07A-04C20B9EBA7B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.3.0","versionEndExcluding":"12.3.2","matchCriteriaId":"5BB337AA-1FBB-4BEF-9652-F462CEC4BE71"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.3.0","versionEndExcluding":"12.3.2","matchCriteriaId":"DB3CF71C-AD05-4866-9629-0DB7E92775C2"}]}]}],"references":[{"url":"https://hackerone.com/reports/633001","source":"support@hackerone.com","tags":["Exploit","Issue Tracking","Third Party Advisory"]},{"url":"https://hackerone.com/reports/633001","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2019-15577","sourceIdentifier":"support@hackerone.com","published":"2019-12-18T21:15:11.867","lastModified":"2026-06-17T02:20:40.623","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed project milestones to be disclosed via groups browsing."},{"lang":"es","value":"Se presenta una vulnerabilidad de divulgación de información en GitLab CE/EE versiones anteriores a v12.3.2, versiones anteriores a v12.2.6, versiones anteriores a v12.1.12, que permitió que se revelaran los hitos del proyecto por medio de la exploración de grupos."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"n/a","product":"GitLab CE/EE","versions":[{"version":"12.3.2, 12.2.6, and 12.1.12","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"support@hackerone.com","type":"Secondary","description":[{"lang":"en","value":"CWE-200"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-307"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"12.1.12","matchCriteriaId":"E0B15B71-88A5-4565-9F28-FED3637D26E9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"12.1.12","matchCriteriaId":"EDD47A7D-F6FD-46A5-BE34-882BADBED556"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.6","matchCriteriaId":"ABCEAA2E-75C8-426B-8EAA-52D3F78FB2A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.6","matchCriteriaId":"AF5AC653-CE12-4759-B07A-04C20B9EBA7B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.3.0","versionEndExcluding":"12.3.2","matchCriteriaId":"5BB337AA-1FBB-4BEF-9652-F462CEC4BE71"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.3.0","versionEndExcluding":"12.3.2","matchCriteriaId":"DB3CF71C-AD05-4866-9629-0DB7E92775C2"}]}]}],"references":[{"url":"https://hackerone.com/reports/636560","source":"support@hackerone.com","tags":["Exploit","Issue Tracking","Third Party Advisory"]},{"url":"https://hackerone.com/reports/636560","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2019-15580","sourceIdentifier":"support@hackerone.com","published":"2019-12-18T21:15:11.977","lastModified":"2026-06-17T02:20:40.980","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An information exposure vulnerability exists in gitlab.com <v12.3.2, <v12.2.6, and <v12.1.10 when using the blocking merge request feature, it was possible for an unauthenticated user to see the head pipeline data of a public project even though pipeline visibility was restricted."},{"lang":"es","value":"Se presenta una vulnerabilidad de exposición de información en gitlab.com versiones anteriores a v12.3.2, versiones anteriores a v12.2.6 y versiones anteriores a v12.1.10, cuando se utiliza el bloqueo de la funcionalidad de petición de fusion, era posible que un usuario no autenticado visualizara los datos de la tubería principal de un proyecto público inclusive aunque la visibilidad de la tubería estaba restringida."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"n/a","product":"gitlab.com","versions":[{"version":"12.3.2, 12.2.6, and 12.1.10","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"support@hackerone.com","type":"Secondary","description":[{"lang":"en","value":"CWE-201"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-200"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"12.1.10","matchCriteriaId":"AB2637E9-3EAC-4CC2-A614-E6BF2564484B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"12.1.10","matchCriteriaId":"308ED5C4-D836-4541-A789-DD76A8C61EE5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.6","matchCriteriaId":"ABCEAA2E-75C8-426B-8EAA-52D3F78FB2A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.6","matchCriteriaId":"AF5AC653-CE12-4759-B07A-04C20B9EBA7B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.3.0","versionEndExcluding":"12.3.2","matchCriteriaId":"5BB337AA-1FBB-4BEF-9652-F462CEC4BE71"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.3.0","versionEndExcluding":"12.3.2","matchCriteriaId":"DB3CF71C-AD05-4866-9629-0DB7E92775C2"}]}]}],"references":[{"url":"https://hackerone.com/reports/667408","source":"support@hackerone.com","tags":["Exploit","Third Party Advisory"]},{"url":"https://hackerone.com/reports/667408","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2019-15589","sourceIdentifier":"support@hackerone.com","published":"2019-12-18T21:15:12.083","lastModified":"2026-06-17T02:20:42.043","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An improper access control vulnerability exists in Gitlab <v12.3.2, <v12.2.6, <v12.1.12 which would allow a blocked user would be able to use GIT clone and pull if he had obtained a CI/CD token before."},{"lang":"es","value":"Se presenta una vulnerabilidad de control de acceso inapropiado en Gitlab versiones anteriores a v12.3.2, versiones anteriores a v12.2.6, versiones anteriores a v12.1.12, que permitiría que un usuario bloqueado pudiera ser capaz de usar el clon GIT y extraer si hubiera obtenido un token CI/CD antes."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"n/a","product":"GitLab CE/EE","versions":[{"version":"12.3.2, 12.2.6, 12.1.12","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"support@hackerone.com","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"12.1.12","matchCriteriaId":"E0B15B71-88A5-4565-9F28-FED3637D26E9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"12.1.12","matchCriteriaId":"EDD47A7D-F6FD-46A5-BE34-882BADBED556"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.6","matchCriteriaId":"ABCEAA2E-75C8-426B-8EAA-52D3F78FB2A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.6","matchCriteriaId":"AF5AC653-CE12-4759-B07A-04C20B9EBA7B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.3.0","versionEndExcluding":"12.3.2","matchCriteriaId":"5BB337AA-1FBB-4BEF-9652-F462CEC4BE71"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.3.0","versionEndExcluding":"12.3.2","matchCriteriaId":"DB3CF71C-AD05-4866-9629-0DB7E92775C2"}]}]}],"references":[{"url":"https://hackerone.com/reports/497047","source":"support@hackerone.com","tags":["Exploit","Issue Tracking","Third Party Advisory"]},{"url":"https://hackerone.com/reports/497047","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2019-15591","sourceIdentifier":"support@hackerone.com","published":"2019-12-18T21:15:12.193","lastModified":"2026-06-17T02:20:42.273","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An improper access control vulnerability exists in GitLab <12.3.3 that allows an attacker to obtain container and dependency scanning reports through the merge request widget even though public pipelines were disabled."},{"lang":"es","value":"Se presenta una vulnerabilidad de control de acceso inapropiado en GitLab versiones anteriores a 12.3.3 lo que permite a un atacante obtener informes de escaneo de contenedores y dependencias por medio del widget de petición de fusión a pesar de que las tuberías públicas estaban deshabilitadas."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"n/a","product":"GitLab","versions":[{"version":"12.3.3","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"support@hackerone.com","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"12.3.3","matchCriteriaId":"7A0C8FC9-8BEB-4BE3-9570-23A2AAA49416"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"12.3.3","matchCriteriaId":"E74A4499-7F83-47E8-A40C-DF7AE97345DD"}]}]}],"references":[{"url":"https://hackerone.com/reports/676976","source":"support@hackerone.com","tags":["Exploit","Issue Tracking","Third Party Advisory"]},{"url":"https://hackerone.com/reports/676976","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2019-5469","sourceIdentifier":"support@hackerone.com","published":"2019-12-18T21:15:14.303","lastModified":"2026-06-17T02:37:44.623","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An IDOR vulnerability exists in GitLab <v12.1.2, <v12.0.4, and <v11.11.6 that allowed uploading files from project archive to replace other users files potentially allowing an attacker to replace project binaries or other uploaded assets."},{"lang":"es","value":"Se presenta una vulnerabilidad IDOR en GitLab versiones anteriores a v12.1.2, versiones anteriores a v12.0.4 y versiones anteriores a v11.11.6, que permitió cargar archivos desde el archivo del proyecto para reemplazar los archivos de otros usuarios, lo que permite potencialmente a un atacante reemplazar los binarios del proyecto u otros activos cargados."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"n/a","product":"GitLab","versions":[{"version":"Fixed versions 12.1.2, 12.0.4, and 11.11.6","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:P","baseScore":5.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"support@hackerone.com","type":"Secondary","description":[{"lang":"en","value":"CWE-639"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-639"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.11.0","versionEndExcluding":"11.11.6","matchCriteriaId":"470E2D2F-030A-49C2-AF61-DDC659EBFCC6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.11.0","versionEndExcluding":"11.11.6","matchCriteriaId":"5F241A58-C88E-4155-AF2B-7B852465558E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.0.0","versionEndExcluding":"12.0.4","matchCriteriaId":"62DEEA13-4D2C-436B-9780-983FC707DDF6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.0.0","versionEndExcluding":"12.0.4","matchCriteriaId":"595B584B-2A5C-44F6-AC4C-51ACF913C6C5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.2","matchCriteriaId":"99659BEC-15D0-4E75-BEBE-727FC32D9B35"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.2","matchCriteriaId":"D12A3A81-4A4F-441A-A820-F2D19B1A5C89"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/60551","source":"support@hackerone.com","tags":["Exploit","Vendor Advisory"]},{"url":"https://hackerone.com/reports/534794","source":"support@hackerone.com","tags":["Exploit","Issue Tracking","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/60551","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]},{"url":"https://hackerone.com/reports/534794","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2019-5486","sourceIdentifier":"support@hackerone.com","published":"2019-12-18T21:15:14.413","lastModified":"2026-06-17T02:37:46.667","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.10 in the Salesforce login integration that could be used by an attacker to create an account that bypassed domain restrictions and email verification requirements."},{"lang":"es","value":"Se presenta una vulnerabilidad de omisión de autenticación en GitLab CE/EE versiones anteriores a v12.3.2, versiones anteriores a v12.2.6 y versiones anteriores a v12.1.10, en la integración de inicio de sesión de Salesforce lo que podría ser utilizado por un atacante para crear una cuenta que omitiera las restricciones de dominio y los requisitos de comprobación de correo electrónico."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"n/a","product":"GitLab CE/EE","versions":[{"version":"12.3.2, 12.2.6, and 12.1.10","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"support@hackerone.com","type":"Secondary","description":[{"lang":"en","value":"CWE-288"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-287"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"12.1.10","matchCriteriaId":"AB2637E9-3EAC-4CC2-A614-E6BF2564484B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"12.1.10","matchCriteriaId":"308ED5C4-D836-4541-A789-DD76A8C61EE5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.6","matchCriteriaId":"ABCEAA2E-75C8-426B-8EAA-52D3F78FB2A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.6","matchCriteriaId":"AF5AC653-CE12-4759-B07A-04C20B9EBA7B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.3.0","versionEndExcluding":"12.3.2","matchCriteriaId":"5BB337AA-1FBB-4BEF-9652-F462CEC4BE71"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.3.0","versionEndExcluding":"12.3.2","matchCriteriaId":"DB3CF71C-AD05-4866-9629-0DB7E92775C2"}]}]}],"references":[{"url":"https://hackerone.com/reports/617896","source":"support@hackerone.com","tags":["Exploit","Third Party Advisory"]},{"url":"https://hackerone.com/reports/617896","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2019-5487","sourceIdentifier":"support@hackerone.com","published":"2019-12-18T21:15:14.507","lastModified":"2026-06-17T02:37:46.770","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An improper access control vulnerability exists in Gitlab EE <v12.3.3, <v12.2.7, & <v12.1.13 that allowed the group search feature with Elasticsearch to return private code, merge requests and commits."},{"lang":"es","value":"Se presenta una vulnerabilidad de control de acceso inapropiado en Gitlab EE versiones anteriores a v12.3.3, versiones anteriores a v12.2.7 y versiones anteriores a v12.1.13, lo que permitió que la funcionalidad de búsqueda grupal con Elasticsearch devolviera código privado y fusionara peticiones y confirmaciones."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"n/a","product":"GitLab EE","versions":[{"version":"12.3.3, 12.2.7, 12.1.13","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"support@hackerone.com","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"12.1.13","matchCriteriaId":"9CA53411-DAE1-43A0-B17B-495D057B0B6F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.7","matchCriteriaId":"029A7044-B55D-423A-B415-26D83C82E5BA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.3.0","versionEndExcluding":"12.3.3","matchCriteriaId":"D313012F-7A48-436D-B705-6D76FA386321"}]}]}],"references":[{"url":"https://hackerone.com/reports/692252","source":"support@hackerone.com","tags":["Exploit","Issue Tracking","Third Party Advisory"]},{"url":"https://hackerone.com/reports/692252","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2019-15584","sourceIdentifier":"support@hackerone.com","published":"2019-12-20T22:15:11.473","lastModified":"2026-06-17T02:20:41.443","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A denial of service exists in gitlab <v12.3.2, <v12.2.6, and <v12.1.10 that would let an attacker bypass input validation in markdown fields take down the affected page."},{"lang":"es","value":"Se presenta una denegación de servicio en gitlab versiones anteriores a v12.3.2, versiones anteriores a v12.2.6 y versiones anteriores a v12.1.10, que permitiría a un atacante omitir la comprobación de entrada en los campos markdown para suspender la página afectada."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"n/a","product":"GitLab CE/EE","versions":[{"version":"12.3.2, 12.2.6, and 12.1.10","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:N/A:P","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"support@hackerone.com","type":"Secondary","description":[{"lang":"en","value":"CWE-400"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-400"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"12.1.10","matchCriteriaId":"AB2637E9-3EAC-4CC2-A614-E6BF2564484B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"12.1.10","matchCriteriaId":"308ED5C4-D836-4541-A789-DD76A8C61EE5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.6","matchCriteriaId":"ABCEAA2E-75C8-426B-8EAA-52D3F78FB2A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.6","matchCriteriaId":"AF5AC653-CE12-4759-B07A-04C20B9EBA7B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.3.0","versionEndExcluding":"12.3.2","matchCriteriaId":"5BB337AA-1FBB-4BEF-9652-F462CEC4BE71"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.3.0","versionEndExcluding":"12.3.2","matchCriteriaId":"DB3CF71C-AD05-4866-9629-0DB7E92775C2"}]}]}],"references":[{"url":"https://hackerone.com/reports/670572","source":"support@hackerone.com","tags":["Exploit","Third Party Advisory"]},{"url":"https://hackerone.com/reports/670572","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2018-20492","sourceIdentifier":"cve@mitre.org","published":"2019-12-26T17:15:13.427","lastModified":"2026-06-17T01:52:57.857","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control (issue 2 of 6)."},{"lang":"es","value":"Se detectó un problema en GitLab Community and Enterprise Edition versiones anteriores a 11.4.13, versiones 11.5.x anteriores a 11.5.6 y versiones 11.6.x anteriores a 11.6.1. Presenta un Control de Acceso Incorrecto (problema 2 de 6)."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.0.0","versionEndExcluding":"11.4.13","matchCriteriaId":"F24B4E23-2C72-4798-BD3D-D3D267B60906"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.0.0","versionEndExcluding":"11.4.13","matchCriteriaId":"61EAA692-9EEA-440E-9678-BA7FE58A2D84"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.6","matchCriteriaId":"555DAC6F-1C9E-4D4E-9100-35DDFD320F51"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.6","matchCriteriaId":"584CB55D-C412-4C8A-91A6-B0FB0632D4DF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.1","matchCriteriaId":"BF95CB5A-17FF-413D-BD1E-6D4470E5A7F8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.1","matchCriteriaId":"7B939578-9F4C-4EB0-8FCC-5A9F64109788"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/12/31/security-release-gitlab-11-dot-6-dot-1-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/2018/12/31/security-release-gitlab-11-dot-6-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-20488","sourceIdentifier":"cve@mitre.org","published":"2019-12-30T22:15:11.543","lastModified":"2026-06-17T01:52:57.353","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows Information Exposure."},{"lang":"es","value":"Se descubrió un problema en GitLab Community and Enterprise Edition versiones anteriores a la versión  11.4.13, versiones 11.5.x anteriores a la versión 11.5.6 y versiones 11.6.x anteriores a la versión  11.6.1. Permite una Exposición de Información."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-200"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"9.3.0","versionEndExcluding":"11.4.13","matchCriteriaId":"2376AE2F-E8B4-486C-93A6-751ED4F17EAA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"9.3.0","versionEndExcluding":"11.4.13","matchCriteriaId":"994DDCC1-FCCE-4A0D-8790-4984D429B16A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.6","matchCriteriaId":"555DAC6F-1C9E-4D4E-9100-35DDFD320F51"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.6","matchCriteriaId":"584CB55D-C412-4C8A-91A6-B0FB0632D4DF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.1","matchCriteriaId":"BF95CB5A-17FF-413D-BD1E-6D4470E5A7F8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.1","matchCriteriaId":"7B939578-9F4C-4EB0-8FCC-5A9F64109788"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/12/31/security-release-gitlab-11-dot-6-dot-1-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/53477","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/2018/12/31/security-release-gitlab-11-dot-6-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/53477","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-20489","sourceIdentifier":"cve@mitre.org","published":"2019-12-30T22:15:11.603","lastModified":"2026-06-17T01:52:57.480","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control."},{"lang":"es","value":"Se descubrió un problema en GitLab Community and Enterprise Edition versiones anteriores a la versión 11.4.13, versiones 11.5.x anteriores a la versión  11.5.6 y versiones 11.6.x anteriores a la versión  11.6.1. Tiene un Control de Acceso Incorrecto."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-287"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"9.1.0","versionEndExcluding":"11.4.13","matchCriteriaId":"4C82C873-E324-47C0-9D2C-9699C2936C5C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"9.1.0","versionEndExcluding":"11.4.13","matchCriteriaId":"B837A3C8-4F68-4F4D-81DC-6FD3FE530FAC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.6","matchCriteriaId":"555DAC6F-1C9E-4D4E-9100-35DDFD320F51"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.6","matchCriteriaId":"584CB55D-C412-4C8A-91A6-B0FB0632D4DF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.1","matchCriteriaId":"BF95CB5A-17FF-413D-BD1E-6D4470E5A7F8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.1","matchCriteriaId":"7B939578-9F4C-4EB0-8FCC-5A9F64109788"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/12/31/security-release-gitlab-11-dot-6-dot-1-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-foss/issues/41500","source":"cve@mitre.org","tags":["Patch","Vendor Advisory"]},{"url":"https://about.gitlab.com/2018/12/31/security-release-gitlab-11-dot-6-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-foss/issues/41500","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-20490","sourceIdentifier":"cve@mitre.org","published":"2019-12-30T22:15:11.667","lastModified":"2026-06-17T01:52:57.610","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 11.2.x through 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows XSS."},{"lang":"es","value":"Se descubrió un problema en GitLab Community and Enterprise Edition 11.2.x hasta la versión 11.4.x anterior a la versión  11.4.13, 11.5.x anterior a la versión  11.5.6 y 11.6.x anterior a la versión  11.6.1. Permite un ataque de tipo XSS."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.2.0","versionEndExcluding":"11.4.13","matchCriteriaId":"CC1E9024-42F7-475B-9C50-0638830DEC8A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.2.0","versionEndExcluding":"11.4.13","matchCriteriaId":"A163FA4A-2BDD-4135-A01A-A5A5425B5140"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.6","matchCriteriaId":"555DAC6F-1C9E-4D4E-9100-35DDFD320F51"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.6","matchCriteriaId":"584CB55D-C412-4C8A-91A6-B0FB0632D4DF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.1","matchCriteriaId":"BF95CB5A-17FF-413D-BD1E-6D4470E5A7F8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.1","matchCriteriaId":"7B939578-9F4C-4EB0-8FCC-5A9F64109788"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/12/31/security-release-gitlab-11-dot-6-dot-1-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/54377","source":"cve@mitre.org","tags":["Exploit","Vendor Advisory"]},{"url":"https://about.gitlab.com/2018/12/31/security-release-gitlab-11-dot-6-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/54377","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-20491","sourceIdentifier":"cve@mitre.org","published":"2019-12-30T22:15:11.730","lastModified":"2026-06-17T01:52:57.733","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Enterprise Edition 11.3.x and 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows XSS."},{"lang":"es","value":"Se descubrió un problema en GitLab Enterprise Edition versiones 11.3.x y versiones 11.4.x anteriores a la versión  11.4.13, versiones 11.5.x anteriores a la versión  11.5.6 y versiones 11.6.x anteriores a la versión  11.6.1. Permite un ataque de tipo XSS."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"11.4.13","matchCriteriaId":"056F58D5-63F5-4AFA-BA32-56640F458A21"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"11.4.13","matchCriteriaId":"24E16D5E-4C1A-4F24-8E63-88762961C6AE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.6","matchCriteriaId":"555DAC6F-1C9E-4D4E-9100-35DDFD320F51"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.6","matchCriteriaId":"584CB55D-C412-4C8A-91A6-B0FB0632D4DF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.1","matchCriteriaId":"BF95CB5A-17FF-413D-BD1E-6D4470E5A7F8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.1","matchCriteriaId":"7B939578-9F4C-4EB0-8FCC-5A9F64109788"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/12/31/security-release-gitlab-11-dot-6-dot-1-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/54008","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/2018/12/31/security-release-gitlab-11-dot-6-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/54008","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-20493","sourceIdentifier":"cve@mitre.org","published":"2019-12-30T22:15:11.793","lastModified":"2026-06-17T01:52:57.987","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control."},{"lang":"es","value":"Se descubrió un problema en GitLab Community and Enterprise Edition versiones anteriores a la versión  11.4.13, versiones 11.5.x anteriores a la versión 11.5.6 y versiones 11.6.x anteriores a la versión 11.6.1. Tiene un Control de Acceso Incorrecto."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.17.0","versionEndExcluding":"11.4.13","matchCriteriaId":"E695648C-4530-4CAE-BC99-4162C7C86256"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.17.0","versionEndExcluding":"11.4.13","matchCriteriaId":"602E12ED-3CFF-4D62-A166-C48171A9B6D0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.6","matchCriteriaId":"555DAC6F-1C9E-4D4E-9100-35DDFD320F51"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.6","matchCriteriaId":"584CB55D-C412-4C8A-91A6-B0FB0632D4DF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.1","matchCriteriaId":"BF95CB5A-17FF-413D-BD1E-6D4470E5A7F8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.1","matchCriteriaId":"7B939578-9F4C-4EB0-8FCC-5A9F64109788"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/12/31/security-release-gitlab-11-dot-6-dot-1-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/54914","source":"cve@mitre.org","tags":["Exploit"]},{"url":"https://about.gitlab.com/2018/12/31/security-release-gitlab-11-dot-6-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/54914","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"]}]}},{"cve":{"id":"CVE-2018-20494","sourceIdentifier":"cve@mitre.org","published":"2019-12-30T22:15:11.853","lastModified":"2026-06-17T01:52:58.113","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control."},{"lang":"es","value":"Se descubrió un problema en GitLab Community and Enterprise Edition versiones anteriores a la versión 11.4.13, versiones 11.5.x anteriores a la versión 11.5.6 y versiones 11.6.x anteriores a la versión  11.6.1. Tiene  un Control de Acceso Incorrecto."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.4.0","versionEndExcluding":"11.4.13","matchCriteriaId":"553CCAF0-EB78-4278-88D9-33FDCD444737"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.4.0","versionEndExcluding":"11.4.13","matchCriteriaId":"2BBF5519-5612-4CA3-89D0-A1B3D1A34249"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.6","matchCriteriaId":"555DAC6F-1C9E-4D4E-9100-35DDFD320F51"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.6","matchCriteriaId":"584CB55D-C412-4C8A-91A6-B0FB0632D4DF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.1","matchCriteriaId":"BF95CB5A-17FF-413D-BD1E-6D4470E5A7F8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.1","matchCriteriaId":"7B939578-9F4C-4EB0-8FCC-5A9F64109788"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/12/31/security-release-gitlab-11-dot-6-dot-1-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/54334","source":"cve@mitre.org","tags":["Exploit","Patch","Vendor Advisory"]},{"url":"https://about.gitlab.com/2018/12/31/security-release-gitlab-11-dot-6-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/54334","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Patch","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-20495","sourceIdentifier":"cve@mitre.org","published":"2019-12-30T22:15:11.917","lastModified":"2026-06-17T01:52:58.237","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 11.3.x and 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows Information Exposure."},{"lang":"es","value":"Se descubrió un problema en GitLab Community and Enterprise Edition versiones 11.3.x y versiones 11.4.x anteriores a la versión  11.4.13, versiones 11.5.x anteriores a la versión  11.5.6 y versiones 11.6.x anteriores a la versión  11.6.1. Permite una Exposición de Información."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-200"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"11.4.13","matchCriteriaId":"056F58D5-63F5-4AFA-BA32-56640F458A21"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"11.4.13","matchCriteriaId":"24E16D5E-4C1A-4F24-8E63-88762961C6AE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.6","matchCriteriaId":"555DAC6F-1C9E-4D4E-9100-35DDFD320F51"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.6","matchCriteriaId":"584CB55D-C412-4C8A-91A6-B0FB0632D4DF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.1","matchCriteriaId":"BF95CB5A-17FF-413D-BD1E-6D4470E5A7F8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.1","matchCriteriaId":"7B939578-9F4C-4EB0-8FCC-5A9F64109788"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/12/31/security-release-gitlab-11-dot-6-dot-1-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/51969","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/2018/12/31/security-release-gitlab-11-dot-6-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/51969","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-20496","sourceIdentifier":"cve@mitre.org","published":"2019-12-30T22:15:11.997","lastModified":"2026-06-17T01:52:58.363","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 11.2.x through 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows XSS."},{"lang":"es","value":"Se descubrió un problema en GitLab Community and Enterprise Edition versiones 11.2.x hasta 11.4.x anteriores a la versión  11.4.13, versiones 11.5.x anteriores a la versión 11.5.6 y versiones 11.6.x anteriores a la versión 11.6.1. Permite un ataque de tipo XSS."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.10.0","versionEndExcluding":"11.4.13","matchCriteriaId":"EFAC01C8-704D-4943-8BE0-3E48ACB4DC0B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.10.0","versionEndExcluding":"11.4.13","matchCriteriaId":"777D038F-FE3C-457B-A97A-52DE09A991FC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.6","matchCriteriaId":"555DAC6F-1C9E-4D4E-9100-35DDFD320F51"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.6","matchCriteriaId":"584CB55D-C412-4C8A-91A6-B0FB0632D4DF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.1","matchCriteriaId":"BF95CB5A-17FF-413D-BD1E-6D4470E5A7F8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.1","matchCriteriaId":"7B939578-9F4C-4EB0-8FCC-5A9F64109788"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/12/31/security-release-gitlab-11-dot-6-dot-1-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/54427","source":"cve@mitre.org","tags":["Exploit","Vendor Advisory"]},{"url":"https://about.gitlab.com/2018/12/31/security-release-gitlab-11-dot-6-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/54427","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-20497","sourceIdentifier":"cve@mitre.org","published":"2019-12-30T22:15:12.043","lastModified":"2026-06-17T01:52:58.490","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows SSRF."},{"lang":"es","value":"Se descubrió un problema en GitLab Community and Enterprise Edition versiones anteriores a la versión  11.4.13, versiones 11.5.x anteriores a la versión  11.5.6 y versiones 11.6.x anteriores a la versión 11.6.1. Permite un ataque de tipo SSRF."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N","baseScore":5.0,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.7.0","versionEndExcluding":"11.4.13","matchCriteriaId":"5FFDA4D5-5C61-40D4-8B50-1D79A7A0BFF2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.7.0","versionEndExcluding":"11.4.13","matchCriteriaId":"CF67718D-9B43-4266-A2B9-24B95DC44593"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.6","matchCriteriaId":"555DAC6F-1C9E-4D4E-9100-35DDFD320F51"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.6","matchCriteriaId":"584CB55D-C412-4C8A-91A6-B0FB0632D4DF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.1","matchCriteriaId":"BF95CB5A-17FF-413D-BD1E-6D4470E5A7F8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.1","matchCriteriaId":"7B939578-9F4C-4EB0-8FCC-5A9F64109788"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/12/31/security-release-gitlab-11-dot-6-dot-1-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/51327","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/2018/12/31/security-release-gitlab-11-dot-6-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/51327","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-20498","sourceIdentifier":"cve@mitre.org","published":"2019-12-30T22:15:12.103","lastModified":"2026-06-17T01:52:58.610","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control."},{"lang":"es","value":"Se descubrió un problema en GitLab Community and Enterprise Edition versiones anteriores a la versión 11.4.13, versiones 11.5.x anteriores a la versión 11.5.6 y versiones 11.6.x anteriores a la versión 11.6.1. Tiene  un Control de Acceso Incorrecto."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.10.0","versionEndExcluding":"11.4.13","matchCriteriaId":"EFAC01C8-704D-4943-8BE0-3E48ACB4DC0B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.10.0","versionEndExcluding":"11.4.13","matchCriteriaId":"777D038F-FE3C-457B-A97A-52DE09A991FC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.6","matchCriteriaId":"555DAC6F-1C9E-4D4E-9100-35DDFD320F51"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.6","matchCriteriaId":"584CB55D-C412-4C8A-91A6-B0FB0632D4DF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.1","matchCriteriaId":"BF95CB5A-17FF-413D-BD1E-6D4470E5A7F8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.1","matchCriteriaId":"7B939578-9F4C-4EB0-8FCC-5A9F64109788"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/12/31/security-release-gitlab-11-dot-6-dot-1-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/50995","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/2018/12/31/security-release-gitlab-11-dot-6-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/50995","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-20499","sourceIdentifier":"cve@mitre.org","published":"2019-12-30T22:15:12.167","lastModified":"2026-06-17T01:52:58.733","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows SSRF."},{"lang":"es","value":"Se descubrió  un problema en GitLab Community and Enterprise Edition versiones anteriores a la versión  11.x anteriores a la versión  11.4.13, versiones 11.5.x anteriores a la versión  11.5.6 y versiones 11.6.x anteriores a la versión 11.6.1. Permite un ataque de tipo SSRF."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:N","baseScore":6.4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"11.4.13","matchCriteriaId":"EBE3AA09-1C6F-4FFC-9CCD-9E607677F3BE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"11.4.13","matchCriteriaId":"7C166C32-342D-4A16-8C6C-8C35FAA74190"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.6","matchCriteriaId":"555DAC6F-1C9E-4D4E-9100-35DDFD320F51"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.6","matchCriteriaId":"584CB55D-C412-4C8A-91A6-B0FB0632D4DF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.1","matchCriteriaId":"BF95CB5A-17FF-413D-BD1E-6D4470E5A7F8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.1","matchCriteriaId":"7B939578-9F4C-4EB0-8FCC-5A9F64109788"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/12/31/security-release-gitlab-11-dot-6-dot-1-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/55439","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/2018/12/31/security-release-gitlab-11-dot-6-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/55439","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-20501","sourceIdentifier":"cve@mitre.org","published":"2019-12-30T22:15:12.230","lastModified":"2026-06-17T01:52:58.983","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control."},{"lang":"es","value":"Se descubrió  un problema en GitLab Community and Enterprise Edition versiones anteriores a la versión  11.4.13, versiones 11.5.x anteriores a la versión 11.5.6 y versiones 11.6.x anteriores a la versión 11.6.1. Tiene un Control de Acceso Incorrecto."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","baseScore":6.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":3.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.12.0","versionEndExcluding":"11.4.13","matchCriteriaId":"59F7862C-7086-40AD-BEE6-02C81ED159F9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.12.0","versionEndExcluding":"11.4.13","matchCriteriaId":"AC66AD78-47CB-4D12-9552-AE68CCE862D1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.6","matchCriteriaId":"555DAC6F-1C9E-4D4E-9100-35DDFD320F51"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.6","matchCriteriaId":"584CB55D-C412-4C8A-91A6-B0FB0632D4DF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.1","matchCriteriaId":"BF95CB5A-17FF-413D-BD1E-6D4470E5A7F8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.1","matchCriteriaId":"7B939578-9F4C-4EB0-8FCC-5A9F64109788"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/12/31/security-release-gitlab-11-dot-6-dot-1-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/53543","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/2018/12/31/security-release-gitlab-11-dot-6-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/53543","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-20507","sourceIdentifier":"cve@mitre.org","published":"2019-12-30T22:15:12.307","lastModified":"2026-06-17T01:52:59.780","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Enterprise Edition 11.2.x through 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control."},{"lang":"es","value":"Se descubrió  un problema en GitLab Enterprise Edition versiones 11.2.x hasta 11.4.x anteriores a la versión 11.4.13, versiones 11.5.x anteriores a la versión 11.5.6 y versiones 11.6.x anteriores a la versión 11.6.1. Tiene un Control de Acceso Incorrecto."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-306"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.2.0","versionEndExcluding":"11.4.13","matchCriteriaId":"CC1E9024-42F7-475B-9C50-0638830DEC8A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.2.0","versionEndExcluding":"11.4.13","matchCriteriaId":"A163FA4A-2BDD-4135-A01A-A5A5425B5140"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.6","matchCriteriaId":"555DAC6F-1C9E-4D4E-9100-35DDFD320F51"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.6","matchCriteriaId":"584CB55D-C412-4C8A-91A6-B0FB0632D4DF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.1","matchCriteriaId":"BF95CB5A-17FF-413D-BD1E-6D4470E5A7F8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"11.6.1","matchCriteriaId":"7B939578-9F4C-4EB0-8FCC-5A9F64109788"}]}]}],"references":[{"url":"https://about.gitlab.com/2018/12/31/security-release-gitlab-11-dot-6-dot-1-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/2018/12/31/security-release-gitlab-11-dot-6-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-19086","sourceIdentifier":"cve@mitre.org","published":"2020-01-03T16:15:10.577","lastModified":"2026-06-17T02:26:08.587","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Gitlab Enterprise Edition (EE) before 12.5.1 has Insecure Permissions (issue 1 of 2)."},{"lang":"es","value":"Gitlab Enterprise Edition (EE) versiones anteriores a la versíon 12.5.1, tiene Permisos No Seguros (problema 1 de 2)."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-732"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.17.0","versionEndExcluding":"12.5.1","matchCriteriaId":"9C54776F-8A1B-4ECF-A732-AFC29F89F965"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-19087","sourceIdentifier":"cve@mitre.org","published":"2020-01-03T16:15:10.797","lastModified":"2026-06-17T02:26:08.780","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Gitlab Enterprise Edition (EE) before 12.5.1 has Insecure Permissions (issue 2 of 2)."},{"lang":"es","value":"Gitlab Enterprise Edition (EE) versiones anteriores a la versión 12.5.1, tiene Permisos No Seguros"}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-732"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.17.0","versionEndExcluding":"12.5.1","matchCriteriaId":"9C54776F-8A1B-4ECF-A732-AFC29F89F965"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-19088","sourceIdentifier":"cve@mitre.org","published":"2020-01-03T16:15:10.860","lastModified":"2026-06-17T02:26:08.947","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Gitlab Enterprise Edition (EE) 11.3 through 12.4.2 allows Directory Traversal."},{"lang":"es","value":"Gitlab Enterprise Edition (EE) versiones 11.3 hasta la versión 12.4.2, permite un Salto de Directorio."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-22"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"12.5.1","matchCriteriaId":"1081568B-3E11-458D-88D4-B953F06FF685"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-19254","sourceIdentifier":"cve@mitre.org","published":"2020-01-03T16:15:10.953","lastModified":"2026-06-17T02:26:22.560","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab Community Edition (CE) and Enterprise Edition (EE). 9.6 and later through 12.5 has Incorrect Access Control."},{"lang":"es","value":"GitLab Community Edition (CE) and Enterprise Edition (EE). Versiones 9.6 y posteriores hasta la versión 12.5, tiene un Control de Acceso Incorrecto."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-200"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"9.6.0","versionEndExcluding":"12.5.1","matchCriteriaId":"00060387-3773-439B-88A8-D255BF0629E5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"9.6.0","versionEndExcluding":"12.5.1","matchCriteriaId":"F583103C-AB51-4D51-8BAB-C5C5FE2E7CCF"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/issues/12219","source":"cve@mitre.org","tags":["Broken Link","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/issues/12219","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-19311","sourceIdentifier":"cve@mitre.org","published":"2020-01-03T16:15:11.047","lastModified":"2026-06-17T02:26:28.800","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 allows XSS in group and profile fields."},{"lang":"es","value":"GitLab EE versiones 8.14 hasta la versión  12.5, 12.4.3 y 12.3.6, permite un ataque de tipo XSS en los campos group y profile."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.14.0","versionEndExcluding":"12.3.7","matchCriteriaId":"510691CD-4CA1-4242-83A5-FA3A190F930C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.4.0","versionEndExcluding":"12.4.4","matchCriteriaId":"E7EB52F6-C421-423C-A8AE-BB947C828A87"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.5.0","versionEndExcluding":"12.5.1","matchCriteriaId":"389365E0-7E8B-46AD-85B8-9CC7743E8E7D"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/issues/31536","source":"cve@mitre.org","tags":["Broken Link","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/issues/31536","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-19255","sourceIdentifier":"cve@mitre.org","published":"2020-01-03T17:15:11.397","lastModified":"2026-06-17T02:26:22.703","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab Enterprise Edition (EE) 12.3 and later through 12.5 has Incorrect Access Control."},{"lang":"es","value":"GitLab Enterprise Edition (EE) versiones 12.3 y posteriores hasta la versión 12.5, tiene  un Control de Acceso Incorrecto."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.3.0","versionEndExcluding":"12.5.1","matchCriteriaId":"4F13F62D-A604-4194-A6AA-7BDE9555AD24"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-19256","sourceIdentifier":"cve@mitre.org","published":"2020-01-03T17:15:11.490","lastModified":"2026-06-17T02:26:22.823","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab Enterprise Edition (EE) 12.2 and later through 12.5 has Incorrect Access Control."},{"lang":"es","value":"GitLab Enterprise Edition (EE) versiones 12.2 y posteriores hasta la versión 12.5, tienen un Control de Acceso Incorrecto."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-200"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.5.1","matchCriteriaId":"0BA76AAB-DEFC-4FE3-9313-B6A665924B7E"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-19257","sourceIdentifier":"cve@mitre.org","published":"2020-01-03T17:15:11.570","lastModified":"2026-06-17T02:26:22.947","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab Community Edition (CE) and Enterprise Edition (EE) through 12.5 has Incorrect Access Control (issue 1 of 2)."},{"lang":"es","value":"GitLab Community Edition (CE) and Enterprise Edition (EE) versiones hasta la versión 12.5, tienen un Control de Acceso Incorrecto"}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"12.5.1","matchCriteriaId":"AE8051ED-0D0E-491F-A65E-8A7E9674AAC9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"12.5.1","matchCriteriaId":"28249DA0-1630-48E5-844C-53D1B6790D34"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-19258","sourceIdentifier":"cve@mitre.org","published":"2020-01-03T17:15:11.647","lastModified":"2026-06-17T02:26:23.067","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab Enterprise Edition (EE) 10.8 and later through 12.5 has Incorrect Access Control."},{"lang":"es","value":"GitLab Enterprise Edition (EE) versiones 10.8 y posteriores hasta la versión 12.5, tiene un Control de Acceso Incorrecto."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.8.0","versionEndExcluding":"12.5.1","matchCriteriaId":"F2D5D08A-3982-4C5E-B5D7-3E1A7A1048AC"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-19259","sourceIdentifier":"cve@mitre.org","published":"2020-01-03T17:15:11.710","lastModified":"2026-06-17T02:26:23.187","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab Enterprise Edition (EE) 11.3 and later through 12.5 allows an Insecure Direct Object Reference (IDOR)."},{"lang":"es","value":"GitLab Enterprise Edition (EE) versiones 11.3 y posteriores hasta la versión  12.5, permite una Referencia de Objeto Directo No Seguro (IDOR)."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-639"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"12.5.1","matchCriteriaId":"1081568B-3E11-458D-88D4-B953F06FF685"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-19260","sourceIdentifier":"cve@mitre.org","published":"2020-01-03T17:15:11.787","lastModified":"2026-06-17T02:26:23.317","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab Community Edition (CE) and Enterprise Edition (EE) through 12.5 has Incorrect Access Control (issue 2 of 2)."},{"lang":"es","value":"GitLab Community Edition (CE) and Enterprise Edition (EE) versiones hasta la versión  12.5, tiene un Control de Acceso Incorrecto (problema 2 de 2)."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.5}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:N","baseScore":5.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"12.5.1","matchCriteriaId":"AE8051ED-0D0E-491F-A65E-8A7E9674AAC9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"12.5.1","matchCriteriaId":"28249DA0-1630-48E5-844C-53D1B6790D34"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-19261","sourceIdentifier":"cve@mitre.org","published":"2020-01-03T17:15:11.850","lastModified":"2026-06-17T02:26:23.433","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab Enterprise Edition (EE) 6.7 and later through 12.5 allows SSRF."},{"lang":"es","value":"GitLab Enterprise Edition (EE) versiones 6.7 y posteriores hasta la 12.5, permite un ataque de tipo SSRF."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"6.7.0","versionEndExcluding":"12.5.1","matchCriteriaId":"0FF3F160-306E-4FA2-8DC7-B981DD0D729B"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-19262","sourceIdentifier":"cve@mitre.org","published":"2020-01-03T17:15:11.913","lastModified":"2026-06-17T02:26:23.553","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab Enterprise Edition (EE) 11.9 and later through 12.5 has Insecure Permissions."},{"lang":"es","value":"GitLab Enterprise Edition (EE) versiones 11.9 y posteriores hasta la versión 12.5, tiene Permisos No Seguros."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-732"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.9.0","versionEndExcluding":"12.5.2","matchCriteriaId":"C8F5391A-6735-4EE9-BDEC-9E988CA2900A"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-2-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-19263","sourceIdentifier":"cve@mitre.org","published":"2020-01-03T17:15:11.977","lastModified":"2026-06-17T02:26:23.677","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab Enterprise Edition (EE) 8.2 and later through 12.5 has Insecure Permissions."},{"lang":"es","value":"GitLab Enterprise Edition (EE) versiones 8.2 y posteriores hasta la versíon 12.5, tiene Permisos No Seguros."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-732"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.2.0","versionEndExcluding":"12.5.1","matchCriteriaId":"A3298E25-AEA2-4AA2-A80F-2D136847A8FC"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-19309","sourceIdentifier":"cve@mitre.org","published":"2020-01-03T17:15:12.037","lastModified":"2026-06-17T02:26:28.553","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab Enterprise Edition (EE) 8.90 and later through 12.5 has Incorrect Access Control."},{"lang":"es","value":"GitLab Enterprise Edition (EE) versiones 8.90 y posteriores hasta la versión  12.5, tiene un Control de Acceso Incorrecto."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.90","versionEndExcluding":"12.5.1","matchCriteriaId":"059FCAC9-3DA6-49EA-9CA1-2FB664963CE9"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-19310","sourceIdentifier":"cve@mitre.org","published":"2020-01-03T17:15:12.117","lastModified":"2026-06-17T02:26:28.673","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab Enterprise Edition (EE) 9.0 and later through 12.5 allows Information Disclosure."},{"lang":"es","value":"GitLab Enterprise Edition (EE) versiones 9.0 y posteriores hasta la versión  12.5, permite una Divulgación de Información."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-522"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"9.0.0","versionEndExcluding":"12.5.1","matchCriteriaId":"4E117602-8E89-41FF-8F19-5CD13AC92713"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-19312","sourceIdentifier":"cve@mitre.org","published":"2020-01-05T22:15:10.707","lastModified":"2026-06-17T02:26:28.923","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 has Incorrect Access Control. After a project changed to private, previously forked repositories were still able to get information about the private project through the API."},{"lang":"es","value":"GitLab EE versiones 8.14 hasta las versiones 12.5, 12.4.3 y 12.3.6, tiene un Control de Acceso Incorrecto. Después de que un proyecto cambió a privado, los repositorios previamente bifurcados podían aún ser capaces de obtener información sobre el proyecto privado mediante la API."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N","baseScore":5.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.14.0","versionEndExcluding":"12.3.8","matchCriteriaId":"789C863D-94A0-486C-88C4-59F12802A549"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.4.0","versionEndExcluding":"12.4.5","matchCriteriaId":"2C7ABFDC-276A-4FC0-A1F3-1A5682D63844"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.5.0","versionEndExcluding":"12.5.2","matchCriteriaId":"6BE7EFD6-E3DA-4103-A1FD-FC7C7ABD3487"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/issues/28802","source":"cve@mitre.org","tags":["Broken Link"]},{"url":"https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/issues/28802","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2019-19313","sourceIdentifier":"cve@mitre.org","published":"2020-01-05T22:15:11.033","lastModified":"2026-06-17T02:26:29.047","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab EE 12.3 through 12.5, 12.4.3, and 12.3.6 allows Denial of Service. Certain characters were making it impossible to create, edit, or view issues and commits."},{"lang":"es","value":"GitLab EE versiones 12.3 hasta 12.5, 12.4.3 y 12.3.6, permite una Denegación de Servicio. Ciertos caracteres hacían imposible crear, editar o visualizar problemas y confirmaciones."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-755"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.3.0","versionEndExcluding":"12.3.8","matchCriteriaId":"6AAC3F35-A2DB-4378-956F-63B73754B3C1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.4.0","versionEndExcluding":"12.4.5","matchCriteriaId":"2C7ABFDC-276A-4FC0-A1F3-1A5682D63844"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.5.0","versionEndExcluding":"12.5.2","matchCriteriaId":"6BE7EFD6-E3DA-4103-A1FD-FC7C7ABD3487"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/issues/14947","source":"cve@mitre.org","tags":["Broken Link"]},{"url":"https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/issues/14947","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2019-19314","sourceIdentifier":"cve@mitre.org","published":"2020-01-05T22:15:11.097","lastModified":"2026-06-17T02:26:29.180","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab EE 8.4 through 12.5, 12.4.3, and 12.3.6 stored several tokens in plaintext."},{"lang":"es","value":"GitLab EE versiones 8.4 hasta 12.5, 12.4.3 y 12.3.6, almacenaron varios tokens en texto plano."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-312"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.4.0","versionEndExcluding":"12.3.8","matchCriteriaId":"F76A9636-E267-4B4C-9B96-D8F535EFB1D1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.4.0","versionEndExcluding":"12.4.5","matchCriteriaId":"2C7ABFDC-276A-4FC0-A1F3-1A5682D63844"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.5.0","versionEndExcluding":"12.5.2","matchCriteriaId":"6BE7EFD6-E3DA-4103-A1FD-FC7C7ABD3487"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/issues/32381","source":"cve@mitre.org","tags":["Broken Link"]},{"url":"https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/issues/32381","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2019-19628","sourceIdentifier":"cve@mitre.org","published":"2020-01-05T22:15:11.173","lastModified":"2026-06-17T02:26:58.377","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In GitLab EE 11.3 through 12.5.3, 12.4.5, and 12.3.8, insufficient parameter sanitization for the Maven package registry could lead to privilege escalation and remote code execution vulnerabilities under certain conditions."},{"lang":"es","value":"En GitLab EE versiones 11.3 hasta 12.5.3, 12.4.5 y 12.3.8, un saneamiento de parámetro insuficiente para el registro del paquete Maven podría derivar a una escalada de privilegios y vulnerabilidades de ejecución de código remota bajo determinadas condiciones."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-22"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.3.0","versionEndIncluding":"12.3.8","matchCriteriaId":"A9499B78-8DC4-4A6F-B15E-51554FB557EC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.4.0","versionEndIncluding":"12.4.5","matchCriteriaId":"01A13F26-D691-4436-80EB-BAF8E5AE4F18"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.5.0","versionEndIncluding":"12.5.3","matchCriteriaId":"A115AF1C-294B-4F45-9BB9-72DA706968E9"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/2019/12/10/critical-security-release-gitlab-12-5-4-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes"]},{"url":"https://about.gitlab.com/blog/2019/12/10/critical-security-release-gitlab-12-5-4-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"]}]}},{"cve":{"id":"CVE-2019-19629","sourceIdentifier":"cve@mitre.org","published":"2020-01-05T22:15:11.253","lastModified":"2026-06-17T02:26:58.493","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In GitLab EE 10.5 through 12.5.3, 12.4.5, and 12.3.8, when transferring a public project to a private group, private code would be disclosed via the Group Search API provided by the Elasticsearch integration."},{"lang":"es","value":"En GitLab EE versiones 10.5 hasta 12.5.3, 12.4.5 y 12.3.8, cuando se transfiere un proyecto público a un grupo privado, el código privado sería divulgado por medio de la API Group Search proporcionada por la integración de Elasticsearch."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.5.0","versionEndIncluding":"12.3.8","matchCriteriaId":"6E6FA3FE-ED7B-4976-8DD2-9421846C9B7A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.4.0","versionEndIncluding":"12.4.5","matchCriteriaId":"01A13F26-D691-4436-80EB-BAF8E5AE4F18"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.5.0","versionEndIncluding":"12.5.3","matchCriteriaId":"A115AF1C-294B-4F45-9BB9-72DA706968E9"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/2019/12/10/critical-security-release-gitlab-12-5-4-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes"]},{"url":"https://about.gitlab.com/blog/2019/12/10/critical-security-release-gitlab-12-5-4-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"]}]}},{"cve":{"id":"CVE-2019-20145","sourceIdentifier":"cve@mitre.org","published":"2020-01-13T20:15:13.607","lastModified":"2026-06-17T02:30:00.277","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 11.4 through 12.6.1. It has Incorrect Access Control."},{"lang":"es","value":"Se descubrió un problema en GitLab Community Edition (CE) and Enterprise Edition (EE) versiones 11.4 hasta la versión  12.6.1. Tiene un Control de Acceso Incorrecto."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.4.0","versionEndIncluding":"12.6.1","matchCriteriaId":"41F70CD7-7BED-41A0-BBCF-312E95A80B30"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.4.0","versionEndIncluding":"12.6.1","matchCriteriaId":"8649D40B-5B56-4D68-AA06-7822A479A3B5"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/01/02/security-release-gitlab-12-6-2-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/01/02/security-release-gitlab-12-6-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-20146","sourceIdentifier":"cve@mitre.org","published":"2020-01-13T20:15:13.687","lastModified":"2026-06-17T02:30:00.390","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 11.0 through 12.6. It allows Uncontrolled Resource Consumption."},{"lang":"es","value":"Se descubrió un problema en GitLab Community Edition (CE) and Enterprise Edition (EE) versiones 11.0 hasta la versión  12.6. Permite un Consumo No Controlado de Recursos."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-400"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.0.0","versionEndIncluding":"12.6.0","matchCriteriaId":"AC3494C2-D981-4E9A-BC16-ECBCDDC5B98F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.0.0","versionEndIncluding":"12.6.0","matchCriteriaId":"57943830-8860-4E13-AFA9-6263899568CA"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/01/02/security-release-gitlab-12-6-2-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/01/02/security-release-gitlab-12-6-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-20147","sourceIdentifier":"cve@mitre.org","published":"2020-01-13T20:15:13.780","lastModified":"2026-06-17T02:30:00.507","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 9.1 through 12.6.1. It has Incorrect Access Control."},{"lang":"es","value":"Se descubrió un problema en GitLab Community Edition (CE) and Enterprise Edition (EE) versiones 9.1 hasta la versión 12.6.1. tiene un Control de Acceso Incorrecto."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"9.1.0","versionEndIncluding":"12.6.1","matchCriteriaId":"178E8D3C-E300-4161-89DD-94AEB0950CB2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"9.1.0","versionEndIncluding":"12.6.1","matchCriteriaId":"F4414CB7-CB32-422B-B2CD-CC9710F89CD0"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/01/02/security-release-gitlab-12-6-2-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/01/02/security-release-gitlab-12-6-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-20148","sourceIdentifier":"cve@mitre.org","published":"2020-01-13T20:15:13.873","lastModified":"2026-06-17T02:30:00.620","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 8.13 through 12.6.1. It has Incorrect Access Control."},{"lang":"es","value":"Se descubrió un problema en GitLab Community Edition (CE) and Enterprise Edition (EE) versiones 8.13 hasta la versión 12.6.1. Tiene un Control de Acceso Incorrecto."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.13","versionEndIncluding":"12.6.1","matchCriteriaId":"51C8C7D8-21F3-4FA8-ACE3-9446526FD093"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.13","versionEndIncluding":"12.6.1","matchCriteriaId":"85B5ECA1-FF73-47BB-92FD-23C75D61B54E"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/01/02/security-release-gitlab-12-6-2-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/01/02/security-release-gitlab-12-6-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-5197","sourceIdentifier":"cve@mitre.org","published":"2020-01-13T20:15:13.983","lastModified":"2026-06-17T03:21:00.580","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 5.1 through 12.6.1. It has Incorrect Access Control."},{"lang":"es","value":"Se descubrió un problema en GitLab Community Edition (CE) and Enterprise Edition (EE) versiones 5.1 hasta la versión 12.6.1. Tiene un Control de Acceso Incorrecto."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:P/I:N/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-200"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"5.1.0","versionEndIncluding":"12.6.1","matchCriteriaId":"E3A7E30B-AD83-4C18-9CE6-52FAD58F53EA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"5.1.0","versionEndIncluding":"12.6.1","matchCriteriaId":"8908F9BA-3BD4-4BBF-9C2E-8EC412BC9284"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/01/02/security-release-gitlab-12-6-2-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/01/02/security-release-gitlab-12-6-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-6832","sourceIdentifier":"cve@mitre.org","published":"2020-01-13T20:15:14.063","lastModified":"2026-06-17T03:23:53.310","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Enterprise Edition (EE) 8.9.0 through 12.6.1. Using the project import feature, it was possible for someone to obtain issues from private projects."},{"lang":"es","value":"Se descubrió un problema en GitLab Enterprise Edition (EE) versiones 8.9.0 hasta la versión 12.6.1. Usando la funcionalidad de importación de proyectos, fue posible que alguien obtuviera problemas a partir de proyectos privados."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.9.0","versionEndIncluding":"12.6.1","matchCriteriaId":"37E232F3-BEE8-4B3E-88A9-B51A6258CF03"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.9.0","versionEndIncluding":"12.6.1","matchCriteriaId":"0FF6288D-C9C8-47CB-BFB1-D30A2D51382F"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/01/13/critical-security-release-gitlab-12-dot-6-dot-4-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/01/13/critical-security-release-gitlab-12-dot-6-dot-4-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-20142","sourceIdentifier":"cve@mitre.org","published":"2020-01-13T21:15:11.197","lastModified":"2026-06-17T02:29:59.937","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 12.3 through 12.6.1. It allows Denial of Service."},{"lang":"es","value":"Se descubrió un problema en GitLab Community Edition (CE) and Enterprise Edition (EE) versiones 12.3 hasta la versión 12.6.1. Permite una Denegación de Servicio."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:N/A:P","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.3.0","versionEndIncluding":"12.6.1","matchCriteriaId":"3FEBE0AA-4812-4FC1-9F08-A0A4E708423C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.3.0","versionEndIncluding":"12.6.1","matchCriteriaId":"B6F56D50-775A-4E1E-A1CE-798EB4940DE3"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/01/02/security-release-gitlab-12-6-2-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/01/02/security-release-gitlab-12-6-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-20143","sourceIdentifier":"cve@mitre.org","published":"2020-01-13T21:15:11.307","lastModified":"2026-06-17T02:30:00.057","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 12.6. It has Incorrect Access Control."},{"lang":"es","value":"Se descubrió un problema en GitLab Community Edition (CE) and Enterprise Edition (EE) versión 12.6. Tiene un Control de Acceso Incorrecto."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-306"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:12.6.0:*:*:*:community:*:*:*","matchCriteriaId":"5BEE65CF-7FC8-4409-8FC7-9D0083779204"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:12.6.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"46BCD350-71F7-4490-8B2D-FD1DA1C4F691"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/01/02/security-release-gitlab-12-6-2-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/01/02/security-release-gitlab-12-6-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-20144","sourceIdentifier":"cve@mitre.org","published":"2020-01-13T21:15:11.400","lastModified":"2026-06-17T02:30:00.163","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 10.8 through 12.6.1. It has Incorrect Access Control."},{"lang":"es","value":"Se descubrió un problema en GitLab Community Edition (CE) and Enterprise Edition (EE) versiones 10.8 hasta la versión 12.6.1. Tiene un Control de Acceso Incorrecto."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.8.0","versionEndIncluding":"12.6.1","matchCriteriaId":"1B87FBC2-FD35-41CD-B468-96700BF3262E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.8.0","versionEndIncluding":"12.6.1","matchCriteriaId":"571DAFB1-693B-443A-8D69-4FC40FFAB7A4"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/01/02/security-release-gitlab-12-6-2-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/01/02/security-release-gitlab-12-6-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-15578","sourceIdentifier":"support@hackerone.com","published":"2020-01-28T03:15:10.200","lastModified":"2026-06-17T02:20:40.737","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE). The path of a private project, that used to be public, would be disclosed in the unsubscribe email link of issues and merge requests."},{"lang":"es","value":"Se presenta una divulgación de información en versiones anteriores a 12.3.2, versiones anteriores a 12.2.6 y versiones anteriores a 12.1.12 para GitLab Community Edition (CE) y Enterprise Edition (EE). La ruta de un proyecto privado, que solía ser pública, sería divulgada en el enlace de correo  electrónico de desafiliación de problemas y peticiones de fusión."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"GitLab","product":"GitLab CE/EE","versions":[{"version":"before 12.3.2","status":"affected"},{"version":"before 12.2.6","status":"affected"},{"version":"before 12.1.12","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"support@hackerone.com","type":"Secondary","description":[{"lang":"en","value":"CWE-200"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-200"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.12","matchCriteriaId":"EA55F9E0-8A03-4981-8F24-0AB5B41D341C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.12","matchCriteriaId":"FE25BD72-3EF8-4D1B-A81D-B9B2DC08A6CB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.6","matchCriteriaId":"ABCEAA2E-75C8-426B-8EAA-52D3F78FB2A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.6","matchCriteriaId":"AF5AC653-CE12-4759-B07A-04C20B9EBA7B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.3.0","versionEndExcluding":"12.3.2","matchCriteriaId":"5BB337AA-1FBB-4BEF-9652-F462CEC4BE71"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.3.0","versionEndExcluding":"12.3.2","matchCriteriaId":"DB3CF71C-AD05-4866-9629-0DB7E92775C2"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/2019/09/30/security-release-gitlab-12-dot-3-dot-2-released/","source":"support@hackerone.com","tags":["Vendor Advisory"]},{"url":"https://hackerone.com/reports/650574","source":"support@hackerone.com","tags":["Permissions Required"]},{"url":"https://about.gitlab.com/blog/2019/09/30/security-release-gitlab-12-dot-3-dot-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://hackerone.com/reports/650574","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2019-15579","sourceIdentifier":"support@hackerone.com","published":"2020-01-28T03:15:10.263","lastModified":"2026-06-17T02:20:40.853","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) where the assignee(s) of a confidential issue in a private project would be disclosed to a guest via milestones."},{"lang":"es","value":"Se presenta una divulgación de información en versiones anteriores a 12.3.2, versiones anteriores a 12.2.6 y versiones anteriores a 12.1.12 para GitLab Community Edition (CE) y Enterprise Edition (EE), donde el o los cesionarios de un problema confidencial en un proyecto privado serían revelados a un invitado por medio de hitos."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"GitLab","product":"GitLab CE/EE","versions":[{"version":"before 12.3.2","status":"affected"},{"version":"before 12.2.6","status":"affected"},{"version":"before 12.1.12","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"support@hackerone.com","type":"Secondary","description":[{"lang":"en","value":"CWE-200"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.12","matchCriteriaId":"EA55F9E0-8A03-4981-8F24-0AB5B41D341C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.12","matchCriteriaId":"FE25BD72-3EF8-4D1B-A81D-B9B2DC08A6CB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.6","matchCriteriaId":"ABCEAA2E-75C8-426B-8EAA-52D3F78FB2A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.6","matchCriteriaId":"AF5AC653-CE12-4759-B07A-04C20B9EBA7B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.3.0","versionEndExcluding":"12.3.2","matchCriteriaId":"5BB337AA-1FBB-4BEF-9652-F462CEC4BE71"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.3.0","versionEndExcluding":"12.3.2","matchCriteriaId":"DB3CF71C-AD05-4866-9629-0DB7E92775C2"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/2019/09/30/security-release-gitlab-12-dot-3-dot-2-released/","source":"support@hackerone.com","tags":["Vendor Advisory"]},{"url":"https://hackerone.com/reports/635516","source":"support@hackerone.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://about.gitlab.com/blog/2019/09/30/security-release-gitlab-12-dot-3-dot-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://hackerone.com/reports/635516","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2019-15581","sourceIdentifier":"support@hackerone.com","published":"2020-01-28T03:15:10.340","lastModified":"2026-06-17T02:20:41.093","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An IDOR exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) that allowed a project owner or maintainer to see the members of any private group via merge request approval rules."},{"lang":"es","value":"Se presenta un IDOR en versiones anteriores a 12.3.2, versiones anteriores a 12.2.6 y versiones anteriores a 12.1.12 para GitLab Community Edition (CE) y Enterprise Edition (EE), que permitió al propietario o mantenedor del proyecto visualizar a los miembros de cualquier grupo privado mediante las reglas de aprobación de petición de fusión."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"GitLab","product":"GitLab EE","versions":[{"version":"before 12.3.2","status":"affected"},{"version":"before 12.2.6","status":"affected"},{"version":"before 12.1.12","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"support@hackerone.com","type":"Secondary","description":[{"lang":"en","value":"CWE-639"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-639"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.12","matchCriteriaId":"EA55F9E0-8A03-4981-8F24-0AB5B41D341C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.12","matchCriteriaId":"FE25BD72-3EF8-4D1B-A81D-B9B2DC08A6CB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.6","matchCriteriaId":"ABCEAA2E-75C8-426B-8EAA-52D3F78FB2A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.6","matchCriteriaId":"AF5AC653-CE12-4759-B07A-04C20B9EBA7B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.3.0","versionEndExcluding":"12.3.2","matchCriteriaId":"5BB337AA-1FBB-4BEF-9652-F462CEC4BE71"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.3.0","versionEndExcluding":"12.3.2","matchCriteriaId":"DB3CF71C-AD05-4866-9629-0DB7E92775C2"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/2019/09/30/security-release-gitlab-12-dot-3-dot-2-released/","source":"support@hackerone.com","tags":["Vendor Advisory"]},{"url":"https://hackerone.com/reports/518995","source":"support@hackerone.com","tags":["Permissions Required"]},{"url":"https://about.gitlab.com/blog/2019/09/30/security-release-gitlab-12-dot-3-dot-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://hackerone.com/reports/518995","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2019-15582","sourceIdentifier":"support@hackerone.com","published":"2020-01-28T03:15:10.403","lastModified":"2026-06-17T02:20:41.213","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An IDOR was discovered in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) that allowed a maintainer to add any private group to a protected environment."},{"lang":"es","value":"Se detectó un IDOR en versiones anteriores a 12.3.2, versiones anteriores a 12.2.6 y versiones anteriores a 12.1.12 para GitLab Community Edition (CE) y Enterprise Edition (EE), que permitió a un mantenedor agregar cualquier grupo privado a un entorno protegido."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"GitLab","product":"GitLab EE","versions":[{"version":"before 12.3.2","status":"affected"},{"version":"before 12.2.6","status":"affected"},{"version":"before 12.1.12","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"support@hackerone.com","type":"Secondary","description":[{"lang":"en","value":"CWE-639"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-639"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.12","matchCriteriaId":"EA55F9E0-8A03-4981-8F24-0AB5B41D341C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.12","matchCriteriaId":"FE25BD72-3EF8-4D1B-A81D-B9B2DC08A6CB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.6","matchCriteriaId":"ABCEAA2E-75C8-426B-8EAA-52D3F78FB2A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.6","matchCriteriaId":"AF5AC653-CE12-4759-B07A-04C20B9EBA7B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.3.0","versionEndExcluding":"12.3.2","matchCriteriaId":"5BB337AA-1FBB-4BEF-9652-F462CEC4BE71"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.3.0","versionEndExcluding":"12.3.2","matchCriteriaId":"DB3CF71C-AD05-4866-9629-0DB7E92775C2"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/2019/09/30/security-release-gitlab-12-dot-3-dot-2-released/","source":"support@hackerone.com","tags":["Vendor Advisory"]},{"url":"https://hackerone.com/reports/566216","source":"support@hackerone.com","tags":["Permissions Required"]},{"url":"https://about.gitlab.com/blog/2019/09/30/security-release-gitlab-12-dot-3-dot-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://hackerone.com/reports/566216","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2019-15583","sourceIdentifier":"support@hackerone.com","published":"2020-01-28T03:15:10.497","lastModified":"2026-06-17T02:20:41.330","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE). When an issue was moved to a public project from a private one, the associated private labels and the private project namespace would be disclosed through the GitLab API."},{"lang":"es","value":"Se presenta una divulgación de información en versiones anteriores a 12.3.2, versiones anteriores a 12.2.6 y versiones anteriores a 12.1.12 para GitLab Community Edition (CE) y Enterprise Edition (EE). Cuando un problema fue trasladado hacia un proyecto público desde uno privado, las etiquetas privadas asociadas y el espacio de nombres del proyecto privado serían divulgados por medio de la API de GitLab."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"GitLab","product":"GitLab CE/EE","versions":[{"version":"before 12.3.2","status":"affected"},{"version":"before 12.2.6","status":"affected"},{"version":"before 12.1.12","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"support@hackerone.com","type":"Secondary","description":[{"lang":"en","value":"CWE-200"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-200"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.12","matchCriteriaId":"EA55F9E0-8A03-4981-8F24-0AB5B41D341C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.12","matchCriteriaId":"FE25BD72-3EF8-4D1B-A81D-B9B2DC08A6CB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.6","matchCriteriaId":"ABCEAA2E-75C8-426B-8EAA-52D3F78FB2A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.6","matchCriteriaId":"AF5AC653-CE12-4759-B07A-04C20B9EBA7B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.3.0","versionEndExcluding":"12.3.2","matchCriteriaId":"5BB337AA-1FBB-4BEF-9652-F462CEC4BE71"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.3.0","versionEndExcluding":"12.3.2","matchCriteriaId":"DB3CF71C-AD05-4866-9629-0DB7E92775C2"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/2019/09/30/security-release-gitlab-12-dot-3-dot-2-released/","source":"support@hackerone.com","tags":["Vendor Advisory"]},{"url":"https://hackerone.com/reports/643854","source":"support@hackerone.com","tags":["Permissions Required"]},{"url":"https://about.gitlab.com/blog/2019/09/30/security-release-gitlab-12-dot-3-dot-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://hackerone.com/reports/643854","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2019-15585","sourceIdentifier":"support@hackerone.com","published":"2020-01-28T03:15:10.573","lastModified":"2026-06-17T02:20:41.560","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Improper authentication exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) in the GitLab SAML integration had a validation issue that permitted an attacker to takeover another user's account."},{"lang":"es","value":"Se presenta una autenticación inapropiada en versiones anteriores a 12.3.2, versiones anteriores a 12.2.6 y versiones anteriores a 12.1.12 para GitLab Community Edition (CE) y Enterprise Edition (EE), en la integración GitLab SAML se presenta un problema de comprobación que permitió a un atacante tomar el control de la cuenta de otro usuario."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"GitLab","product":"Gitlab CE/EE","versions":[{"version":"before 12.3.2","status":"affected"},{"version":"before 12.2.6","status":"affected"},{"version":"before 12.1.12","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"support@hackerone.com","type":"Secondary","description":[{"lang":"en","value":"CWE-287"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-287"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.12","matchCriteriaId":"EA55F9E0-8A03-4981-8F24-0AB5B41D341C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.12","matchCriteriaId":"FE25BD72-3EF8-4D1B-A81D-B9B2DC08A6CB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.6","matchCriteriaId":"ABCEAA2E-75C8-426B-8EAA-52D3F78FB2A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.6","matchCriteriaId":"AF5AC653-CE12-4759-B07A-04C20B9EBA7B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.3.0","versionEndExcluding":"12.3.2","matchCriteriaId":"5BB337AA-1FBB-4BEF-9652-F462CEC4BE71"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.3.0","versionEndExcluding":"12.3.2","matchCriteriaId":"DB3CF71C-AD05-4866-9629-0DB7E92775C2"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/2019/09/30/security-release-gitlab-12-dot-3-dot-2-released/","source":"support@hackerone.com","tags":["Vendor Advisory"]},{"url":"https://hackerone.com/reports/471323","source":"support@hackerone.com","tags":["Permissions Required"]},{"url":"https://about.gitlab.com/blog/2019/09/30/security-release-gitlab-12-dot-3-dot-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://hackerone.com/reports/471323","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2019-15586","sourceIdentifier":"support@hackerone.com","published":"2020-01-28T03:15:10.637","lastModified":"2026-06-17T02:20:41.677","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A XSS exists in Gitlab CE/EE < 12.1.10 in the Mermaid plugin."},{"lang":"es","value":"Se presenta una vulnerabilidad de tipo XSS en Gitlab CE/EE versiones anteriores a 12.1.10, en el complemento Mermaid."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"GitLab","product":"Gitlab CE/EE","versions":[{"version":"before 12.1.10","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"support@hackerone.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.10","matchCriteriaId":"589F861E-094C-485C-A33F-F4113206C70E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.10","matchCriteriaId":"7BA8FBCA-CC5C-4D17-88C6-EB14B35E19F1"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/2019/09/30/security-release-gitlab-12-dot-3-dot-2-released/","source":"support@hackerone.com","tags":["Vendor Advisory"]},{"url":"https://hackerone.com/reports/645043","source":"support@hackerone.com","tags":["Permissions Required"]},{"url":"https://about.gitlab.com/blog/2019/09/30/security-release-gitlab-12-dot-3-dot-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://hackerone.com/reports/645043","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2019-15590","sourceIdentifier":"support@hackerone.com","published":"2020-01-28T03:15:10.717","lastModified":"2026-06-17T02:20:42.157","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An access control issue exists in < 12.3.5, < 12.2.8, and < 12.1.14 for GitLab Community Edition (CE) and Enterprise Edition (EE) where private merge requests and issues would be disclosed with the Group Search feature provided by Elasticsearch integration"},{"lang":"es","value":"Se presenta un problema de control de acceso en versiones anteriores a 12.3.5, versiones anteriores a 12.2.8 y versiones anteriores a 12.1.14 para GitLab Community Edition (CE) y Enterprise Edition (EE), donde las peticiones y problemas de fusión privada serían divulgados con la funcionalidad Group Search proporcionada por la integración Elasticsearch."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"GitLab","product":"GitLab EE","versions":[{"version":"before 12.3.5","status":"affected"},{"version":"before 12.2.8","status":"affected"},{"version":"before 12.1.14","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"support@hackerone.com","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.14","matchCriteriaId":"58179BD4-F1A3-4BF0-9CED-A3A26022E044"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.14","matchCriteriaId":"F63D9855-07A6-4498-A85C-53FF85EFB2B2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.8","matchCriteriaId":"C48750EE-F01A-4EB6-A54D-FAA997A996B0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.8","matchCriteriaId":"D02BA806-98A1-489D-8285-7E6591246714"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.3.0","versionEndExcluding":"12.3.5","matchCriteriaId":"74F9E3F7-91CD-4334-A789-C878BDD3BBFF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.3.0","versionEndExcluding":"12.3.5","matchCriteriaId":"37B80747-1EBB-4906-B129-F3F73C0BE9B2"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2019/10/07/security-release-gitlab-12-dot-3-dot-5-released/","source":"support@hackerone.com","tags":["Vendor Advisory"]},{"url":"https://hackerone.com/reports/701144","source":"support@hackerone.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://about.gitlab.com/releases/2019/10/07/security-release-gitlab-12-dot-3-dot-5-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://hackerone.com/reports/701144","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2019-5462","sourceIdentifier":"support@hackerone.com","published":"2020-01-28T03:15:10.857","lastModified":"2026-06-17T02:37:43.903","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A privilege escalation issue was discovered in GitLab CE/EE 9.0 and later when trigger tokens are not rotated once ownership of them has changed."},{"lang":"es","value":"Se detectó un problema de escalada de privilegios en GitLab CE/EE versiones 9.0 y posteriores, cuando los tokens de activación no son rotados una vez que la propiedad de ellos ha cambiado."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"GitLab","product":"GitLab Community Edition and GitLab Enterprise Edition","versions":[{"version":"Affects GitLab CE/EE 9.0 and later","status":"affected"},{"version":"Fixed in 12.1.2 in 12.0.4 and in 11.11.6","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-613"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"9.0.0","versionEndExcluding":"11.11.7","matchCriteriaId":"77236F56-7013-4DB8-AD3B-162CF76BA076"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"9.0.0","versionEndExcluding":"11.11.7","matchCriteriaId":"B3782482-4816-4D4F-A59E-A0AD92F0207D"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2019/07/29/security-release-gitlab-12-dot-1-dot-2-released/","source":"support@hackerone.com","tags":["Patch","Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/58312","source":"support@hackerone.com","tags":["Exploit","Vendor Advisory"]},{"url":"https://hackerone.com/reports/495282","source":"support@hackerone.com","tags":["Permissions Required"]},{"url":"https://about.gitlab.com/releases/2019/07/29/security-release-gitlab-12-dot-1-dot-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/58312","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]},{"url":"https://hackerone.com/reports/495282","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2019-5464","sourceIdentifier":"support@hackerone.com","published":"2020-01-28T03:15:10.903","lastModified":"2026-06-17T02:37:44.110","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A flawed DNS rebinding protection issue was discovered in GitLab CE/EE 10.2 and later in the `url_blocker.rb` which could result in SSRF where the library is utilized."},{"lang":"es","value":"Se detectó un problema de fallo de protección de un reenlace de DNS en GitLab CE/EE versiones 10.2 y posteriores, en el archivo \"url_blocker.rb\" que podría resultar en vulnerabilidad de tipo SSRF donde la biblioteca es utilizada."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"GitLab","product":"GitLab CE/EE","versions":[{"version":"Affects GitLab CE/EE 10.2 and later","status":"affected"},{"version":"Fixed in 12.1.2 in 12.0.4 and in 11.11.6","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"support@hackerone.com","type":"Secondary","description":[{"lang":"en","value":"CWE-20"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.2.0","versionEndExcluding":"11.11.7","matchCriteriaId":"45C55859-5F6B-4FD7-9DF5-431DF4D9454B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.2.0","versionEndExcluding":"11.11.7","matchCriteriaId":"265380D4-A82B-4A5A-9F41-5E1311515AB8"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2019/07/29/security-release-gitlab-12-dot-1-dot-2-released/","source":"support@hackerone.com","tags":["Patch","Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/63959","source":"support@hackerone.com","tags":["Exploit","Vendor Advisory"]},{"url":"https://hackerone.com/reports/632101","source":"support@hackerone.com","tags":["Permissions Required"]},{"url":"https://about.gitlab.com/releases/2019/07/29/security-release-gitlab-12-dot-1-dot-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/63959","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]},{"url":"https://hackerone.com/reports/632101","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2019-5465","sourceIdentifier":"support@hackerone.com","published":"2020-01-28T03:15:10.980","lastModified":"2026-06-17T02:37:44.217","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An information disclosure issue was discovered in GitLab CE/EE 8.14 and later, by using the move issue feature which could result in disclosure of the newly created issue ID."},{"lang":"es","value":"Se detectó un problema de divulgación de información en GitLab CE/EE versiones 8.14 y posteriores, mediante el uso de la funcionalidad move issue lo que podría resultar en la divulgación del ID de un problema creado recientemente."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"GitLab","product":"GitLab CE/EE","versions":[{"version":"Affects GitLab CE/EE 8.14 and later","status":"affected"},{"version":"Fixed in 12.1.2 in 12.0.4 and in 11.11.6","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"support@hackerone.com","type":"Secondary","description":[{"lang":"en","value":"CWE-200"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.14.0","versionEndExcluding":"11.11.7","matchCriteriaId":"E231171F-A62E-44DD-9F31-CE288F7E461B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.14.0","versionEndExcluding":"11.11.7","matchCriteriaId":"E078A819-EEDD-4C78-8915-4D742041883C"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2019/07/29/security-release-gitlab-12-dot-1-dot-2-released/","source":"support@hackerone.com","tags":["Patch","Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/62070","source":"support@hackerone.com","tags":["Exploit","Vendor Advisory"]},{"url":"https://hackerone.com/reports/584534","source":"support@hackerone.com","tags":["Permissions Required"]},{"url":"https://about.gitlab.com/releases/2019/07/29/security-release-gitlab-12-dot-1-dot-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/62070","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]},{"url":"https://hackerone.com/reports/584534","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2019-5466","sourceIdentifier":"support@hackerone.com","published":"2020-01-28T03:15:11.043","lastModified":"2026-06-17T02:37:44.317","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An IDOR was discovered in GitLab CE/EE 11.5 and later that allowed new merge requests endpoint to disclose label names."},{"lang":"es","value":"Se detectó un IDOR en GitLab CE/EE versiones 11.5 y posteriores, que permitía nuevos endpoints de peticiones de fusión para revelar nombres de etiquetas."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"n/a","product":"GitLab CE/EE","versions":[{"version":"Affects GitLab CE/EE 11.5 and later","status":"affected"},{"version":"Fixed in 12.1.2 in 12.0.4 and in 11.11.6","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"support@hackerone.com","type":"Secondary","description":[{"lang":"en","value":"CWE-639"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-639"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.11.7","matchCriteriaId":"40E858BA-EF2A-403E-9C00-45DF0C5D0908"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.11.7","matchCriteriaId":"479BCD91-D442-4FB2-AA1F-CE61447781AE"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2019/07/29/security-release-gitlab-12-dot-1-dot-2-released/","source":"support@hackerone.com","tags":["Patch","Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/59809","source":"support@hackerone.com","tags":["Exploit","Vendor Advisory"]},{"url":"https://hackerone.com/reports/507113","source":"support@hackerone.com","tags":["Permissions Required"]},{"url":"https://about.gitlab.com/releases/2019/07/29/security-release-gitlab-12-dot-1-dot-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/59809","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]},{"url":"https://hackerone.com/reports/507113","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2019-5468","sourceIdentifier":"support@hackerone.com","published":"2020-01-28T03:15:11.107","lastModified":"2026-06-17T02:37:44.520","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An privilege escalation issue was discovered in Gitlab versions < 12.1.2, < 12.0.4, and < 11.11.6 when Mattermost slash commands are used with a blocked account."},{"lang":"es","value":"Se detectó un problema de escalada de privilegios en GitLab versiones anteriores a 12.1.2, versiones anteriores a 12.0.4 y versiones anteriores a 11.11.6, cuando los comandos de barra de Mattermost son usados con una cuenta bloqueada."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"GiltLab","product":"GitLab","versions":[{"version":"before 12.1.2","status":"affected"},{"version":"before 12.0.4","status":"affected"},{"version":"before 11.11.6","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-269"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.11.0","versionEndExcluding":"11.11.6","matchCriteriaId":"470E2D2F-030A-49C2-AF61-DDC659EBFCC6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.11.0","versionEndExcluding":"11.11.6","matchCriteriaId":"5F241A58-C88E-4155-AF2B-7B852465558E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.0.0","versionEndExcluding":"12.0.4","matchCriteriaId":"62DEEA13-4D2C-436B-9780-983FC707DDF6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.0.0","versionEndExcluding":"12.0.4","matchCriteriaId":"595B584B-2A5C-44F6-AC4C-51ACF913C6C5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.2","matchCriteriaId":"99659BEC-15D0-4E75-BEBE-727FC32D9B35"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.2","matchCriteriaId":"D12A3A81-4A4F-441A-A820-F2D19B1A5C89"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2019/07/29/security-release-gitlab-12-dot-1-dot-2-released/","source":"support@hackerone.com","tags":["Patch","Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/57556","source":"support@hackerone.com","tags":["Exploit","Vendor Advisory"]},{"url":"https://hackerone.com/reports/493562","source":"support@hackerone.com","tags":["Permissions Required"]},{"url":"https://about.gitlab.com/releases/2019/07/29/security-release-gitlab-12-dot-1-dot-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/57556","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]},{"url":"https://hackerone.com/reports/493562","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2019-5470","sourceIdentifier":"support@hackerone.com","published":"2020-01-28T03:15:11.167","lastModified":"2026-06-17T02:37:44.730","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An information disclosure issue was discovered GitLab versions < 12.1.2, < 12.0.4, and < 11.11.6 in the security dashboard which could result in disclosure of vulnerability feedback information."},{"lang":"es","value":"Se detectó un problema de divulgación de información en GitLab versiones anteriores a 12.1.2, versiones anteriores a 12.0.4 y versiones anteriores a 11.11.6, en el panel de seguridad que podría resultar en la divulgación de la información de retroalimentación de la vulnerabilidad."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":"before 12.1.2","status":"affected"},{"version":"before 12.0.4","status":"affected"},{"version":"before 11.11.6","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"support@hackerone.com","type":"Secondary","description":[{"lang":"en","value":"CWE-200"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.8.0","versionEndExcluding":"11.11.6","matchCriteriaId":"BAB57750-B567-4E4F-822C-0BA2B6D10A4D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.8.0","versionEndExcluding":"11.11.6","matchCriteriaId":"3E4D688F-A03E-4AB6-9448-C232AD50C683"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.0.0","versionEndExcluding":"12.0.4","matchCriteriaId":"62DEEA13-4D2C-436B-9780-983FC707DDF6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.0.0","versionEndExcluding":"12.0.4","matchCriteriaId":"595B584B-2A5C-44F6-AC4C-51ACF913C6C5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.2","matchCriteriaId":"99659BEC-15D0-4E75-BEBE-727FC32D9B35"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.2","matchCriteriaId":"D12A3A81-4A4F-441A-A820-F2D19B1A5C89"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2019/07/29/security-release-gitlab-12-dot-1-dot-2-released/","source":"support@hackerone.com","tags":["Patch","Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ee/issues/9665","source":"support@hackerone.com","tags":["Vendor Advisory"]},{"url":"https://hackerone.com/reports/490250","source":"support@hackerone.com","tags":["Permissions Required"]},{"url":"https://about.gitlab.com/releases/2019/07/29/security-release-gitlab-12-dot-1-dot-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ee/issues/9665","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://hackerone.com/reports/490250","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2019-5472","sourceIdentifier":"support@hackerone.com","published":"2020-01-28T03:15:11.247","lastModified":"2026-06-17T02:37:44.950","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An authorization issue was discovered in Gitlab versions < 12.1.2, < 12.0.4, and < 11.11.6 that prevented owners and maintainer to delete epic comments."},{"lang":"es","value":"Se detectó un problema de autorización en GitLab versiones anteriores a 12.1.2, versiones anteriores a 12.0.4 y versiones anteriores a 11.11.6, que impedían a los propietarios y al mantenedor eliminar comentarios épicos."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":"before 12.1.2","status":"affected"},{"version":"before 12.0.4","status":"affected"},{"version":"before 11.11.6","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"support@hackerone.com","type":"Secondary","description":[{"lang":"en","value":"CWE-400"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-269"},{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.11.0","versionEndExcluding":"11.11.6","matchCriteriaId":"470E2D2F-030A-49C2-AF61-DDC659EBFCC6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.11.0","versionEndExcluding":"11.11.6","matchCriteriaId":"5F241A58-C88E-4155-AF2B-7B852465558E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.0.0","versionEndExcluding":"12.0.4","matchCriteriaId":"62DEEA13-4D2C-436B-9780-983FC707DDF6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.0.0","versionEndExcluding":"12.0.4","matchCriteriaId":"595B584B-2A5C-44F6-AC4C-51ACF913C6C5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.2","matchCriteriaId":"99659BEC-15D0-4E75-BEBE-727FC32D9B35"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.2","matchCriteriaId":"D12A3A81-4A4F-441A-A820-F2D19B1A5C89"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2019/07/29/security-release-gitlab-12-dot-1-dot-2-released/","source":"support@hackerone.com","tags":["Patch","Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ee/issues/11381","source":"support@hackerone.com","tags":["Exploit","Vendor Advisory"]},{"url":"https://hackerone.com/reports/538101","source":"support@hackerone.com","tags":["Permissions Required"]},{"url":"https://about.gitlab.com/releases/2019/07/29/security-release-gitlab-12-dot-1-dot-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ee/issues/11381","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]},{"url":"https://hackerone.com/reports/538101","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2019-5474","sourceIdentifier":"support@hackerone.com","published":"2020-01-28T03:15:11.310","lastModified":"2026-06-17T02:37:45.160","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An authorization issue was discovered in GitLab EE < 12.1.2, < 12.0.4, and < 11.11.6 allowing the merge request approval rules to be overridden without appropriate permissions."},{"lang":"es","value":"Se detectó un problema de autorización en GitLab EE versiones anteriores a 12.1.2, versiones anteriores a 12.0.4 y versiones anteriores a 11.11.6, permitiendo que las reglas de aprobación de petición de fusión sea anuladas sin los permisos apropiados."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"GitLab","product":"GitLab EE","versions":[{"version":"before 12.1.2","status":"affected"},{"version":"before 12.0.4","status":"affected"},{"version":"before 11.11.6","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"support@hackerone.com","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"11.11.6","matchCriteriaId":"0DFC060B-1FAC-44C9-9300-0E2F5B5CAE69"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.0.0","versionEndExcluding":"12.0.4","matchCriteriaId":"595B584B-2A5C-44F6-AC4C-51ACF913C6C5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.2","matchCriteriaId":"D12A3A81-4A4F-441A-A820-F2D19B1A5C89"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2019/07/29/security-release-gitlab-12-dot-1-dot-2-released/","source":"support@hackerone.com","tags":["Patch","Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ee/issues/11423","source":"support@hackerone.com","tags":["Exploit","Vendor Advisory"]},{"url":"https://hackerone.com/reports/544756","source":"support@hackerone.com","tags":["Permissions Required"]},{"url":"https://about.gitlab.com/releases/2019/07/29/security-release-gitlab-12-dot-1-dot-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-ee/issues/11423","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]},{"url":"https://hackerone.com/reports/544756","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2013-4582","sourceIdentifier":"secalert@redhat.com","published":"2020-01-28T16:15:11.633","lastModified":"2026-06-16T23:57:29.713","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"The (1) create_branch, (2) create_tag, (3) import_project, and (4) fork_project functions in lib/gitlab_projects.rb in GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote authenticated users to include information from local files into the metadata of a Git repository via the web interface."},{"lang":"es","value":"Las funciones (1) create_branch, (2) create_tag, (3) import_project y (4) fork_project en el archivo lib/gitlab_projects.rb en GitLab versiones 5.0 anteriores a 5.4.2, Community Edition versiones anteriores a 6.2.4, Enterprise Edition versiones anteriores a 6.2.1 y gitlab-shell versiones anteriores a 1.7.8, permite a usuarios autenticados remotos incluir información de archivos locales en los metadatos de un repositorio de Git por medio de la interfaz web."}],"affected":[{"source":"secalert@redhat.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":"5.0 before 5.4.2","status":"affected"}]},{"vendor":"GitLab","product":"GitLab Community Edition","versions":[{"version":"before 6.2.4","status":"affected"}]},{"vendor":"GitLab","product":"GitLab Enterprise Edition","versions":[{"version":"before 6.2.1","status":"affected"}]},{"vendor":"GitLab","product":"gitlab-shell","versions":[{"version":"before 1.7.8","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-829"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"5.0.0","versionEndExcluding":"5.4.2","matchCriteriaId":"EFC253A4-2439-48AB-A8EE-B5044C854BA8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"6.0.0","versionEndExcluding":"6.2.1","matchCriteriaId":"7EF97FC1-3CFD-4845-8FDE-030F03E44D9F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"6.0.0","versionEndExcluding":"6.2.4","matchCriteriaId":"EBF7F82C-67FB-456F-A8B5-5944124F7D42"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab-shell:*:*:*:*:*:*:*:*","versionEndExcluding":"1.7.8","matchCriteriaId":"AEE8E666-9552-4559-9D80-B3F749F68AF7"}]}]}],"references":[{"url":"http://www.openwall.com/lists/oss-security/2013/11/15/4","source":"secalert@redhat.com","tags":["Mailing List","Third Party Advisory"]},{"url":"https://www.gitlab.com/2013/11/14/multiple-critical-vulnerabilities-in-gitlab/","source":"secalert@redhat.com","tags":["Permissions Required"]},{"url":"https://www.openwall.com/lists/oss-security/2013/11/18/4","source":"secalert@redhat.com","tags":["Mailing List","Third Party Advisory"]},{"url":"http://www.openwall.com/lists/oss-security/2013/11/15/4","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"]},{"url":"https://www.gitlab.com/2013/11/14/multiple-critical-vulnerabilities-in-gitlab/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]},{"url":"https://www.openwall.com/lists/oss-security/2013/11/18/4","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2013-4583","sourceIdentifier":"secalert@redhat.com","published":"2020-01-28T16:15:11.743","lastModified":"2026-06-16T23:57:29.833","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"The parse_cmd function in lib/gitlab_shell.rb in GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, and Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote authenticated users to gain privileges and clone arbitrary repositories."},{"lang":"es","value":"La función parse_cmd en el archivo lib/gitlab_shell.rb en GitLab versiones 5.0 anteriores a 5.4.2, Community Edition versiones anteriores a 6.2.4 y Enterprise Edition versiones anteriores a 6.2.1 y gitlab-shell versiones anteriores a 1.7.8, permite a usuarios autenticados remotos alcanzar privilegios y clonar repositorios arbitrarios ."}],"affected":[{"source":"secalert@redhat.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":"5.0 before 5.4.2","status":"affected"}]},{"vendor":"GitLab","product":"GitLab Community Edition","versions":[{"version":"before 6.2.4","status":"affected"}]},{"vendor":"GitLab","product":"GitLab Enterprise Edition","versions":[{"version":"before 6.2.1","status":"affected"}]},{"vendor":"GitLab","product":"gitlab-shell","versions":[{"version":"before 1.7.8","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-269"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"5.0.0","versionEndExcluding":"5.4.2","matchCriteriaId":"EFC253A4-2439-48AB-A8EE-B5044C854BA8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"6.0.0","versionEndExcluding":"6.2.1","matchCriteriaId":"7EF97FC1-3CFD-4845-8FDE-030F03E44D9F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"6.0.0","versionEndExcluding":"6.2.4","matchCriteriaId":"EBF7F82C-67FB-456F-A8B5-5944124F7D42"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab-shell:*:*:*:*:*:*:*:*","versionEndExcluding":"1.7.8","matchCriteriaId":"AEE8E666-9552-4559-9D80-B3F749F68AF7"}]}]}],"references":[{"url":"http://www.openwall.com/lists/oss-security/2013/11/15/4","source":"secalert@redhat.com","tags":["Mailing List","Third Party Advisory"]},{"url":"https://www.gitlab.com/2013/11/14/multiple-critical-vulnerabilities-in-gitlab/","source":"secalert@redhat.com","tags":["Permissions Required"]},{"url":"https://www.openwall.com/lists/oss-security/2013/11/18/4","source":"secalert@redhat.com","tags":["Mailing List","Patch","Third Party Advisory"]},{"url":"http://www.openwall.com/lists/oss-security/2013/11/15/4","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"]},{"url":"https://www.gitlab.com/2013/11/14/multiple-critical-vulnerabilities-in-gitlab/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]},{"url":"https://www.openwall.com/lists/oss-security/2013/11/18/4","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Patch","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2020-7979","sourceIdentifier":"cve@mitre.org","published":"2020-02-05T15:15:10.147","lastModified":"2026-06-17T03:25:43.893","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab EE 8.9 and later through 12.7.2 has Insecure Permission"},{"lang":"es","value":"GitLab EE versiones 8.9 y posteriores hasta 12.7.2, presenta Permisos No Seguros."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-276"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.9.0","versionEndExcluding":"12.5.9","matchCriteriaId":"F237A32A-1B5E-46A8-948D-5ED1E4424534"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.6.0","versionEndExcluding":"12.6.6","matchCriteriaId":"A7A1183B-BB42-4A60-BE8D-9869AF0E0E58"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.7.0","versionEndIncluding":"12.7.2","matchCriteriaId":"1E8A935F-8F5A-401E-B745-9CC2E382F003"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/01/30/security-release-gitlab-12-7-4-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/01/30/security-release-gitlab-12-7-4-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-8114","sourceIdentifier":"cve@mitre.org","published":"2020-02-05T15:15:10.207","lastModified":"2026-06-17T03:25:53.143","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab EE 8.9 and later through 12.7.2 has Insecure Permission"},{"lang":"es","value":"GitLab EE versiones 8.9 y posteriores hasta 12.7.2, presenta Permisos No Seguros."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-276"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.9.0","versionEndExcluding":"12.5.9","matchCriteriaId":"F237A32A-1B5E-46A8-948D-5ED1E4424534"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.6.0","versionEndExcluding":"12.6.6","matchCriteriaId":"A7A1183B-BB42-4A60-BE8D-9869AF0E0E58"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.7.0","versionEndIncluding":"12.7.2","matchCriteriaId":"1E8A935F-8F5A-401E-B745-9CC2E382F003"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2020/01/30/security-release-gitlab-12-7-4-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/issues/37468","source":"cve@mitre.org","tags":["Broken Link"]},{"url":"https://about.gitlab.com/releases/2020/01/30/security-release-gitlab-12-7-4-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/issues/37468","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2020-7966","sourceIdentifier":"cve@mitre.org","published":"2020-02-05T16:15:11.613","lastModified":"2026-06-17T03:25:42.693","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab EE 11.11 and later through 12.7.2 allows Directory Traversal."},{"lang":"es","value":"GitLab EE versiones 11.11 y posteriores hasta 12.7.2, permite un Salto de Directorio."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-22"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.11.0","versionEndExcluding":"12.5.9","matchCriteriaId":"500DE6D3-6415-4CFE-8A3F-60399C384F58"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.6.0","versionEndExcluding":"12.6.6","matchCriteriaId":"A7A1183B-BB42-4A60-BE8D-9869AF0E0E58"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.7.0","versionEndIncluding":"12.7.2","matchCriteriaId":"1E8A935F-8F5A-401E-B745-9CC2E382F003"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/01/30/security-release-gitlab-12-7-4-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/01/30/security-release-gitlab-12-7-4-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-7967","sourceIdentifier":"cve@mitre.org","published":"2020-02-05T16:15:11.707","lastModified":"2026-06-17T03:25:42.800","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab EE 8.0 through 12.7.2 has Insecure Permissions (issue 1 of 2)."},{"lang":"es","value":"GitLab EE versiones 8.0 hasta 12.7.2, presenta Permisos No Seguros (problema 1 de 2)."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-276"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.0.0","versionEndIncluding":"12.7.2","matchCriteriaId":"311216BB-4287-4370-85C0-9ED92B9E913F"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/01/30/security-release-gitlab-12-7-4-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/01/30/security-release-gitlab-12-7-4-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-7968","sourceIdentifier":"cve@mitre.org","published":"2020-02-05T16:15:11.787","lastModified":"2026-06-17T03:25:42.907","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab EE 8.0 through 12.7.2 has Incorrect Access Control."},{"lang":"es","value":"GitLab EE versiones 8.0 hasta 12.7.2, presenta un Control de Acceso Incorrecto."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"12.5.9","matchCriteriaId":"1018DA2C-38BF-4DA0-9212-E093781F7362"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"12.5.9","matchCriteriaId":"3B95AC9E-3E67-4692-B598-6D8773ECB350"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.6.0","versionEndExcluding":"12.6.6","matchCriteriaId":"59C090CD-F859-4008-8332-F516A3C0241C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.6.0","versionEndExcluding":"12.6.6","matchCriteriaId":"A7A1183B-BB42-4A60-BE8D-9869AF0E0E58"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.7.0","versionEndExcluding":"12.7.4","matchCriteriaId":"D937C9B4-F585-4EAE-8BAC-FAEC0DBD129D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.7.0","versionEndIncluding":"12.7.4","matchCriteriaId":"005E1D8E-E04B-457F-921E-D14612EEC52A"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/01/30/security-release-gitlab-12-7-4-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/01/30/security-release-gitlab-12-7-4-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-7969","sourceIdentifier":"cve@mitre.org","published":"2020-02-05T16:15:11.927","lastModified":"2026-06-17T03:25:43.013","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab EE 8.0 and later through 12.7.2 allows Information Disclosure."},{"lang":"es","value":"GitLab EE versiones 8.0 y posteriores hasta 12.7.2, permite una Divulgación de Información."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.0.0","versionEndExcluding":"12.5.9","matchCriteriaId":"54CCC5BE-C237-41F4-A7C8-EF741FC74A23"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.6.0","versionEndExcluding":"12.6.6","matchCriteriaId":"A7A1183B-BB42-4A60-BE8D-9869AF0E0E58"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.7.0","versionEndIncluding":"12.7.2","matchCriteriaId":"1E8A935F-8F5A-401E-B745-9CC2E382F003"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/01/30/security-release-gitlab-12-7-4-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/01/30/security-release-gitlab-12-7-4-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-7971","sourceIdentifier":"cve@mitre.org","published":"2020-02-05T16:15:12.097","lastModified":"2026-06-17T03:25:43.123","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab EE 11.0 and later through 12.7.2 allows XSS."},{"lang":"es","value":"GitLab EE versiones 11.0 y posteriores hasta 12.7.2, permite un ataque de tipo XSS."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"12.5.9","matchCriteriaId":"1EB7D3A3-376B-4EAB-8EAD-E6E79F4ADF40"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.6.0","versionEndExcluding":"12.6.6","matchCriteriaId":"A7A1183B-BB42-4A60-BE8D-9869AF0E0E58"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.7.0","versionEndIncluding":"12.7.2","matchCriteriaId":"1E8A935F-8F5A-401E-B745-9CC2E382F003"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/01/30/security-release-gitlab-12-7-4-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/01/30/security-release-gitlab-12-7-4-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-7972","sourceIdentifier":"cve@mitre.org","published":"2020-02-05T16:15:12.177","lastModified":"2026-06-17T03:25:43.230","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab EE 12.2 has Insecure Permissions (issue 2 of 2)."},{"lang":"es","value":"GitLab EE versión 12.2, presenta Permisos No Seguros (problema 2 de 2)."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-276"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.0","versionEndExcluding":"12.5.9","matchCriteriaId":"367AC35D-F3DE-4F1D-A7F8-53D1E8E63FCA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.6.0","versionEndExcluding":"12.6.6","matchCriteriaId":"A7A1183B-BB42-4A60-BE8D-9869AF0E0E58"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.7.0","versionEndExcluding":"12.7.4","matchCriteriaId":"D7CD9828-96CA-496F-82AB-1EB0024C5CE4"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/01/30/security-release-gitlab-12-7-4-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/01/30/security-release-gitlab-12-7-4-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-7973","sourceIdentifier":"cve@mitre.org","published":"2020-02-05T16:15:12.223","lastModified":"2026-06-17T03:25:43.343","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab through 12.7.2 allows XSS."},{"lang":"es","value":"GitLab versiones hasta 12.7.2, permite un ataque de tipo XSS."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"12.5.9","matchCriteriaId":"1018DA2C-38BF-4DA0-9212-E093781F7362"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"12.5.9","matchCriteriaId":"3B95AC9E-3E67-4692-B598-6D8773ECB350"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.6.0","versionEndExcluding":"12.6.6","matchCriteriaId":"59C090CD-F859-4008-8332-F516A3C0241C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.6.0","versionEndExcluding":"12.6.6","matchCriteriaId":"A7A1183B-BB42-4A60-BE8D-9869AF0E0E58"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.7.0","versionEndIncluding":"12.7.2","matchCriteriaId":"E4FECC43-C076-4307-9A12-DC80D29E3CDE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.7.0","versionEndIncluding":"12.7.2","matchCriteriaId":"1E8A935F-8F5A-401E-B745-9CC2E382F003"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/01/30/security-release-gitlab-12-7-4-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/security/gitlab/issues/14","source":"cve@mitre.org","tags":["Permissions Required","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/01/30/security-release-gitlab-12-7-4-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/security/gitlab/issues/14","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-7974","sourceIdentifier":"cve@mitre.org","published":"2020-02-05T16:15:12.300","lastModified":"2026-06-17T03:25:43.450","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab EE 10.1 through 12.7.2 allows Information Disclosure."},{"lang":"es","value":"GitLab EE versiones 10.1 hasta 12.7.2, permite una Divulgación de Información."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.1.0","versionEndExcluding":"12.5.9","matchCriteriaId":"AA94B868-06C8-4EC6-A237-2A97A0BFFE62"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.6.0","versionEndExcluding":"12.6.6","matchCriteriaId":"A7A1183B-BB42-4A60-BE8D-9869AF0E0E58"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.7.0","versionEndIncluding":"12.7.2","matchCriteriaId":"1E8A935F-8F5A-401E-B745-9CC2E382F003"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/01/30/security-release-gitlab-12-7-4-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/01/30/security-release-gitlab-12-7-4-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-7976","sourceIdentifier":"cve@mitre.org","published":"2020-02-05T16:15:12.363","lastModified":"2026-06-17T03:25:43.580","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab EE 12.4 and later through 12.7.2 has Incorrect Access Control."},{"lang":"es","value":"GitLab EE versiones 12.4 y posteriores hasta 12.7.2, presenta un Control de Acceso Incorrecto."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.4.0","versionEndExcluding":"12.5.9","matchCriteriaId":"4E3F25B4-BE46-4B84-92A6-F9E386015673"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.6.0","versionEndExcluding":"12.6.6","matchCriteriaId":"A7A1183B-BB42-4A60-BE8D-9869AF0E0E58"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.7.0","versionEndIncluding":"12.7.2","matchCriteriaId":"1E8A935F-8F5A-401E-B745-9CC2E382F003"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/01/30/security-release-gitlab-12-7-4-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/01/30/security-release-gitlab-12-7-4-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-7977","sourceIdentifier":"cve@mitre.org","published":"2020-02-05T16:15:12.443","lastModified":"2026-06-17T03:25:43.683","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab EE 8.8 and later through 12.7.2 has Insecure Permissions."},{"lang":"es","value":"GitLab EE versiones 8.8 y posteriores hasta 12.7.2, presenta Permisos No Seguros."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-276"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.8.0","versionEndExcluding":"12.5.9","matchCriteriaId":"689ADF3A-67CF-4C91-81E8-644B64FD3781"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.6.0","versionEndExcluding":"12.6.6","matchCriteriaId":"A7A1183B-BB42-4A60-BE8D-9869AF0E0E58"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.7.0","versionEndIncluding":"12.7.2","matchCriteriaId":"1E8A935F-8F5A-401E-B745-9CC2E382F003"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/01/30/security-release-gitlab-12-7-4-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/01/30/security-release-gitlab-12-7-4-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-7978","sourceIdentifier":"cve@mitre.org","published":"2020-02-05T16:15:12.507","lastModified":"2026-06-17T03:25:43.790","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab EE 12.6 and later through 12.7.2 allows Denial of Service."},{"lang":"es","value":"GitLab EE versiones 12.6 y posteriores hasta 12.7.2, permiten una Denegación de Servicio."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.6.0","versionEndExcluding":"12.6.6","matchCriteriaId":"A7A1183B-BB42-4A60-BE8D-9869AF0E0E58"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.7.0","versionEndIncluding":"12.7.2","matchCriteriaId":"1E8A935F-8F5A-401E-B745-9CC2E382F003"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/01/30/security-release-gitlab-12-7-4-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/01/30/security-release-gitlab-12-7-4-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-6833","sourceIdentifier":"cve@mitre.org","published":"2020-02-05T17:15:10.597","lastModified":"2026-06-17T03:23:53.423","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab EE 11.3 and later. A GitLab Workhorse bypass could lead to package and file disclosure via request smuggling."},{"lang":"es","value":"Se detectó un problema en GitLab EE versiones 11.3 y posteriores. Una omisión de GitLab Workhorse podría conllevar a una divulgación de paquetes y archivos mediante el tráfico no autorizado de peticiones."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"12.5.9","matchCriteriaId":"B8588B9C-3FC6-43C6-ABA0-B30039CF4F4E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.6.0","versionEndExcluding":"12.6.6","matchCriteriaId":"A7A1183B-BB42-4A60-BE8D-9869AF0E0E58"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.7.2","versionEndExcluding":"12.7.4","matchCriteriaId":"BD1DFD56-D36D-4221-A516-590B619D2663"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/01/30/security-release-gitlab-12-7-4-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/01/30/security-release-gitlab-12-7-4-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-15592","sourceIdentifier":"support@hackerone.com","published":"2020-02-14T22:15:10.360","lastModified":"2026-06-17T02:20:42.387","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab 12.2.2 and below contains a security vulnerability that allows a guest user in a private project to see the merge request ID associated to an issue via the activity timeline."},{"lang":"es","value":"GitLab versiones 12.2.2 y por debajo, contienen una vulnerabilidad de seguridad que permite a un usuario invitado en un proyecto privado visualizar el ID de la petición de combinación asociada a un problema por medio de la línea de tiempo de la actividad."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"n/a","product":"GitLab","versions":[{"version":"12.2.3","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"support@hackerone.com","type":"Secondary","description":[{"lang":"en","value":"CWE-200"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.2.0","versionEndExcluding":"12.0.8","matchCriteriaId":"C0D64621-2E24-4698-B116-0FCC6EE6D30F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.2.0","versionEndExcluding":"12.0.8","matchCriteriaId":"5AC10563-1F00-4CAB-94E0-8464E5DBA517"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.8","matchCriteriaId":"BE0BA50B-833E-4F74-95CB-EC8963B0ABCA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.8","matchCriteriaId":"36F29405-3C84-4ECF-96B7-E25D88926B46"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.3","matchCriteriaId":"16FD6BD6-8B76-4053-81C1-E9B00F279113"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.2.3","matchCriteriaId":"F131A404-4B2B-4F77-981B-A12D8FC7F590"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2019/08/29/security-release-gitlab-12-dot-2-dot-3-released/","source":"support@hackerone.com","tags":["Vendor Advisory"]},{"url":"https://hackerone.com/reports/588876","source":"support@hackerone.com","tags":["Permissions Required"]},{"url":"https://about.gitlab.com/releases/2019/08/29/security-release-gitlab-12-dot-2-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://hackerone.com/reports/588876","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2019-15594","sourceIdentifier":"support@hackerone.com","published":"2020-02-14T22:15:10.437","lastModified":"2026-06-17T02:20:42.620","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab 11.8 and later contains a security vulnerability that allows a user to obtain details of restricted pipelines via the merge request endpoint."},{"lang":"es","value":"GitLab versiones 11.8 y posteriores, contiene una vulnerabilidad de seguridad que permite a un usuario obtener detalles de las tuberías restringidas por medio del endpoint de petición de combinación."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"n/a","product":"GitLab","versions":[{"version":"12.1.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"support@hackerone.com","type":"Secondary","description":[{"lang":"en","value":"CWE-200"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndIncluding":"11.8","matchCriteriaId":"E69C80D9-A568-4E3E-99BF-A760237EF58B"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2019/07/29/security-release-gitlab-12-dot-1-dot-2-released/","source":"support@hackerone.com","tags":["Vendor Advisory"]},{"url":"https://hackerone.com/reports/507064","source":"support@hackerone.com","tags":["Permissions Required"]},{"url":"https://about.gitlab.com/releases/2019/07/29/security-release-gitlab-12-dot-1-dot-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://hackerone.com/reports/507064","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2019-12825","sourceIdentifier":"cve@mitre.org","published":"2020-02-17T14:15:11.810","lastModified":"2026-06-17T02:15:33.977","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Unauthorized Access to the Container Registry of other groups was discovered in GitLab Enterprise 12.0.0-pre. In other words, authenticated remote attackers can read Docker registries of other groups. When a legitimate user changes the path of a group, Docker registries are not adapted, leaving them in the old namespace. They are not protected and are available to all other users with no previous access to the repo."},{"lang":"es","value":"Se detectó un Acceso no Autorizado en Container Registry de otros grupos en GitLab Enterprise versión 12.0.0-pre. En otras palabras, atacantes remotos autenticados pueden leer registros Docker de otros grupos. Cuando un usuario legítimo cambia la ruta de un grupo, los registros Docker no son adaptados, dejándolos en el antiguo espacio de nombres. No están protegidos y están disponibles para todos los demás usuarios sin acceso previo al repo."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-922"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.0.1","versionEndExcluding":"12.5.0","matchCriteriaId":"A9689B8A-119E-467A-8E84-C4F7A5F0EB25"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:12.0.0:-:*:*:enterprise:*:*:*","matchCriteriaId":"343E77D4-D306-47B4-BFF2-E8393CDA47CD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:12.0.0:pre:*:*:enterprise:*:*:*","matchCriteriaId":"373F749E-769B-49D9-83F8-59BBED86D8D5"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://atomic111.github.io/article/gitlab-Unauthorized-Access-to-Container-Registry","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://atomic111.github.io/article/gitlab-Unauthorized-Access-to-Container-Registry","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2020-8795","sourceIdentifier":"cve@mitre.org","published":"2020-02-17T15:15:11.963","lastModified":"2026-06-17T03:26:57.480","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In GitLab Enterprise Edition (EE) 12.5.0 through 12.7.5, sharing a group with a group could grant project access to unauthorized users."},{"lang":"es","value":"En GitLab Enterprise Edition (EE) versiones 12.5.0 hasta 12.7.5, compartir un grupo con un grupo podría otorgar acceso al proyecto a usuarios no autorizados."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.5.0","versionEndIncluding":"12.7.5","matchCriteriaId":"3D7144BF-8738-46C3-B522-33CF1AB15D6A"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2020/02/13/critical-security-release-gitlab-12-dot-7-dot-6-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/02/13/critical-security-release-gitlab-12-dot-7-dot-6-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-8113","sourceIdentifier":"cve@mitre.org","published":"2020-03-06T18:15:11.757","lastModified":"2026-06-17T03:25:53.033","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab 10.7 and later through 12.7.2 has Incorrect Access Control."},{"lang":"es","value":"GitLab versiones 10.7 hasta 12.7.2, presenta un Control de Acceso Incorrecto."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-269"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.7.0","versionEndExcluding":"12.6.8","matchCriteriaId":"5CDA57FD-EE93-45EF-A4FC-36BDDD630576"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.7.0","versionEndExcluding":"12.6.8","matchCriteriaId":"71648D2B-02E8-4B22-9CD8-BFC446D1CF0A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.7.0","versionEndIncluding":"12.7.2","matchCriteriaId":"E4FECC43-C076-4307-9A12-DC80D29E3CDE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.7.0","versionEndIncluding":"12.7.2","matchCriteriaId":"1E8A935F-8F5A-401E-B745-9CC2E382F003"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/categories/releases/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/issues/31599","source":"cve@mitre.org","tags":["Broken Link"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/issues/31599","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2019-12428","sourceIdentifier":"cve@mitre.org","published":"2020-03-10T14:15:11.503","lastModified":"2026-06-17T02:14:38.237","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 6.8 through 11.11. Users could bypass the mandatory external authentication provider sign-in restrictions by sending a specially crafted request. It has Improper Authorization."},{"lang":"es","value":"Se detectó un problema en GitLab Community and Enterprise Edition versiones 6.8 hasta 11.11. Tiene una Autorización Inapropiada."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"6.8.0","versionEndIncluding":"11.11.0","matchCriteriaId":"73A5C34C-69FB-4299-B8D5-71C3563CEF1C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"6.8.0","versionEndIncluding":"11.11.0","matchCriteriaId":"CF909B05-5FF3-4263-B78A-7D5373B67177"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2019/06/03/security-release-gitlab-11-dot-11-dot-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2019/06/03/security-release-gitlab-11-dot-11-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-12429","sourceIdentifier":"cve@mitre.org","published":"2020-03-10T14:15:11.567","lastModified":"2026-06-17T02:14:38.430","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 11.9 through 11.11. Unprivileged users were able to access labels, status and merge request counts of confidential issues via the milestone details page. It has Improper Access Control."},{"lang":"es","value":"Se detectó un problema en GitLab Community and Enterprise Edition versiones 11.9 hasta 11.11. Tiene un Control de Acceso Inapropiado."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.9.0","versionEndIncluding":"11.11.0","matchCriteriaId":"34BD22A7-B958-4678-A17D-E9E0546089C2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.9.0","versionEndIncluding":"11.11.0","matchCriteriaId":"70808629-1611-4E26-B708-DF1A5ECAA635"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2019/06/03/security-release-gitlab-11-dot-11-dot-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2019/06/03/security-release-gitlab-11-dot-11-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-12430","sourceIdentifier":"cve@mitre.org","published":"2020-03-10T14:15:11.660","lastModified":"2026-06-17T02:14:38.613","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 11.11. A specially crafted payload would allow an authenticated malicious user to execute commands remotely through the repository download feature. It allows Command Injection."},{"lang":"es","value":"Se detectó un problema en GitLab Community and Enterprise Edition versión 11.11. Permite una Inyección de Comandos."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-77"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.11.0:*:*:*:community:*:*:*","matchCriteriaId":"2978DE93-5543-4893-A944-19B97FCCF9D8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.11.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"8B22A15E-7C79-4811-B300-8E8DDA092766"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2019/06/03/security-release-gitlab-11-dot-11-dot-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2019/06/03/security-release-gitlab-11-dot-11-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-12431","sourceIdentifier":"cve@mitre.org","published":"2020-03-10T14:15:11.753","lastModified":"2026-06-17T02:14:38.740","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 8.13 through 11.11. Restricted users could access the metadata of private milestones through the Search API. It has Improper Access Control."},{"lang":"es","value":"Se ha detectado  un problema en GitLab Community and Enterprise Edition versiones 8.13 hasta 11.11. Tiene un Control de Acceso Inapropiado."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.13.0","versionEndIncluding":"11.11.0","matchCriteriaId":"61D08DBF-E4D2-453C-8295-46A7375E03FE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.13.0","versionEndIncluding":"11.11.0","matchCriteriaId":"66FEEC02-9250-46C8-B48D-912E7F2B9CC0"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2019/06/03/security-release-gitlab-11-dot-11-dot-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2019/06/03/security-release-gitlab-11-dot-11-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-12432","sourceIdentifier":"cve@mitre.org","published":"2020-03-10T14:15:11.817","lastModified":"2026-06-17T02:14:38.860","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 8.13 through 11.11. Non-member users who subscribed to issue notifications could access the title of confidential issues through the unsubscription page. It allows Information Disclosure."},{"lang":"es","value":"Se detectó un problema en GitLab Community and Enterprise Edition versiones 8.13 hasta 11.11. Permite una Divulgación de Información."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-200"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.13.0","versionEndIncluding":"11.11.0","matchCriteriaId":"61D08DBF-E4D2-453C-8295-46A7375E03FE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.13.0","versionEndIncluding":"11.11.0","matchCriteriaId":"66FEEC02-9250-46C8-B48D-912E7F2B9CC0"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2019/06/03/security-release-gitlab-11-dot-11-dot-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2019/06/03/security-release-gitlab-11-dot-11-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-12433","sourceIdentifier":"cve@mitre.org","published":"2020-03-10T14:15:11.897","lastModified":"2026-06-17T02:14:38.983","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 11.7 through 11.11. It has Improper Input Validation. Restricted visibility settings allow creating internal projects in private groups, leading to multiple permission issues."},{"lang":"es","value":"Se detectó un problema en GitLab Community and Enterprise Edition versiones 11.7 hasta 11.11. Tiene una Comprobación de Entrada Inapropiada. La configuración de visibilidad restringida permite una creación de proyectos internos en grupos privados, conllevando a múltiples problemas de permisos."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-20"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.7.0","versionEndIncluding":"11.11.0","matchCriteriaId":"5A179FB4-C52E-433E-A5E6-15021CF65932"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.7.0","versionEndIncluding":"11.11.0","matchCriteriaId":"884AED11-2D89-4F70-90EF-600C10DAD7C1"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2019/06/03/security-release-gitlab-11-dot-11-dot-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2019/06/03/security-release-gitlab-11-dot-11-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-12434","sourceIdentifier":"cve@mitre.org","published":"2020-03-10T14:15:11.957","lastModified":"2026-06-17T02:14:39.107","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 10.6 through 11.11. Users could guess the URL slug of private projects through the contrast of the destination URLs of issues linked in comments. It allows Information Disclosure."},{"lang":"es","value":"Se detectó un problema en GitLab Community and Enterprise Edition versiones 10.6 hasta 11.11. Unos usuarios podían adivinar el URL slug de proyectos privados por medio del contraste de las URL de destino de los temas vinculados en los comentarios. Permite una Divulgación de Información."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-330"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.6.0","versionEndIncluding":"11.11.0","matchCriteriaId":"CEFC11B2-B54A-4BC9-997C-8365C8AC923F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.6.0","versionEndIncluding":"11.11.0","matchCriteriaId":"FA00A2BC-0A44-4898-9071-F0442352C38C"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2019/06/03/security-release-gitlab-11-dot-11-dot-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2019/06/03/security-release-gitlab-11-dot-11-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-12441","sourceIdentifier":"cve@mitre.org","published":"2020-03-10T15:15:14.353","lastModified":"2026-06-17T02:14:39.903","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 8.4 through 11.11. The protected branches feature contained a access control issue which resulted in a bypass of the protected branches restriction rules. It has Incorrect Access Control."},{"lang":"es","value":"Se detectó un problema en GitLab Community and Enterprise Edition versiones 8.4 hasta 11.11. La funcionalidad de sucursales protegidas contenían un problema de control de acceso que resultó en la omisión de las reglas de restricción de sucursales protegidas. Tiene un Control de Acceso Incorrecto."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-732"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.4.0","versionEndIncluding":"11.11.0","matchCriteriaId":"E4867E11-A8FD-4CA1-9900-CEFFE0D0B31D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.4.0","versionEndIncluding":"11.11.0","matchCriteriaId":"DF5B045E-DFCE-45C9-BF4E-5E55B7705B14"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2019/06/03/security-release-gitlab-11-dot-11-dot-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2019/06/03/security-release-gitlab-11-dot-11-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-12442","sourceIdentifier":"cve@mitre.org","published":"2020-03-10T15:15:14.637","lastModified":"2026-06-17T02:14:40.027","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Enterprise Edition 11.7 through 11.11. The epic details page contained a lack of input validation and output encoding issue which resulted in a persistent XSS vulnerability on child epics."},{"lang":"es","value":"Se detectó un problema en GitLab Enterprise Edition versiones  11.7 hasta 11.11. La página epic details contenía una falta de comprobación de entrada y un problema de codificación de salida que resultó en una vulnerabilidad de tipo XSS persistente sobre child epics."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.7.0","versionEndIncluding":"11.11.0","matchCriteriaId":"5A179FB4-C52E-433E-A5E6-15021CF65932"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.7.0","versionEndIncluding":"11.11.0","matchCriteriaId":"884AED11-2D89-4F70-90EF-600C10DAD7C1"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2019/06/03/security-release-gitlab-11-dot-11-dot-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2019/06/03/security-release-gitlab-11-dot-11-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-12443","sourceIdentifier":"cve@mitre.org","published":"2020-03-10T15:15:14.870","lastModified":"2026-06-17T02:14:40.147","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 10.2 through 11.11. Multiple features contained Server-Side Request Forgery (SSRF) vulnerabilities caused by an insufficient validation to prevent DNS rebinding attacks."},{"lang":"es","value":"Se detectó un problema en GitLab Community and Enterprise Edition versiones 10.2 hasta 11.11. Múltiples funcionalidades contenían vulnerabilidades de tipo Server-Side Request Forgery (SSRF) causadas por una comprobación insuficiente para impedir ataques de tipo DNS rebinding."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.9.0","versionEndIncluding":"11.11.0","matchCriteriaId":"34BD22A7-B958-4678-A17D-E9E0546089C2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.9.0","versionEndIncluding":"11.11.0","matchCriteriaId":"70808629-1611-4E26-B708-DF1A5ECAA635"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2019/06/03/security-release-gitlab-11-dot-11-dot-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2019/06/03/security-release-gitlab-11-dot-11-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-12444","sourceIdentifier":"cve@mitre.org","published":"2020-03-10T15:15:15.010","lastModified":"2026-06-17T02:14:40.270","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 8.9 through 11.11. Wiki Pages contained a lack of input validation which resulted in a persistent XSS vulnerability."},{"lang":"es","value":"Se ha detectado un problema en GitLab Community and Enterprise Edition versiones 8.9 hasta 11.11. Unas Páginas Wiki contenían una falta de comprobación de entrada que resultó en una vulnerabilidad de tipo XSS  persistente."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.9.0","versionEndIncluding":"11.11.0","matchCriteriaId":"AB6722BA-84FF-44A4-9498-F0B44A8DFCF3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.9.0","versionEndIncluding":"11.11.0","matchCriteriaId":"70C7344F-239D-45B7-8FBB-C2BACA9F999A"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2019/06/03/security-release-gitlab-11-dot-11-dot-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2019/06/03/security-release-gitlab-11-dot-11-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-12445","sourceIdentifier":"cve@mitre.org","published":"2020-03-10T15:15:15.307","lastModified":"2026-06-17T02:14:40.407","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 8.4 through 11.11. A malicious user could execute JavaScript code on notes by importing a specially crafted project file. It allows XSS."},{"lang":"es","value":"Se detectó un problema en GitLab Community and Enterprise Edition versiones 8.4 hasta 11.11. Un usuario malicioso podría ejecutar código JavaScript en unas notas al importar un archivo de proyecto especialmente diseñado. Permite un ataque de tipo XSS."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.4.0","versionEndIncluding":"11.11.0","matchCriteriaId":"E4867E11-A8FD-4CA1-9900-CEFFE0D0B31D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.4.0","versionEndIncluding":"11.11.0","matchCriteriaId":"DF5B045E-DFCE-45C9-BF4E-5E55B7705B14"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2019/06/03/security-release-gitlab-11-dot-11-dot-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2019/06/03/security-release-gitlab-11-dot-11-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-12446","sourceIdentifier":"cve@mitre.org","published":"2020-03-10T15:15:15.480","lastModified":"2026-06-17T02:14:40.530","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 8.3 through 11.11. It allows Information Exposure through an Error Message."},{"lang":"es","value":"Se detectó un problema en GitLab Community and Enterprise Edition versiones  8.3 hasta 11.11. Permite una Exposición de la Información por medio de un Mensaje de Error."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-209"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.3.0","versionEndIncluding":"11.11.0","matchCriteriaId":"3029AF1A-A7DC-4B54-9E7D-45968E67B2D6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.3.0","versionEndIncluding":"11.11.0","matchCriteriaId":"9E3CFC84-8F3B-49D5-A4E2-32AF7FF39228"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2019/06/03/security-release-gitlab-11-dot-11-dot-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2019/06/03/security-release-gitlab-11-dot-11-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-13001","sourceIdentifier":"cve@mitre.org","published":"2020-03-10T15:15:15.557","lastModified":"2026-06-17T02:15:53.790","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 11.9 and later through 12.0.2. GitLab Snippets were vulnerable to an authorization issue that allowed unauthorized users to add comments to a private snippet. It allows authentication bypass."},{"lang":"es","value":"Se detectó un problema en GitLab Community and Enterprise Edition versiones 11.9 y posteriores hasta 12.0.2. GitLab Snippets eran vulnerables a un problema de autorización que permitía a usuarios no autorizados agregar comentarios a un fragmento privado. Permite una omisión de autenticación."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.9.0","versionEndIncluding":"12.0.2","matchCriteriaId":"E844FE2B-6076-44E7-94F4-159B965A9374"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.9.0","versionEndIncluding":"12.0.2","matchCriteriaId":"4D375233-7AF3-4074-B5F8-33D742195E2E"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2019/07/03/security-release-gitlab-12-dot-0-dot-3-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2019/07/03/security-release-gitlab-12-dot-0-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-13002","sourceIdentifier":"cve@mitre.org","published":"2020-03-10T15:15:15.667","lastModified":"2026-06-17T02:15:53.930","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 11.10 through 12.0.2. Unauthorized users were able to read pipeline information of the last merge request. It has Incorrect Access Control."},{"lang":"es","value":"Se detectó un problema en GitLab Community and Enterprise Edition versiones 11.10 hasta 12.0.2. Usuarios no autorizados fueron capaces de leer información de la tubería de la última petición de fusión. Tiene un Control de Acceso Incorrecto."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.10.0","versionEndIncluding":"12.0.2","matchCriteriaId":"7FBD6615-1E4F-4E68-99B0-0075404FC1FD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.10.0","versionEndIncluding":"12.0.2","matchCriteriaId":"A45D79D8-143C-4075-9214-E6620747815D"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2019/07/03/security-release-gitlab-12-dot-0-dot-3-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2019/07/03/security-release-gitlab-12-dot-0-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-13003","sourceIdentifier":"cve@mitre.org","published":"2020-03-10T15:15:15.730","lastModified":"2026-06-17T02:15:54.070","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 12.0.3. One of the parsers used by Gilab CI was vulnerable to a resource exhaustion attack. It allows Uncontrolled Resource Consumption."},{"lang":"es","value":"Se detectó un problema en GitLab Community and Enterprise Edition versiones anteriores a la versión  12.0.3. Uno de los analizadores usados por Gilab CI era vulnerable a un ataque de agotamiento de recursos. Permite un Consumo de Recursos No Controlado."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-400"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"12.0.3","matchCriteriaId":"0905D3B6-C09B-4CB2-9FE5-EE209D6E9755"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"12.0.3","matchCriteriaId":"72C46840-4DD5-43F5-A783-588A5A8EEB00"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2019/07/03/security-release-gitlab-12-dot-0-dot-3-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2019/07/03/security-release-gitlab-12-dot-0-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-13004","sourceIdentifier":"cve@mitre.org","published":"2020-03-10T15:15:15.853","lastModified":"2026-06-17T02:15:54.203","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 11.10 through 12.0.2. When specific encoded characters were added to comments, the comments section would become inaccessible. It has Incorrect Access Control (issue 1 of 2)."},{"lang":"es","value":"Se detectó un problema en GitLab Community and Enterprise Edition versiones 11.10 hasta 12.0.2. Cuando fueron agregados caracteres codificados específicos a los comentarios, la sección de comentarios se volvería inaccesible. tiene un Control de Acceso Incorrecto (problema 1 de 2)."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.10.0","versionEndIncluding":"12.0.2","matchCriteriaId":"7FBD6615-1E4F-4E68-99B0-0075404FC1FD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.10.0","versionEndIncluding":"12.0.2","matchCriteriaId":"A45D79D8-143C-4075-9214-E6620747815D"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2019/07/03/security-release-gitlab-12-dot-0-dot-3-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2019/07/03/security-release-gitlab-12-dot-0-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-13005","sourceIdentifier":"cve@mitre.org","published":"2020-03-10T15:15:15.917","lastModified":"2026-06-17T02:15:54.343","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Enterprise Edition and Community Edition 1.10 through 12.0.2. The GitLab graphql service was vulnerable to multiple authorization issues that disclosed restricted user, group, and repository metadata to unauthorized users. It has Incorrect Access Control."},{"lang":"es","value":"Se detectó un problema en GitLab Enterprise Edition and Community Edition versiones 1.10 hasta 12.0.2. El servicio graphql de GitLab era vulnerable a múltiples problemas de autorización que revelaban metadatos restringidos de usuarios, grupos y repositorios a usuarios no autorizados. tienen un Control de Acceso Incorrecto."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.10.0","versionEndIncluding":"12.0.2","matchCriteriaId":"7FBD6615-1E4F-4E68-99B0-0075404FC1FD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.10.0","versionEndIncluding":"12.0.2","matchCriteriaId":"A45D79D8-143C-4075-9214-E6620747815D"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2019/07/03/security-release-gitlab-12-dot-0-dot-3-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2019/07/03/security-release-gitlab-12-dot-0-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-13006","sourceIdentifier":"cve@mitre.org","published":"2020-03-10T17:15:12.783","lastModified":"2026-06-17T02:15:54.480","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 9.0 and through 12.0.2. Users with access to issues, but not the repository were able to view the number of related merge requests on an issue. It has Incorrect Access Control."},{"lang":"es","value":"Se detectó un problema en GitLab Community and Enterprise Edition versiones 9.0  hasta 12.0.2. Los usuarios con acceso a problemas, pero no el repositorio pudieron visualizar la cantidad de peticiones de fusión relacionadas en un problema. Tienen un Control de Acceso Incorrecto."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"9.0.0","versionEndIncluding":"12.0.2","matchCriteriaId":"C60ED70B-EEBF-40E7-B8AB-2230EF47692B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"9.0.0","versionEndIncluding":"12.0.2","matchCriteriaId":"4BA84245-650C-4421-B7F2-4994EDE98286"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2019/07/03/security-release-gitlab-12-dot-0-dot-3-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2019/07/03/security-release-gitlab-12-dot-0-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-13007","sourceIdentifier":"cve@mitre.org","published":"2020-03-10T18:15:11.263","lastModified":"2026-06-17T02:15:54.613","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 11.11 through 12.0.2. When an admin enabled one of the service templates, it was triggering an action that leads to resource depletion. It allows Uncontrolled Resource Consumption."},{"lang":"es","value":"Se detectó un problema en GitLab Community and Enterprise Edition versiones 11.11 hasta la versión  12.0.2. Cuando un administrador habilitó una de las plantillas de servicio, estaba activando una acción que conlleva al agotamiento de los recursos. Permite un Consumo de Recursos No Controlado."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":1.2,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:N/A:P","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-400"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.11","versionEndIncluding":"12.0.2","matchCriteriaId":"2CC739EC-7561-4CA7-9A76-618A7E7808FB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.11","versionEndIncluding":"12.0.2","matchCriteriaId":"1E955270-CC5C-431E-A0EC-EFF9E742731D"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2019/07/03/security-release-gitlab-12-dot-0-dot-3-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2019/07/03/security-release-gitlab-12-dot-0-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-13009","sourceIdentifier":"cve@mitre.org","published":"2020-03-10T18:15:11.343","lastModified":"2026-06-17T02:15:54.757","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition 9.2 through 12.0.2. Uploaded files associated with unsaved personal snippets were accessible to unauthorized users due to improper permission settings. It has Incorrect Access Control."},{"lang":"es","value":"Se descubrió un problema en GitLab Community and Enterprise Edition 9.2 a 12.0.2. Los archivos cargados asociados con fragmentos personales no guardados eran accesibles para usuarios no autorizados debido a la configuración incorrecta de permisos. Tiene control de acceso incorrecto."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:N/A:P","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-400"},{"lang":"en","value":"CWE-732"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"9.2.0","versionEndIncluding":"12.0.2","matchCriteriaId":"1553E2A5-4D0B-4C72-AD55-C7A57DB7AA3A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"9.2.0","versionEndIncluding":"12.0.2","matchCriteriaId":"EA45FCB1-3E56-47C8-95B1-45E333DBBB98"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2019/07/03/security-release-gitlab-12-dot-0-dot-3-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2019/07/03/security-release-gitlab-12-dot-0-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-13010","sourceIdentifier":"cve@mitre.org","published":"2020-03-10T18:15:11.437","lastModified":"2026-06-17T02:15:54.900","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Enterprise Edition 8.3 through 12.0.2. The color codes decoder was vulnerable to a resource depletion attack if specific formats were used. It allows Uncontrolled Resource Consumption."},{"lang":"es","value":"Se descubrió un problema en GitLab Enterprise Edition 8.3 a 12.0.2. El decodificador de códigos de color era vulnerable a un ataque de agotamiento de recursos si se usaban formatos específicos. Permite el consumo incontrolado de recursos."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.2,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:N/A:P","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.3.0","versionEndIncluding":"12.0.2","matchCriteriaId":"935FCD98-8FDE-4464-9574-532B9729A7EB"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2019/07/03/security-release-gitlab-12-dot-0-dot-3-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2019/07/03/security-release-gitlab-12-dot-0-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-13011","sourceIdentifier":"cve@mitre.org","published":"2020-03-10T18:15:11.547","lastModified":"2026-06-17T02:15:55.033","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Enterprise Edition 8.11.0 through 12.0.2. By using brute-force a user with access to a project, but not it's repository could create a list of merge requests template names. It has excessive algorithmic complexity."},{"lang":"es","value":"Se detectó un problema en GitLab Enterprise Edition versiones 8.11.0 hasta la versión   12.0.2. Mediante el uso de fuerza bruta, un usuario con acceso a un proyecto, pero no a su repositorio, podría crear una lista de nombres de plantillas de peticiones de fusión. Presenta un complejidad algorítmica excesiva."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-400"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.11.0","versionEndIncluding":"12.0.2","matchCriteriaId":"1723F70C-DE12-4C39-BE96-7A9E31E9438C"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2019/07/03/security-release-gitlab-12-dot-0-dot-3-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2019/07/03/security-release-gitlab-12-dot-0-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-13121","sourceIdentifier":"cve@mitre.org","published":"2020-03-10T18:15:11.623","lastModified":"2026-06-17T02:16:06.697","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Enterprise Edition 10.6 through 12.0.2. The GitHub project integration was vulnerable to an SSRF vulnerability which allowed an attacker to make requests to local network resources. It has Incorrect Access Control."},{"lang":"es","value":"Se detectó un problema en GitLab Enterprise Edition versiones 10.6 hasta la versión  12.0.2. La integración del proyecto de GitHub era vulnerable a una vulnerabilidad de tipo SSRF que permitía a un atacante realizar peticiones a recursos de red local. Presenta un Control de Acceso Incorrecto."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.6.0","versionEndIncluding":"12.0.2","matchCriteriaId":"A953B9BF-CA2B-4804-A33E-FA75986AA529"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2019/07/03/security-release-gitlab-12-dot-0-dot-3-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2019/07/03/security-release-gitlab-12-dot-0-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-10535","sourceIdentifier":"cve@mitre.org","published":"2020-03-12T23:15:12.313","lastModified":"2026-06-17T02:47:58.013","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab 12.8.x before 12.8.6, when sign-up is enabled, allows remote attackers to bypass email domain restrictions within the two-day grace period for an unconfirmed email address."},{"lang":"es","value":"GitLab versiones 12.8.x anteriores a la versión 12.8.6, cuando el registro está habilitado, permite a atacantes remotos omitir las restricciones del dominio de correo electrónico dentro del período de gracia de dos días para una dirección de correo electrónico no confirmada."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.8.0","versionEndExcluding":"12.8.6","matchCriteriaId":"F3572ABC-3320-4849-8B4A-26788F12A0FD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.8.0","versionEndExcluding":"12.8.6","matchCriteriaId":"244EFF68-602B-4E95-AD8C-7F1BC7C9CDBD"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2020/03/11/critical-security-release-gitlab-12-dot-8-dot-6-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/11/critical-security-release-gitlab-12-dot-8-dot-6-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-10078","sourceIdentifier":"cve@mitre.org","published":"2020-03-13T17:15:11.703","lastModified":"2026-06-17T02:47:18.760","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab 12.1 through 12.8.1 allows XSS. The merge request submission form was determined to have a stored cross-site scripting vulnerability."},{"lang":"es","value":"GitLab versiones 12.1 hasta 12.8.1, permite un ataque de tipo XSS. Se determinó que el formulario de solicitud de una petición de fusión presenta una vulnerabilidad de tipo cross-site scripting almacenado."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.1.0","versionEndIncluding":"12.8.1","matchCriteriaId":"87B8AD6C-FFEC-4026-A6AA-DAB724A502B6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.1.0","versionEndIncluding":"12.8.1","matchCriteriaId":"8EA3C0C6-74B3-4E71-B9B0-34ED15888BEF"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/index.html","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/index.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-10079","sourceIdentifier":"cve@mitre.org","published":"2020-03-13T17:15:11.797","lastModified":"2026-06-17T02:47:18.867","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab 7.10 through 12.8.1 has Incorrect Access Control. Under certain conditions where users should have been required to configure two-factor authentication, it was not being required."},{"lang":"es","value":"GitLab versiones 7.10 hasta 12.8.1, presenta un Control de Acceso Incorrecto. En determinadas condiciones donde los usuarios debieron haber sido requeridos para configurar la autenticación de 2 factores, no habían sido requeridos."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-306"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"7.10.0","versionEndIncluding":"12.8.1","matchCriteriaId":"4CB37CDE-EF6C-4687-8E22-EA091417FBA0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"7.10.0","versionEndIncluding":"12.8.1","matchCriteriaId":"B7CDA00F-F39B-4F45-B1BF-FBEB2FBEC3CA"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/index.html","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/index.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-10080","sourceIdentifier":"cve@mitre.org","published":"2020-03-13T17:15:11.860","lastModified":"2026-06-17T02:47:18.983","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab 8.3 through 12.8.1 allows Information Disclosure. It was possible for certain non-members to access the Contribution Analytics page of a private group."},{"lang":"es","value":"GitLab versiones 8.3 hasta 12.8.1, permite una Divulgación de Información. Era posible que determinados no miembros accedieran a la página Contribution Analytics de un grupo privado."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.3.0","versionEndIncluding":"12.8.1","matchCriteriaId":"781CF6A0-DEAE-4DD2-B6C6-97ADC205D756"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.3.0","versionEndIncluding":"12.8.1","matchCriteriaId":"5AC9BAC5-FA24-4EA4-997A-C0979D7B3613"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/index.html","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/index.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-10081","sourceIdentifier":"cve@mitre.org","published":"2020-03-13T17:15:11.940","lastModified":"2026-06-17T02:47:19.093","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab before 12.8.2 has Incorrect Access Control. It was internally discovered that the LFS import process could potentially be used to incorrectly access LFS objects not owned by the user."},{"lang":"es","value":"GitLab versiones anteriores a 12.8.2, presentan un Control de Acceso Incorrecto. Se detectó internamente que el proceso de importación de LFS podría ser usado potencialmente para acceder incorrectamente a objetos LFS que no son propiedad del usuario."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndIncluding":"12.8.1","matchCriteriaId":"CA0ACC3F-4AE5-4003-92CE-07E1568F31CA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndIncluding":"12.8.1","matchCriteriaId":"99277FB9-CDB3-4238-A3CF-7BD8B024192D"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/index.html","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/index.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-10082","sourceIdentifier":"cve@mitre.org","published":"2020-03-13T17:15:12.000","lastModified":"2026-06-17T02:47:19.203","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab 12.2 through 12.8.1 allows Denial of Service. A denial of service vulnerability impacting the designs for public issues was discovered."},{"lang":"es","value":"GitLab versiones 12.2 hasta 12.8.1, permite una Denegación de Servicio. Una vulnerabilidad de denegación de servicio impacta los diseños para problemas públicos que fueron detectados."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.2.0","versionEndIncluding":"12.8.1","matchCriteriaId":"316E7D08-5444-4390-B4DD-4DF9BB6642F9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.2.0","versionEndIncluding":"12.8.1","matchCriteriaId":"EBBABBB7-A8AF-4D32-B460-2666B36D470E"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/index.html","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/index.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-10083","sourceIdentifier":"cve@mitre.org","published":"2020-03-13T17:15:12.377","lastModified":"2026-06-17T02:47:19.317","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab 12.7 through 12.8.1 has Insecure Permissions. Under certain conditions involving groups, project authorization changes were not being applied."},{"lang":"es","value":"GitLab versiones 12.7 hasta 12.8.1, presenta Permisos No Seguros. Bajo determinadas condiciones que involucran a los grupos, no están siendo aplicados los cambios de autorización de proyectos."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":5.2}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:N","baseScore":6.4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-281"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.7.0","versionEndIncluding":"12.8.1","matchCriteriaId":"B5C04A28-12D9-4BCC-9A4C-77EB87B98F62"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.7.0","versionEndIncluding":"12.8.1","matchCriteriaId":"FB2BA174-32BB-470F-9B28-9434E29FB238"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/index.html","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/index.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-10084","sourceIdentifier":"cve@mitre.org","published":"2020-03-13T17:15:12.470","lastModified":"2026-06-17T02:47:19.430","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab EE 11.6 through 12.8.1 allows Information Disclosure. Sending a specially crafted request to the vulnerability_feedback endpoint could result in the exposure of a private project namespace"},{"lang":"es","value":"GitLab EE versiones 11.6 hasta 12.8.1, permite una Divulgación de Información. Enviar una petición  especialmente diseñada hacia el endpoint vulnerability_feedback podría resultar en una exposición de un espacio de nombres de un proyecto privado"}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.6.0","versionEndIncluding":"12.8.1","matchCriteriaId":"1EB8EB76-743E-4CDF-8615-50C2509B67CF"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/index.html","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/index.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-10085","sourceIdentifier":"cve@mitre.org","published":"2020-03-13T17:15:12.533","lastModified":"2026-06-17T02:47:19.540","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab 12.3.5 through 12.8.1 allows Information Disclosure. A particular view was exposing merge private merge request titles."},{"lang":"es","value":"GitLab versiones 12.3.5 hasta 12.8.1, permite una Divulgación de Información. Una vista en particular estaba exponiendo los títulos de peticiones de fusión privadas."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.3.5","versionEndIncluding":"12.8.1","matchCriteriaId":"25E31782-C256-4A65-BA1A-F90D85C02BF1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.3.5","versionEndIncluding":"12.8.1","matchCriteriaId":"6651CD42-2830-4C7A-8C16-15F7075EF701"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/index.html","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/index.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-10086","sourceIdentifier":"cve@mitre.org","published":"2020-03-13T17:15:12.597","lastModified":"2026-06-17T02:47:19.650","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab 10.4 through 12.8.1 allows Directory Traversal. A particular endpoint was vulnerable to a directory traversal vulnerability, leading to arbitrary file read."},{"lang":"es","value":"GitLab versiones 10.4 hasta 12.8.1, permite un Salto de Directorio. Un endpoint en particular era susceptible a una vulnerabilidad de Salto de Directorio, conllevando a una lectura de archivos arbitraria."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-22"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.4.0","versionEndIncluding":"12.8.1","matchCriteriaId":"F024DCC4-C674-4061-B403-93E04F1FE67F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.4.0","versionEndIncluding":"12.8.1","matchCriteriaId":"BBF19DF0-6B4F-474A-9534-3D364225E76C"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/index.html","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/index.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-10087","sourceIdentifier":"cve@mitre.org","published":"2020-03-13T17:15:12.673","lastModified":"2026-06-17T02:47:19.767","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab before 12.8.2 allows Information Disclosure. Badge images were not being proxied, causing mixed content warnings as well as leaking the IP address of the user."},{"lang":"es","value":"GitLab versiones anteriores a 12.8.2, permite una Divulgación de Información. Las imágenes de las tarjetas de identificación no estaban siendo procesadas por un proxy, causando advertencias de contenido mixto, así como un filtrado de la dirección IP del usuario."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndIncluding":"12.8.1","matchCriteriaId":"CA0ACC3F-4AE5-4003-92CE-07E1568F31CA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndIncluding":"12.8.1","matchCriteriaId":"99277FB9-CDB3-4238-A3CF-7BD8B024192D"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/index.html","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/index.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-10088","sourceIdentifier":"cve@mitre.org","published":"2020-03-13T17:15:12.737","lastModified":"2026-06-17T02:47:19.873","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab 12.5 through 12.8.1 has Insecure Permissions. Depending on particular group settings, it was possible for invited groups to be given the incorrect permission level."},{"lang":"es","value":"GitLab versiones 12.5 hasta 12.8.1, presenta Permisos No Seguros. Dependiendo de la configuración de cada grupo en particular, era posible que los grupos invitados recibieran un nivel de permiso incorrecto."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":5.2}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:N","baseScore":5.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-269"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.5.0","versionEndIncluding":"12.8.1","matchCriteriaId":"76F9FA95-BA9B-4516-A10E-C29786F706E1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.5.0","versionEndIncluding":"12.8.1","matchCriteriaId":"4D342A30-C246-44D4-A699-767CEF3A1E10"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/index.html","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/index.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-10089","sourceIdentifier":"cve@mitre.org","published":"2020-03-13T17:15:12.830","lastModified":"2026-06-17T02:47:19.993","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab 8.11 through 12.8.1 allows a Denial of Service when using several features to recursively request eachother,"},{"lang":"es","value":"GitLab versiones 8.11 hasta 12.8.1, permite una Denegación de Servicio cuando se usan  varias funcionalidades para una petición eachother de forma recursiva."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-674"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.11.0","versionEndIncluding":"12.8.1","matchCriteriaId":"1EB47252-7936-45DA-ACF5-04701A0C9F64"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.11.0","versionEndIncluding":"12.8.1","matchCriteriaId":"5B323E6C-B269-4892-B4D6-76E68BAE5EC8"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/index.html","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/index.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-10090","sourceIdentifier":"cve@mitre.org","published":"2020-03-13T17:15:12.893","lastModified":"2026-06-17T02:47:20.107","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab 11.7 through 12.8.1 allows Information Disclosure. Under certain group conditions, group epic information was unintentionally being disclosed."},{"lang":"es","value":"GitLab versiones anteriores a 11.7 hasta 12.8.1, permite una Divulgación de Información. Bajo determinadas  condiciones grupales, la información del epic del grupo se revelaba involuntariamente."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-200"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.7.0","versionEndIncluding":"12.8.1","matchCriteriaId":"6402E9C7-5A66-483A-976D-56752E04DF3A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.7.0","versionEndIncluding":"12.8.1","matchCriteriaId":"AEC26417-B95A-474E-A6BC-D5707B2D2FE8"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/index.html","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/index.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-10091","sourceIdentifier":"cve@mitre.org","published":"2020-03-13T17:15:12.970","lastModified":"2026-06-17T02:47:20.220","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab 9.3 through 12.8.1 allows XSS. A cross-site scripting vulnerability was found when viewing particular file types."},{"lang":"es","value":"GitLab versiones anteriores a 9.3  hasta 12.8.1, permite un ataque de tipo XSS. Se encontró una vulnerabilidad de tipo cross-site scripting  en una vista particular relacionada con la integración de Grafana."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"9.3.0","versionEndIncluding":"12.8.1","matchCriteriaId":"A3C39198-B450-4195-A1DC-EF00297BF494"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"9.3.0","versionEndIncluding":"12.8.1","matchCriteriaId":"EE5A04AF-2235-47C1-85E4-C0AA62E43704"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/index.html","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/index.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-10092","sourceIdentifier":"cve@mitre.org","published":"2020-03-13T17:15:13.047","lastModified":"2026-06-17T02:47:20.330","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab 12.1 through 12.8.1 allows XSS. A cross-site scripting vulnerability was present in a particular view relating to the Grafana integration."},{"lang":"es","value":"GitLab versiones 12.1 hasta 12.8.1, permite un ataque de tipo XSS. Una vulnerabilidad de tipo cross-site scripting estaba presente en una vista particular relacionada con la integración de Grafana."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.1.0","versionEndIncluding":"12.8.1","matchCriteriaId":"87B8AD6C-FFEC-4026-A6AA-DAB724A502B6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.1.0","versionEndIncluding":"12.8.1","matchCriteriaId":"8EA3C0C6-74B3-4E71-B9B0-34ED15888BEF"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/index.html","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/index.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-10073","sourceIdentifier":"cve@mitre.org","published":"2020-03-13T18:15:12.857","lastModified":"2026-06-17T02:47:18.200","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab EE 12.4.2 through 12.8.1 allows Denial of Service. It was internally discovered that a potential denial of service involving permissions checks could impact a project home page."},{"lang":"es","value":"GitLab EE versiones 12.4.2 hasta 12.8.1, permite una Denegación de Servicio. Se detectó  internamente que una potencial denegación de servicio que involucra las comprobaciones de permisos podría impactar a una página de inicio de proyecto."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.4.2","versionEndIncluding":"12.8.1","matchCriteriaId":"7EE34D22-6B13-44D1-AD1F-292D8A6D1A71"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/index.html","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/index.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-10074","sourceIdentifier":"cve@mitre.org","published":"2020-03-13T18:15:12.920","lastModified":"2026-06-17T02:47:18.317","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab 10.1 through 12.8.1 has Incorrect Access Control. A scenario was discovered in which a GitLab account could be taken over through an expired link."},{"lang":"es","value":"GitLab versiones 10.1 hasta 12.8.1, presenta un Control de Acceso Incorrecto. Se detectó  un escenario en el cual una cuenta de GitLab podría ser controlada por medio de un enlace expirado."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.1.0","versionEndIncluding":"12.8.1","matchCriteriaId":"B0061D87-823E-4327-937F-BA0BDBBA6479"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.1.0","versionEndIncluding":"12.8.1","matchCriteriaId":"9142E4D0-63E5-481D-AA9F-3B72114A7768"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/index.html","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/index.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-10075","sourceIdentifier":"cve@mitre.org","published":"2020-03-13T18:15:13.013","lastModified":"2026-06-17T02:47:18.427","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab 12.5 through 12.8.1 allows HTML Injection. A particular error header was potentially susceptible to injection or potentially other vulnerabilities via unescaped input."},{"lang":"es","value":"GitLab versiones 12.5 hasta 12.8.1, permite una inyección de HTML. Un encabezado de error en particular era potencialmente susceptible a una inyección o a otras vulnerabilidades por medio de una entrada sin escape."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:N","baseScore":5.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.5.0","versionEndIncluding":"12.8.1","matchCriteriaId":"76F9FA95-BA9B-4516-A10E-C29786F706E1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.5.0","versionEndIncluding":"12.8.1","matchCriteriaId":"4D342A30-C246-44D4-A699-767CEF3A1E10"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/index.html","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/index.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-10076","sourceIdentifier":"cve@mitre.org","published":"2020-03-13T18:15:13.077","lastModified":"2026-06-17T02:47:18.537","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab 12.1 through 12.8.1 allows XSS. A stored cross-site scripting vulnerability was discovered when displaying merge requests."},{"lang":"es","value":"GitLab versiones 12.1 hasta 12.8.1, permite un ataque de tipo XSS. Se detectó una vulnerabilidad de tipo cross-site scripting almacenado cuando se desplegaban peticiones de fusión."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.1.0","versionEndIncluding":"12.8.1","matchCriteriaId":"87B8AD6C-FFEC-4026-A6AA-DAB724A502B6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.1.0","versionEndIncluding":"12.8.1","matchCriteriaId":"8EA3C0C6-74B3-4E71-B9B0-34ED15888BEF"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/index.html","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/index.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-10077","sourceIdentifier":"cve@mitre.org","published":"2020-03-13T18:15:13.170","lastModified":"2026-06-17T02:47:18.647","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab EE 3.0 through 12.8.1 allows SSRF. An internal investigation revealed that a particular deprecated service was creating a server side request forgery risk."},{"lang":"es","value":"GitLab EE versiones 3.0 hasta 12.8.1, permite un ataque de tipo SSRF. Una investigación interna reveló que un servicio obsoleto en particular estaba creando un riesgo de falsificación de petición del lado del servidor."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"3.0.0","versionEndIncluding":"12.8.1","matchCriteriaId":"87F4A86C-12C6-4693-B46F-0887F1C89CA0"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/index.html","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/index.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-10952","sourceIdentifier":"cve@mitre.org","published":"2020-03-27T19:15:11.243","lastModified":"2026-06-17T02:48:44.297","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab EE/CE 8.11 through 12.9.1 allows blocked users to pull/push docker images."},{"lang":"es","value":"GitLab EE/CE versiones 8.11 hasta 12.9.1, permite a usuarios bloqueados extraer y empujar imágenes de docker."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":2.5}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:N","baseScore":5.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.11.0","versionEndIncluding":"12.9.1","matchCriteriaId":"C6D9B8CC-A789-45E2-9EA0-4F72E66926D3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.11.0","versionEndIncluding":"12.9.1","matchCriteriaId":"1745ED5A-C216-4559-8A66-71D31C58EECE"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2020/03/26/security-release-12-dot-9-dot-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/26/security-release-12-dot-9-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-10953","sourceIdentifier":"cve@mitre.org","published":"2020-03-27T19:15:11.290","lastModified":"2026-06-17T02:48:44.413","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In GitLab EE 11.7 through 12.9, the NPM feature is vulnerable to a path traversal issue."},{"lang":"es","value":"En GitLab EE versiones 11.7 hasta 12.9, la funcionalidad NPM es vulnerable a un problema de salto de ruta."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-22"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.7.0","versionEndIncluding":"12.9","matchCriteriaId":"CA17643F-C92D-45F4-863F-360BE37C33EF"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2020/03/26/security-release-12-dot-9-dot-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/26/security-release-12-dot-9-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-10954","sourceIdentifier":"cve@mitre.org","published":"2020-03-27T19:15:11.337","lastModified":"2026-06-17T02:48:44.523","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab through 12.9 is affected by a potential DoS in repository archive download."},{"lang":"es","value":"GitLab versiones hasta 12.9, está afectado por una DoS potencial en una descarga de archivo del repositorio."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-400"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndIncluding":"12.9","matchCriteriaId":"066CDF0C-B606-4D25-B023-639496980660"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndIncluding":"12.9","matchCriteriaId":"53D3E261-BA7B-4BC5-9934-5631BAD398EC"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2020/03/26/security-release-12-dot-9-dot-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/26/security-release-12-dot-9-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-10955","sourceIdentifier":"cve@mitre.org","published":"2020-03-27T19:15:11.383","lastModified":"2026-06-17T02:48:44.633","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab EE/CE 11.1 through 12.9 is vulnerable to parameter tampering on an upload feature that allows an unauthorized user to read content available under specific folders."},{"lang":"es","value":"GitLab EE/CE versiones 11.1 hasta 12.9, es vulnerable a una manipulación de parámetros en una funcionalidad de carga que permite a un usuario no autorizado leer el contenido disponible bajo carpetas específicas."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.1.0","versionEndExcluding":"12.9.1","matchCriteriaId":"4E0DDF15-D401-464A-A051-A533C528A662"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.1.0","versionEndExcluding":"12.9.1","matchCriteriaId":"12BD5403-468B-48C5-9542-B7F1F7B8FC53"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*","matchCriteriaId":"07B237A9-69A3-4A9C-9DA0-4E06BD37AE73"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2020/03/26/security-release-12-dot-9-dot-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://www.debian.org/security/2020/dsa-4691","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/26/security-release-12-dot-9-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://www.debian.org/security/2020/dsa-4691","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2020-10956","sourceIdentifier":"cve@mitre.org","published":"2020-03-27T19:15:11.447","lastModified":"2026-06-17T02:48:44.743","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab 8.10 and later through 12.9 is vulnerable to an SSRF in a project import note feature."},{"lang":"es","value":"GitLab versiones 8.10 y posteriores a 12.9, es vulnerable a un ataque de tipo SSRF en una funcionalidad de nota de importación de proyecto."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.10.0","versionEndExcluding":"12.9.1","matchCriteriaId":"96977F42-3F97-4EB2-98A2-41FAD0CF925A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.10.0","versionEndExcluding":"12.9.1","matchCriteriaId":"E371A916-4B1D-4263-B30D-1BB9D7620FAC"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2020/03/26/security-release-12-dot-9-dot-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/26/security-release-12-dot-9-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-10975","sourceIdentifier":"cve@mitre.org","published":"2020-04-08T19:15:12.883","lastModified":"2026-06-17T02:48:47.283","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab EE/CE 10.8 to 12.9 is leaking metadata and comments on vulnerabilities to unauthorized users on the vulnerability feedback page."},{"lang":"es","value":"GitLab EE/CE versiones 10.8 hasta 12.9, está filtrando metadatos y comentarios sobre vulnerabilidades a usuarios no autorizados en la página de comentarios sobre vulnerabilidades."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.8.0","versionEndIncluding":"12.9","matchCriteriaId":"1115DBD1-B6C4-4999-8E31-4914BCF528D4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.8.0","versionEndIncluding":"12.9","matchCriteriaId":"F079F1DE-4614-471E-9C2A-07639CF6D7FE"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2020/03/26/security-release-12-dot-9-dot-1-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/26/security-release-12-dot-9-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-10976","sourceIdentifier":"cve@mitre.org","published":"2020-04-08T19:15:12.930","lastModified":"2026-06-17T02:48:47.403","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab EE/CE 8.17 to 12.9 is vulnerable to information leakage when querying a merge request widget."},{"lang":"es","value":"GitLab EE/CE versiones 8.17 hasta 12.9, es vulnerable a la filtrado de información al consultar un widget de una petición de fusión."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-200"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.17.0","versionEndIncluding":"12.9","matchCriteriaId":"E15ADFF8-8F42-4CB1-8CFC-CF2C08A5A369"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.17.0","versionEndIncluding":"12.9","matchCriteriaId":"873AA465-420B-45F8-BA91-93F19F74C29D"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2020/03/26/security-release-12-dot-9-dot-1-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/26/security-release-12-dot-9-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-10977","sourceIdentifier":"cve@mitre.org","published":"2020-04-08T19:15:12.977","lastModified":"2026-06-17T02:48:47.513","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab EE/CE 8.5 to 12.9 is vulnerable to a an path traversal when moving an issue between projects."},{"lang":"es","value":"GitLab EE/CE versiones 8.5 hasta 12.9, es vulnerable a un salto de ruta cuando se mueve un problema entre proyectos."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:N/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-22"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.5.0","versionEndIncluding":"12.9","matchCriteriaId":"8217519D-4E42-431A-93C3-57657F2B3A8D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.5.0","versionEndIncluding":"12.9","matchCriteriaId":"AE0D16E4-EB54-4193-9875-325A005E1639"}]}]}],"references":[{"url":"http://packetstormsecurity.com/files/160441/GitLab-File-Read-Remote-Code-Execution.html","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory","VDB Entry"]},{"url":"https://about.gitlab.com/releases/2020/03/26/security-release-12-dot-9-dot-1-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"http://packetstormsecurity.com/files/160441/GitLab-File-Read-Remote-Code-Execution.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory","VDB Entry"]},{"url":"https://about.gitlab.com/releases/2020/03/26/security-release-12-dot-9-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-10978","sourceIdentifier":"cve@mitre.org","published":"2020-04-08T19:15:13.027","lastModified":"2026-06-17T02:48:47.627","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab EE/CE 8.11 to 12.9 is leaking information on Issues opened in a public project and then moved to a private project through Web-UI and GraphQL API."},{"lang":"es","value":"GitLab EE/CE versiones 8.11 hasta 12.9, está filtrando información sobre Problemas aperturados en un proyecto público y luego es movido a un proyecto privado por medio de Interfaz de Usuario Web y la API GraphQL."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.11.0","versionEndIncluding":"12.9","matchCriteriaId":"1C402102-B78F-408E-8F5C-A31C2681C115"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.11.0","versionEndIncluding":"12.9","matchCriteriaId":"F86F551E-C68A-468F-BAFB-2E3DA48D4670"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2020/03/26/security-release-12-dot-9-dot-1-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/26/security-release-12-dot-9-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-10979","sourceIdentifier":"cve@mitre.org","published":"2020-04-08T19:15:13.087","lastModified":"2026-06-17T02:48:47.740","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab EE/CE 11.10 to 12.9 is leaking information on restricted CI pipelines metrics to unauthorized users."},{"lang":"es","value":"GitLab EE/CE versiones 11.10 hasta 12.9, está filtrando información sobre métricas de tuberías de CI a usuarios no autorizados."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.10.0","versionEndIncluding":"12.9","matchCriteriaId":"842DFFAE-0003-49BD-BFCB-5BAA1A0ECF41"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.10.0","versionEndIncluding":"12.9","matchCriteriaId":"1A7C0825-D27E-413A-B7E3-8429EC82C91A"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2020/03/26/security-release-12-dot-9-dot-1-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/26/security-release-12-dot-9-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-10980","sourceIdentifier":"cve@mitre.org","published":"2020-04-08T19:15:13.133","lastModified":"2026-06-17T02:48:47.847","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab EE/CE 8.0.rc1 to 12.9 is vulnerable to a blind SSRF in the FogBugz integration."},{"lang":"es","value":"GitLab EE/CE versiones 8.0.rc1 hasta 12.9, es vulnerable a un ataque de tipo SSRF ciego en la integración de FogBugz."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.0.0","versionEndIncluding":"12.9","matchCriteriaId":"E2B2E533-9B0F-4998-A1F3-654DEB6DAD92"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.0.0","versionEndIncluding":"12.9","matchCriteriaId":"5A15DB56-7081-486E-9A73-81D03191AABE"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2020/03/26/security-release-12-dot-9-dot-1-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/26/security-release-12-dot-9-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-10981","sourceIdentifier":"cve@mitre.org","published":"2020-04-08T19:15:13.197","lastModified":"2026-06-17T02:48:47.960","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab EE/CE 9.0 to 12.9 allows a maintainer to modify other maintainers' pipeline trigger descriptions within the same project."},{"lang":"es","value":"GitLab EE/CE versiones 9.0 hasta 12.9, permite a un mantenedor modificar las descripciones de activación de la tubería de otros mantenedores dentro del mismo proyecto."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"9.0.0","versionEndIncluding":"12.9","matchCriteriaId":"C4EB5724-0BCC-4ADE-A034-8BC7A580C50A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"9.0.0","versionEndIncluding":"12.9","matchCriteriaId":"DE1F3B59-E38A-40C2-90E0-0FB82632A101"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2020/03/26/security-release-12-dot-9-dot-1-released/","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"https://about.gitlab.com/releases/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Third Party Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/26/security-release-12-dot-9-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://about.gitlab.com/releases/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2020-11505","sourceIdentifier":"cve@mitre.org","published":"2020-04-22T20:15:11.327","lastModified":"2026-06-17T02:50:18.397","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) before 12.7.9, 12.8.x before 12.8.9, and 12.9.x before 12.9.3. A Workhorse bypass could lead to NuGet package and file disclosure (Exposure of Sensitive Information) via request smuggling."},{"lang":"es","value":"Se descubrió un problema en GitLab Community Edition (CE) and Enterprise Edition (EE) versiones anteriores a la versión 12.7.9, versiones 12.8.x anteriores a la versión 12.8.9 y versiones 12.9.x anteriores a la versión 12.9.3. Una omisión de Workhorse podría conllevar a una divulgación de paquetes y archivos NuGet (Exposición de información confidencial) por medio del tráfico no autorizado de peticiones."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-444"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"12.7.9","matchCriteriaId":"8F0DBEF5-297A-4A22-8D86-75A08AFAEC50"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"12.7.9","matchCriteriaId":"EFB6690C-5691-4B05-84F8-D1EF394EF89B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.8.0","versionEndExcluding":"12.8.9","matchCriteriaId":"861030F1-A2CF-4506-9B9F-164F1F51CE03"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.8.0","versionEndExcluding":"12.8.9","matchCriteriaId":"004FAF2E-056E-4E13-9791-28EF5E840A4E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.9.0","versionEndExcluding":"12.9.3","matchCriteriaId":"C653AACA-267F-4307-96AA-956B70E9990B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.9.0","versionEndExcluding":"12.9.3","matchCriteriaId":"3B2272BF-C48F-451D-9822-523994A982D4"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/04/14/critical-security-release-gitlab-12-dot-9-dot-3-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/04/14/critical-security-release-gitlab-12-dot-9-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-11506","sourceIdentifier":"cve@mitre.org","published":"2020-04-22T20:15:11.370","lastModified":"2026-06-17T02:50:18.573","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab 10.7.0 and later through 12.9.2. A Workhorse bypass could lead to job artifact uploads and file disclosure (Exposure of Sensitive Information) via request smuggling."},{"lang":"es","value":"Se descubrió un problema en GitLab versiones 10.7.0 y posteriores hasta la versión 12.9.2. Una omisión de Workhorse podría conllevar a una carga de artefactos de trabajo y una divulgación de archivos (Exposición de información confidencial) por medio del tráfico no autorizado de peticiones."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-444"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.7.0","versionEndExcluding":"12.7.9","matchCriteriaId":"2432E6B8-E40F-4BA5-AEC4-71A6119BADBB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.7.9","versionEndExcluding":"12.7.9","matchCriteriaId":"77293DD5-FADE-43D0-9861-8C717504BC3C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.8.0","versionEndExcluding":"12.8.9","matchCriteriaId":"861030F1-A2CF-4506-9B9F-164F1F51CE03"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.8.0","versionEndExcluding":"12.8.9","matchCriteriaId":"004FAF2E-056E-4E13-9791-28EF5E840A4E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.9.0","versionEndExcluding":"12.9.3","matchCriteriaId":"C653AACA-267F-4307-96AA-956B70E9990B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.9.0","versionEndExcluding":"12.9.3","matchCriteriaId":"3B2272BF-C48F-451D-9822-523994A982D4"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/04/14/critical-security-release-gitlab-12-dot-9-dot-3-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/04/14/critical-security-release-gitlab-12-dot-9-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-11649","sourceIdentifier":"cve@mitre.org","published":"2020-04-22T20:15:11.433","lastModified":"2026-06-17T02:50:33.057","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab CE and EE 8.15 through 12.9.2. Members of a group could still have access after the group is deleted."},{"lang":"es","value":"Se descubrió un problema en GitLab CE and EE versiones 8.15 hasta la versión 12.9.2. Los miembros de un grupo aún podrían tener acceso después de que se elimine el grupo."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-306"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.15.0","versionEndExcluding":"12.7.9","matchCriteriaId":"6818C887-3174-4E71-91FF-355F89FB21AF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.15.0","versionEndExcluding":"12.7.9","matchCriteriaId":"032C29FD-B8AC-4D6C-8A65-6768322A22A2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.8.0","versionEndExcluding":"12.8.9","matchCriteriaId":"861030F1-A2CF-4506-9B9F-164F1F51CE03"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.8.0","versionEndExcluding":"12.8.9","matchCriteriaId":"004FAF2E-056E-4E13-9791-28EF5E840A4E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.9.0","versionEndExcluding":"12.9.3","matchCriteriaId":"C653AACA-267F-4307-96AA-956B70E9990B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.9.0","versionEndExcluding":"12.9.3","matchCriteriaId":"3B2272BF-C48F-451D-9822-523994A982D4"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/04/14/critical-security-release-gitlab-12-dot-9-dot-3-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/04/14/critical-security-release-gitlab-12-dot-9-dot-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-12275","sourceIdentifier":"cve@mitre.org","published":"2020-04-29T17:15:11.943","lastModified":"2026-06-17T02:51:33.043","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab 12.6 through 12.9 is vulnerable to a privilege escalation that allows an external user to create a personal snippet through the API."},{"lang":"es","value":"GitLab versiones 12.6 hasta 12.9 es vulnerable a una escalada de privilegios que permite a un usuario externo crear un fragmento personal por medio de la API."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.6.0","versionEndExcluding":"12.7.8","matchCriteriaId":"8B439031-D14F-4E86-8823-BCA76602240B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.6.0","versionEndExcluding":"12.7.8","matchCriteriaId":"785E0234-05A6-493F-A461-A473752F78FD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.8.0","versionEndExcluding":"12.8.8","matchCriteriaId":"B61029C4-FE10-4775-B51E-20A551C53F6F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.8.0","versionEndExcluding":"12.8.8","matchCriteriaId":"DEFDD1F7-3FBD-4A58-9E9D-FECF042B830F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.9.0","versionEndExcluding":"12.9.1","matchCriteriaId":"59932E33-AB4E-45B2-B40C-CB09AB2799A9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.9.0","versionEndExcluding":"12.9.1","matchCriteriaId":"7E3F1775-FA55-4FCC-BEB3-431D9FDA5A8E"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2020/03/26/security-release-12-dot-9-dot-1-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/26/security-release-12-dot-9-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-12276","sourceIdentifier":"cve@mitre.org","published":"2020-04-29T17:15:11.990","lastModified":"2026-06-17T02:51:33.170","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab 9.5.9 through 12.9 is vulnerable to stored XSS in an admin notification feature."},{"lang":"es","value":"GitLab versiones 9.5.9 hasta 12.9, es vulnerable a un ataque de tipo XSS almacenado en una funcionalidad de notificación de administrador."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N","baseScore":4.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.7,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"9.5.9","versionEndExcluding":"12.7.8","matchCriteriaId":"7855B06D-DE5D-479F-AB1F-B445382FEE32"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"9.5.9","versionEndExcluding":"12.7.8","matchCriteriaId":"FD0AA258-80B5-47B3-B2A8-A66ACAC63B29"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.8.0","versionEndExcluding":"12.8.8","matchCriteriaId":"B61029C4-FE10-4775-B51E-20A551C53F6F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.8.0","versionEndExcluding":"12.8.8","matchCriteriaId":"DEFDD1F7-3FBD-4A58-9E9D-FECF042B830F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.9.0","versionEndExcluding":"12.9.1","matchCriteriaId":"59932E33-AB4E-45B2-B40C-CB09AB2799A9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.9.0","versionEndExcluding":"12.9.1","matchCriteriaId":"7E3F1775-FA55-4FCC-BEB3-431D9FDA5A8E"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2020/03/26/security-release-12-dot-9-dot-1-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/26/security-release-12-dot-9-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-12277","sourceIdentifier":"cve@mitre.org","published":"2020-04-29T17:15:12.037","lastModified":"2026-06-17T02:51:33.280","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab 10.8 through 12.9 has a vulnerability that allows someone to mirror a repository even if the feature is not activated."},{"lang":"es","value":"GitLab versiones 10.8 hasta 12.9, tiene una vulnerabilidad que permite a alguien reflejar un repositorio incluso si la función no está activada."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-276"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.8.0","versionEndExcluding":"12.7.8","matchCriteriaId":"2AC9124B-B0E2-4095-BD45-72FC375D5413"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.8.0","versionEndExcluding":"12.7.8","matchCriteriaId":"C1546EC4-F622-4912-811B-2C0EC73DB790"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.8.0","versionEndExcluding":"12.8.8","matchCriteriaId":"B61029C4-FE10-4775-B51E-20A551C53F6F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.8.0","versionEndExcluding":"12.8.8","matchCriteriaId":"DEFDD1F7-3FBD-4A58-9E9D-FECF042B830F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.9.0","versionEndExcluding":"12.9.1","matchCriteriaId":"59932E33-AB4E-45B2-B40C-CB09AB2799A9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.9.0","versionEndExcluding":"12.9.1","matchCriteriaId":"7E3F1775-FA55-4FCC-BEB3-431D9FDA5A8E"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2020/03/26/security-release-12-dot-9-dot-1-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/2020/03/26/security-release-12-dot-9-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-12448","sourceIdentifier":"cve@mitre.org","published":"2020-05-07T17:15:11.713","lastModified":"2026-06-17T02:51:50.393","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab EE 12.8 and later allows Exposure of Sensitive Information to an Unauthorized Actor via NuGet."},{"lang":"es","value":"GitLab EE versión 12.8 y posterior, permite una Exposición de Información Confidencial a un Actor No Autorizado por medio de NuGet."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-22"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.8.0","versionEndExcluding":"12.8.10","matchCriteriaId":"957717C5-1EC2-428E-BA80-E9214462BBDA"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Product","Release Notes"]},{"url":"https://about.gitlab.com/releases/2020/04/30/security-release-12-10-2-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Product","Release Notes"]},{"url":"https://about.gitlab.com/releases/2020/04/30/security-release-12-10-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-13266","sourceIdentifier":"cve@gitlab.com","published":"2020-06-09T16:15:10.520","lastModified":"2026-06-17T02:52:49.257","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Insecure authorization in Project Deploy Keys in GitLab CE/EE 12.8 and later through 13.0.1 allows users to update permissions of other users' deploy keys under certain conditions"},{"lang":"es","value":"Una autorización no segura en Project Deploy Keys en GitLab CE/EE versiones 12.8 y posteriores hasta 13.0.1, permite a usuarios actualizar los permisos de las claves de despliegue de otros usuarios bajo determinadas condiciones"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.8, <12.9.8","status":"affected"},{"version":">=12.10, <12.10.7","status":"affected"},{"version":">=13.0, <13.0.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.8","versionEndIncluding":"13.0.1","matchCriteriaId":"EB1FF226-31C2-4FDA-BABD-CA1F3CB077A0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.8","versionEndIncluding":"13.0.1","matchCriteriaId":"1CC5A66C-5C37-4B41-9CD7-1B624D35BCE3"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13266.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/208449","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13266.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/208449","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2020-13267","sourceIdentifier":"cve@gitlab.com","published":"2020-06-10T15:15:13.103","lastModified":"2026-06-17T02:52:49.367","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A Stored Cross-Site Scripting vulnerability allowed the execution on Javascript payloads on the Metrics Dashboard in GitLab CE/EE 12.8 and later through 13.0.1"},{"lang":"es","value":"Una vulnerabilidad de tipo Cross-Site Scripting Almacenado, permitió la ejecución en cargas útiles de Javascript en el Metrics Dashboard en GitLab CE/EE versiones 12.8 y posteriores hasta 13.0.1"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.8, <12.9.8","status":"affected"},{"version":">=12.10, <12.10.7","status":"affected"},{"version":">=13.0, <13.0.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.8.0","versionEndIncluding":"13.0.1","matchCriteriaId":"59C9BDD2-1341-4967-A6CA-117BA8A6374D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.8.0","versionEndIncluding":"13.0.1","matchCriteriaId":"30B3D5EC-1C67-4FE7-BA2E-BB64004F96D7"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13267.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/211956","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://hackerone.com/reports/824773","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13267.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/211956","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://hackerone.com/reports/824773","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2020-13268","sourceIdentifier":"cve@gitlab.com","published":"2020-06-10T15:15:13.197","lastModified":"2026-06-17T02:52:49.490","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A specially crafted request could be used to confirm the existence of files hosted on object storage services, without disclosing their contents. This vulnerability affects GitLab CE/EE 12.10 and later through 13.0.1"},{"lang":"es","value":"Se podría usar una petición especialmente diseñada para confirmar la existencia de archivos alojados en servicios de almacenamiento de objetos, sin revelar su contenido. Esta vulnerabilidad afecta a GitLab CE/EE versiones 12.10 y posteriores hasta 13.0.1"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.8, <12.9.8","status":"affected"},{"version":">=12.10, <12.10.7","status":"affected"},{"version":">=13.0, <13.0.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-200"},{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.10.0","versionEndIncluding":"13.0.1","matchCriteriaId":"3F507BEE-48DF-4822-9DC0-3C32229CDF64"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.10.0","versionEndIncluding":"13.0.1","matchCriteriaId":"13280E4D-D896-4E07-A4FE-46E0F809B567"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13268.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/214220","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://hackerone.com/reports/848415","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13268.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/214220","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://hackerone.com/reports/848415","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2020-13269","sourceIdentifier":"cve@gitlab.com","published":"2020-06-10T15:15:13.290","lastModified":"2026-06-17T02:52:49.620","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A Reflected Cross-Site Scripting vulnerability allowed the execution of arbitrary Javascript code on the Static Site Editor in GitLab CE/EE 12.10 and later through 13.0.1"},{"lang":"es","value":"Una vulnerabilidad de tipo Cross-Site Scripting Reflejado permitió la ejecución de código Javascript arbitrario en el Static Site Editor en GitLab CE/EE versiones 12.10 y posteriores hasta 13.0.1"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.10, <12.10.7","status":"affected"},{"version":">=13.0, <13.0.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.10.0","versionEndExcluding":"12.10.7","matchCriteriaId":"C9ED9593-9837-4849-A890-C2FDDC56C5A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.10.0","versionEndExcluding":"12.10.7","matchCriteriaId":"846CD4C7-BFCB-4DFC-901E-46CCA8ADA56A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.0.0","versionEndExcluding":"13.0.1","matchCriteriaId":"1CD346DA-966C-4890-AF19-59A148CBE85D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.0.0","versionEndExcluding":"13.0.1","matchCriteriaId":"1051DEE5-7FE4-476D-815D-29F62B3FCB6E"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13269.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/216528","source":"cve@gitlab.com","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/864356","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13269.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/216528","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/864356","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2020-13270","sourceIdentifier":"cve@gitlab.com","published":"2020-06-10T15:15:13.370","lastModified":"2026-06-17T02:52:49.737","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Missing permission check on fork relation creation in GitLab CE/EE 11.3 and later through 13.0.1 allows guest users to create a fork relation on restricted public projects via API"},{"lang":"es","value":"Una falta de comprobación de permisos en la creación de relaciones de bifurcación en GitLab CE/EE versiones 11.3 y posteriores hasta 13.0.1, permite a usuarios invitados crear una relación de bifurcación en proyectos públicos restringidos mediante la API"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=11.3, <12.9.8","status":"affected"},{"version":">=12.10, <12.10.7","status":"affected"},{"version":">=13.0, <13.0.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.6,"impactScore":5.9},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"11.9.8","matchCriteriaId":"2FA490D9-F529-41C6-8F23-4FF726A0A99F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"12.9.8","matchCriteriaId":"43B86DAC-082A-4D82-9082-74A517BF1B5F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.10.0","versionEndExcluding":"12.10.7","matchCriteriaId":"C9ED9593-9837-4849-A890-C2FDDC56C5A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.10.0","versionEndExcluding":"12.10.7","matchCriteriaId":"846CD4C7-BFCB-4DFC-901E-46CCA8ADA56A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.0.0","versionEndExcluding":"13.0.1","matchCriteriaId":"1CD346DA-966C-4890-AF19-59A148CBE85D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.0.0","versionEndExcluding":"13.0.1","matchCriteriaId":"1051DEE5-7FE4-476D-815D-29F62B3FCB6E"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13270.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/24648","source":"cve@gitlab.com","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/419977","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13270.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/24648","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/419977","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2020-13271","sourceIdentifier":"cve@gitlab.com","published":"2020-06-10T15:15:13.447","lastModified":"2026-06-17T02:52:49.853","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A Stored Cross-Site Scripting vulnerability allowed the execution of arbitrary Javascript code in the blobs API in all previous GitLab CE/EE versions through 13.0.1"},{"lang":"es","value":"Una vulnerabilidad de tipo Cross-Site Scripting Almacenado permitió la ejecución de código Javascript arbitrario en la API blobs en todas las versiones anteriores de GitLab CE/EE hasta 13.0.1"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":"<12.9.8","status":"affected"},{"version":">=12.10, <12.10.7","status":"affected"},{"version":">=13.0, <13.0.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"12.9.8","matchCriteriaId":"5D12F24E-AA18-4BBA-9A00-8CE7B622F599"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"12.9.8","matchCriteriaId":"3D5D493A-5115-481B-B5D6-8A31A6874A9C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.10.0","versionEndExcluding":"12.10.7","matchCriteriaId":"C9ED9593-9837-4849-A890-C2FDDC56C5A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.10.0","versionEndExcluding":"12.10.7","matchCriteriaId":"846CD4C7-BFCB-4DFC-901E-46CCA8ADA56A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.0.0","versionEndExcluding":"13.0.1","matchCriteriaId":"1CD346DA-966C-4890-AF19-59A148CBE85D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.0.0","versionEndExcluding":"13.0.1","matchCriteriaId":"1051DEE5-7FE4-476D-815D-29F62B3FCB6E"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13271.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/200094","source":"cve@gitlab.com","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/672150","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13271.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/200094","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/672150","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2020-14155","sourceIdentifier":"cve@mitre.org","published":"2020-06-15T17:15:10.777","lastModified":"2026-06-17T02:54:18.380","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"libpcre in PCRE before 8.44 allows an integer overflow via a large number after a (?C substring."},{"lang":"es","value":"libpcre en PCRE versiones anteriores a 8.44, permite un desbordamiento de enteros por medio de un número grande después de una subcadena (?C"}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-190"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:pcre:pcre:*:*:*:*:*:*:*:*","versionEndExcluding":"8.44","matchCriteriaId":"DE44B5A4-6CB9-4E93-A4A6-1A9152547258"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*","versionEndExcluding":"11.0.1","matchCriteriaId":"F2EE75CC-3796-416A-9E58-64788BB89240"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"12.10.13","matchCriteriaId":"69A326C9-D3ED-4AA3-9832-CB7C0BC8D66F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"12.10.13","matchCriteriaId":"0C533B72-56E8-40ED-8FC2-D4963DB0C397"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.0.0","versionEndExcluding":"13.0.8","matchCriteriaId":"6C2D99CC-CB24-43D8-A231-C76A2DAE1CFA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.0.0","versionEndExcluding":"13.0.8","matchCriteriaId":"21BF96AA-827E-4CB3-943B-478C141917D2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.2","matchCriteriaId":"51809B8F-141D-43B9-BAC5-328E9F4DD7BF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.2","matchCriteriaId":"54A7E410-0F0C-414A-98AA-C3DA9B5191A5"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.15.0:*:*:*:*:*:*:*","matchCriteriaId":"B4367D9B-BF81-47AD-A840-AC46317C774D"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*","matchCriteriaId":"3A756737-1CC4-42C2-A4DF-E1C893B4E2D5"},{"vulnerable":true,"criteria":"cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:*","matchCriteriaId":"5C2089EE-5D7F-47EC-8EA5-0F69790564C4"},{"vulnerable":true,"criteria":"cpe:2.3:a:netapp:clustered_data_ontap:-:*:*:*:*:*:*:*","matchCriteriaId":"1FE996B1-6951-4F85-AA58-B99A379D2163"},{"vulnerable":true,"criteria":"cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:*","matchCriteriaId":"E7CF3019-975D-40BB-A8A4-894E62BD3797"},{"vulnerable":true,"criteria":"cpe:2.3:a:netapp:steelstore_cloud_integrated_storage:-:*:*:*:*:*:*:*","matchCriteriaId":"E94F7F59-1785-493F-91A7-5F5EA5E87E4D"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:*","matchCriteriaId":"234DEFE0-5CE5-4B0A-96B8-5D227CB8ED31"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:netapp:h410c:-:*:*:*:*:*:*:*","matchCriteriaId":"CDDF61B7-EC5C-467C-B710-B89F502CD04F"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*","matchCriteriaId":"6770B6C3-732E-4E22-BF1C-2D2FD610061C"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:*","matchCriteriaId":"9F9C8C20-42EB-4AB5-BD97-212DEB070C43"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*","matchCriteriaId":"7FFF7106-ED78-49BA-9EC5-B889E3685D53"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:*","matchCriteriaId":"E63D8B0F-006E-4801-BF9D-1C001BBFB4F9"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*","matchCriteriaId":"56409CEC-5A1E-4450-AA42-641E459CC2AF"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:netapp:h700s:-:*:*:*:*:*:*:*","matchCriteriaId":"B06F4839-D16A-4A61-9BB5-55B13F41E47F"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*","matchCriteriaId":"D0B4AD8A-F172-4558-AEC6-FF424BA2D912"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:*","matchCriteriaId":"8497A4C9-8474-4A62-8331-3FE862ED4098"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:splunk:universal_forwarder:*:*:*:*:*:*:*:*","versionStartIncluding":"8.2.0","versionEndExcluding":"8.2.12","matchCriteriaId":"5722E753-75DE-4944-A11B-556CB299B57D"},{"vulnerable":true,"criteria":"cpe:2.3:a:splunk:universal_forwarder:*:*:*:*:*:*:*:*","versionStartIncluding":"9.0.0","versionEndExcluding":"9.0.6","matchCriteriaId":"DC0F9351-81A4-4FEA-B6B5-6E960A933D32"},{"vulnerable":true,"criteria":"cpe:2.3:a:splunk:universal_forwarder:9.1.0:*:*:*:*:*:*:*","matchCriteriaId":"EED24E67-2957-4C1B-8FEA-E2D2FE7B97FC"}]}]}],"references":[{"url":"http://seclists.org/fulldisclosure/2020/Dec/32","source":"cve@mitre.org","tags":["Mailing List","Third Party Advisory"]},{"url":"http://seclists.org/fulldisclosure/2021/Feb/14","source":"cve@mitre.org","tags":["Mailing List","Third Party Advisory"]},{"url":"https://about.gitlab.com/releases/2020/07/01/security-release-13-1-2-release/","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"https://bugs.gentoo.org/717920","source":"cve@mitre.org","tags":["Issue Tracking","Patch","Third Party Advisory"]},{"url":"https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E","source":"cve@mitre.org","tags":["Mailing List","Third Party Advisory"]},{"url":"https://security.netapp.com/advisory/ntap-20221028-0010/","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"https://support.apple.com/kb/HT211931","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"https://support.apple.com/kb/HT212147","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"https://www.oracle.com/security-alerts/cpuapr2022.html","source":"cve@mitre.org","tags":["Patch","Third Party Advisory"]},{"url":"https://www.pcre.org/original/changelog.txt","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"http://seclists.org/fulldisclosure/2020/Dec/32","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"]},{"url":"http://seclists.org/fulldisclosure/2021/Feb/14","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"]},{"url":"https://about.gitlab.com/releases/2020/07/01/security-release-13-1-2-release/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://bugs.gentoo.org/717920","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Patch","Third Party Advisory"]},{"url":"https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"]},{"url":"https://security.netapp.com/advisory/ntap-20221028-0010/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://support.apple.com/kb/HT211931","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://support.apple.com/kb/HT212147","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://www.oracle.com/security-alerts/cpuapr2022.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"]},{"url":"https://www.pcre.org/original/changelog.txt","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-13277","sourceIdentifier":"cve@gitlab.com","published":"2020-06-19T18:15:10.897","lastModified":"2026-06-17T02:52:50.560","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An authorization issue in the mirroring logic allowed read access to private repositories in GitLab CE/EE 10.6 and later through 13.0.5"},{"lang":"es","value":"Un problema de autorización en la lógica de duplicación permitió el acceso de lectura a repositorios privados en GitLab CE/EE 10.6 y posteriores hasta la versión 13.0.5"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=10.6, <12.9.10","status":"affected"},{"version":">=12.10, <12.10.11","status":"affected"},{"version":">=13.0, <13.0.6","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N","baseScore":6.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.8,"impactScore":4.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.6.0","versionEndIncluding":"13.0.5","matchCriteriaId":"74462D93-1B88-4334-9E16-F82802B6D13D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.6.0","versionEndIncluding":"13.0.5","matchCriteriaId":"49D1C8B6-D822-417B-9BBD-35CCA3508EA7"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13277.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/220972","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/894569","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13277.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/220972","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/894569","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2020-13262","sourceIdentifier":"cve@gitlab.com","published":"2020-06-19T22:15:12.647","lastModified":"2026-06-17T02:52:48.800","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Client-Side code injection through Mermaid markup in GitLab CE/EE 12.9 and later through 13.0.1 allows a specially crafted Mermaid payload to PUT requests on behalf of other users via clicking on a link"},{"lang":"es","value":"Una inyección de código de tipo Client-Side por medio del marcado Mermaid en GitLab CE/EE versiones 12.9 y posteriores hasta la versión 13.0.1, permite una carga útil de Mermaid especialmente diseñada para peticiones PUT en nombre de otros usuarios al cliquear en un enlace"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.9, <12.9.8","status":"affected"},{"version":">=12.10, <12.10.7","status":"affected"},{"version":">=13.0, <13.0.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-74"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.9.0","versionEndExcluding":"12.9.8","matchCriteriaId":"63B9688C-C8BC-4E06-9A90-688E1A72EED6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.9.0","versionEndExcluding":"12.9.8","matchCriteriaId":"F76601E6-F6EF-49C4-8FBF-75A24F2ACDED"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.10.0","versionEndExcluding":"12.10.7","matchCriteriaId":"C9ED9593-9837-4849-A890-C2FDDC56C5A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.10.0","versionEndExcluding":"12.10.7","matchCriteriaId":"846CD4C7-BFCB-4DFC-901E-46CCA8ADA56A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:13.0.0:*:*:*:community:*:*:*","matchCriteriaId":"439E1C57-8846-4EB8-A78A-DE6BDAF6CAF5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:13.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"F6CA871C-BEFF-4951-AC88-ACA603C25CE1"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13262.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/211949","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/824689","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13262.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/211949","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/824689","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2020-13265","sourceIdentifier":"cve@gitlab.com","published":"2020-06-19T22:15:12.710","lastModified":"2026-06-17T02:52:49.143","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"User email verification bypass in GitLab CE/EE 12.5 and later through 13.0.1 allows user to bypass email verification"},{"lang":"es","value":"Una omisión de verificación de correo electrónico del usuario en GitLab CE/EE versiones 12.5 y posteriores hasta la versión 13.0.1, permite al usuario omitir la verificación de correo electrónico"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.5, <12.9.8","status":"affected"},{"version":">=12.10, <12.10.7","status":"affected"},{"version":">=13.0, <13.0.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-345"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.5.0","versionEndExcluding":"12.9.8","matchCriteriaId":"9E22A432-C91A-4D80-9884-E835B911D92C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.5.0","versionEndExcluding":"12.9.8","matchCriteriaId":"AAF7D17D-E2EA-4F5E-A367-910AA411914D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.10.0","versionEndExcluding":"12.10.7","matchCriteriaId":"C9ED9593-9837-4849-A890-C2FDDC56C5A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.10.0","versionEndExcluding":"12.10.7","matchCriteriaId":"846CD4C7-BFCB-4DFC-901E-46CCA8ADA56A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:13.0.0:*:*:*:community:*:*:*","matchCriteriaId":"439E1C57-8846-4EB8-A78A-DE6BDAF6CAF5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:13.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"F6CA871C-BEFF-4951-AC88-ACA603C25CE1"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13265.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/121664","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/762568","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13265.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/121664","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/762568","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2020-13272","sourceIdentifier":"cve@gitlab.com","published":"2020-06-19T22:15:12.773","lastModified":"2026-06-17T02:52:49.977","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"OAuth flow missing verification checks CE/EE 12.3 and later through 13.0.1 allows unverified user to use OAuth authorization code flow"},{"lang":"es","value":"Una falta de controles de verificación de flujo de OAuth en CE/EE versiones 12.3 y posteriores hasta la versión 13.0.1, permite al usuario no verificado utilizar un flujo del código de autorización de Oauth"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.3, <12.9.8","status":"affected"},{"version":">=12.10, <12.10.7","status":"affected"},{"version":">=13.0, <13.0.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.6,"impactScore":5.9},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-345"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.3.0","versionEndExcluding":"12.9.8","matchCriteriaId":"20079A54-E0D3-4248-B8BE-C595A8D1CFCB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.3.0","versionEndExcluding":"12.9.8","matchCriteriaId":"19FEA888-5326-4B3D-AF45-795F5ED97CB8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.10.0","versionEndExcluding":"12.10.7","matchCriteriaId":"C9ED9593-9837-4849-A890-C2FDDC56C5A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.10.0","versionEndExcluding":"12.10.7","matchCriteriaId":"846CD4C7-BFCB-4DFC-901E-46CCA8ADA56A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:13.0.0:*:*:*:community:*:*:*","matchCriteriaId":"439E1C57-8846-4EB8-A78A-DE6BDAF6CAF5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:13.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"F6CA871C-BEFF-4951-AC88-ACA603C25CE1"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13272.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/37038","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/743556","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13272.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/37038","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/743556","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2020-13273","sourceIdentifier":"cve@gitlab.com","published":"2020-06-19T22:15:12.850","lastModified":"2026-06-17T02:52:50.093","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A Denial of Service vulnerability allowed exhausting the system resources in GitLab CE/EE 12.0 and later through 13.0.1"},{"lang":"es","value":"Una vulnerabilidad de denegación de servicio permitió agotar los recursos del sistema en GitLab CE/EE versiones 12.0 y posteriores hasta la versión 13.0.1"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.0, <12.9.8","status":"affected"},{"version":">=12.10, <12.10.7","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:C","baseScore":7.8,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":6.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.0.0","versionEndExcluding":"12.9.8","matchCriteriaId":"97A44EBE-7B5C-4303-A7D8-AA97CE8C24A8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.0.0","versionEndExcluding":"12.9.8","matchCriteriaId":"BA12BC2B-2ACE-47FE-B82B-AF0A900E55E4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.10.0","versionEndExcluding":"12.10.7","matchCriteriaId":"C9ED9593-9837-4849-A890-C2FDDC56C5A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.10.0","versionEndExcluding":"12.10.7","matchCriteriaId":"846CD4C7-BFCB-4DFC-901E-46CCA8ADA56A"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13273.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/207349","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13273.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/207349","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2020-13274","sourceIdentifier":"cve@gitlab.com","published":"2020-06-19T22:15:12.927","lastModified":"2026-06-17T02:52:50.200","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A security issue allowed achieving Denial of Service attacks through memory exhaustion by uploading malicious artifacts in all previous GitLab versions through 13.0.1"},{"lang":"es","value":"Un problema de seguridad permitió lograr ataques de Denegación de Servicio por medio del agotamiento de la memoria al cargar artefactos maliciosos en todas las versiones anteriores de GitLab hasta la versión 13.0.1"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":"<12.9.8","status":"affected"},{"version":">=12.10, <12.10.7","status":"affected"},{"version":">=13.0, <13.0.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"12.9.8","matchCriteriaId":"5D12F24E-AA18-4BBA-9A00-8CE7B622F599"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"12.9.8","matchCriteriaId":"3D5D493A-5115-481B-B5D6-8A31A6874A9C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.10.0","versionEndExcluding":"12.10.7","matchCriteriaId":"C9ED9593-9837-4849-A890-C2FDDC56C5A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.10.0","versionEndExcluding":"12.10.7","matchCriteriaId":"846CD4C7-BFCB-4DFC-901E-46CCA8ADA56A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:13.0.0:*:*:*:community:*:*:*","matchCriteriaId":"439E1C57-8846-4EB8-A78A-DE6BDAF6CAF5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:13.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"F6CA871C-BEFF-4951-AC88-ACA603C25CE1"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13274.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/14195","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13274.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/14195","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2020-13275","sourceIdentifier":"cve@gitlab.com","published":"2020-06-19T22:15:12.990","lastModified":"2026-06-17T02:52:50.320","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A user with an unverified email address could request an access to domain restricted groups in GitLab EE 12.2 and later through 13.0.1"},{"lang":"es","value":"Un usuario con una dirección de correo electrónico no verificada podría solicitar un acceso a grupos restringidos de dominio en GitLab EE versiones 12.2 y posteriores hasta la versión 13.0.1"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.2, <12.9.8","status":"affected"},{"version":">=12.10, <12.10.7","status":"affected"},{"version":">=13.0, <13.0.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H","baseScore":8.0,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.3,"impactScore":6.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":5.2}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:N","baseScore":5.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.9.8","matchCriteriaId":"F8647F5D-B823-49A8-8BEC-7E462E1FC258"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"12.9.8","matchCriteriaId":"C97D5B7C-28CF-4C8C-8150-F2EA46988996"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.10.0","versionEndExcluding":"12.10.7","matchCriteriaId":"C9ED9593-9837-4849-A890-C2FDDC56C5A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.10.0","versionEndExcluding":"12.10.7","matchCriteriaId":"846CD4C7-BFCB-4DFC-901E-46CCA8ADA56A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:13.0.0:*:*:*:community:*:*:*","matchCriteriaId":"439E1C57-8846-4EB8-A78A-DE6BDAF6CAF5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:13.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"F6CA871C-BEFF-4951-AC88-ACA603C25CE1"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13275.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/209254","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/806255","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13275.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/209254","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/806255","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2020-13276","sourceIdentifier":"cve@gitlab.com","published":"2020-06-19T22:15:13.070","lastModified":"2026-06-17T02:52:50.433","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"User is allowed to set an email as a notification email even without verifying the new email in all previous GitLab CE/EE versions through 13.0.1"},{"lang":"es","value":"El usuario puede establecer un correo electrónico como correo electrónico de notificación incluso sin verificar el nuevo correo electrónico en todas las versiones anteriores de GitLab CE/EE hasta la 13.0.1"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":"<12.9.8","status":"affected"},{"version":">=12.10, <12.10.7","status":"affected"},{"version":">=13.0, <13.0.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L","baseScore":7.4,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":3.1,"impactScore":3.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"12.9.8","matchCriteriaId":"5D12F24E-AA18-4BBA-9A00-8CE7B622F599"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"12.9.8","matchCriteriaId":"3D5D493A-5115-481B-B5D6-8A31A6874A9C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.10.0","versionEndExcluding":"12.10.7","matchCriteriaId":"C9ED9593-9837-4849-A890-C2FDDC56C5A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.10.0","versionEndExcluding":"12.10.7","matchCriteriaId":"846CD4C7-BFCB-4DFC-901E-46CCA8ADA56A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:13.0.0:*:*:*:community:*:*:*","matchCriteriaId":"439E1C57-8846-4EB8-A78A-DE6BDAF6CAF5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:13.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"F6CA871C-BEFF-4951-AC88-ACA603C25CE1"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13276.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/25994","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/471907","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13276.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/25994","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/471907","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2020-13261","sourceIdentifier":"cve@gitlab.com","published":"2020-06-19T23:15:10.163","lastModified":"2026-06-17T02:52:48.680","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Amazon EKS credentials disclosure in GitLab CE/EE 12.6 and later through 13.0.1 allows other administrators to view Amazon EKS credentials via HTML source code"},{"lang":"es","value":"Una divulgación de credenciales de Amazon EKS en GitLab CE/EE versiones 12.6 y posteriores hasta 13.0.1, permite a otros administradores visualizar las credenciales de Amazon EKS por medio del código fuente HTML"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.6, <12.9.8","status":"affected"},{"version":">=12.10, <12.10.7","status":"affected"},{"version":">=13.0, <13.0.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N","baseScore":2.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-200"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.6.0","versionEndExcluding":"12.9.8","matchCriteriaId":"4C0A7ADA-16F4-492B-977B-FEAEAD3EF50D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.6.0","versionEndExcluding":"12.9.8","matchCriteriaId":"207063E3-5E9C-4E67-B064-E7D161C9E5F5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.10.0","versionEndExcluding":"12.10.7","matchCriteriaId":"C9ED9593-9837-4849-A890-C2FDDC56C5A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.10.0","versionEndExcluding":"12.10.7","matchCriteriaId":"846CD4C7-BFCB-4DFC-901E-46CCA8ADA56A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:13.0.0:*:*:*:community:*:*:*","matchCriteriaId":"439E1C57-8846-4EB8-A78A-DE6BDAF6CAF5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:13.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"F6CA871C-BEFF-4951-AC88-ACA603C25CE1"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13261.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/199242","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/784130","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13261.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/199242","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/784130","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2020-13263","sourceIdentifier":"cve@gitlab.com","published":"2020-06-19T23:15:10.240","lastModified":"2026-06-17T02:52:48.910","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An authorization issue relating to project maintainer impersonation was identified in GitLab EE 9.5 and later through 13.0.1 that could allow unauthorized users to impersonate as a maintainer to perform limited actions."},{"lang":"es","value":"Se identificó un problema de autorización relacionado con la suplantación del mantenedor del proyecto en GitLab EE versiones 9.5 y posteriores hasta 13.0.1, que podría permitir a usuarios no autorizados hacerse pasar como mantenedor para llevar a cabo acciones limitadas"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=9.5, <12.9.8","status":"affected"},{"version":">=12.10, <12.10.7","status":"affected"},{"version":">=13.0, <13.0.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.6,"impactScore":5.9},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"9.5.0","versionEndExcluding":"12.9.8","matchCriteriaId":"3A2A35C7-D758-4200-BDF4-4843DA50AC84"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"9.5.0","versionEndExcluding":"12.9.8","matchCriteriaId":"6B9CDEB2-FA16-481B-A9CD-001143E6A44F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.10.0","versionEndExcluding":"12.10.7","matchCriteriaId":"C9ED9593-9837-4849-A890-C2FDDC56C5A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.10.0","versionEndExcluding":"12.10.7","matchCriteriaId":"846CD4C7-BFCB-4DFC-901E-46CCA8ADA56A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:13.0.0:*:*:*:community:*:*:*","matchCriteriaId":"439E1C57-8846-4EB8-A78A-DE6BDAF6CAF5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:13.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"F6CA871C-BEFF-4951-AC88-ACA603C25CE1"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13263.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/211940","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/819821","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13263.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/211940","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/819821","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2020-13264","sourceIdentifier":"cve@gitlab.com","published":"2020-06-19T23:15:10.320","lastModified":"2026-06-17T02:52:49.027","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Kubernetes cluster token disclosure in GitLab CE/EE 10.3 and later through 13.0.1 allows other group maintainers to view Kubernetes cluster token"},{"lang":"es","value":"Una divulgación de token del clúster de Kubernetes en GitLab CE/EE versiones 10.3 y posteriores hasta 13.0.1, permite que otros mantenedores de grupo visualicen el token del clúster de Kubernetes"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=10.3, <12.9.8","status":"affected"},{"version":">=12.10, <12.10.7","status":"affected"},{"version":">=13.0, <13.0.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-200"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.3.0","versionEndExcluding":"12.9.8","matchCriteriaId":"9C6DABE8-23E5-4AD2-A418-B33535C9498B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.3.0","versionEndExcluding":"12.9.8","matchCriteriaId":"1C84573A-BDF6-4FC8-8611-157BA0570591"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.10.0","versionEndExcluding":"12.10.7","matchCriteriaId":"C9ED9593-9837-4849-A890-C2FDDC56C5A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.10.0","versionEndExcluding":"12.10.7","matchCriteriaId":"846CD4C7-BFCB-4DFC-901E-46CCA8ADA56A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:13.0.0:*:*:*:community:*:*:*","matchCriteriaId":"439E1C57-8846-4EB8-A78A-DE6BDAF6CAF5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:13.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"F6CA871C-BEFF-4951-AC88-ACA603C25CE1"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13264.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/55302","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/702796","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13264.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/55302","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/702796","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2020-15525","sourceIdentifier":"cve@mitre.org","published":"2020-07-07T14:15:11.723","lastModified":"2026-06-17T02:56:47.190","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab EE 11.3 through 13.1.2 has Incorrect Access Control because of the Maven package upload endpoint."},{"lang":"es","value":"GitLab EE versiones 11.3 hasta 13.1.2, presenta un Control de Acceso Incorrecto debido al endpoint de carga del paquete Maven"}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.3.0","versionEndIncluding":"13.1.2","matchCriteriaId":"F943FA79-D406-4A84-B4F3-6E43B0722FB6"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2020/07/06/critical-security-release-gitlab-13-1-3-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/categories/releases/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/225259","source":"cve@mitre.org","tags":["Broken Link"]},{"url":"https://about.gitlab.com/releases/2020/07/06/critical-security-release-gitlab-13-1-3-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://about.gitlab.com/releases/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/225259","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2020-13292","sourceIdentifier":"cve@gitlab.com","published":"2020-08-10T14:15:12.813","lastModified":"2026-06-17T02:52:52.247","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In GitLab before 13.0.12, 13.1.6 and 13.2.3, it is possible to bypass E-mail verification which is required for OAuth Flow."},{"lang":"es","value":"En GitLab versiones anteriores a 13.0.12, 13.1.6 y 13.2.3, es posible omitir una comprobación de correo electrónico que es requerido para OAuth Flow"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.3, <13.0.12","status":"affected"},{"version":">=13.1, <13.1.6","status":"affected"},{"version":">=13.2, <13.2.3","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N","baseScore":9.6,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N","baseScore":9.6,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":5.8}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:N","baseScore":5.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-287"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"12.3.0","versionEndExcluding":"13.0.12","matchCriteriaId":"D98FC3E9-8904-4F99-8FB1-CAA2E22C3D96"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.6","matchCriteriaId":"B611BD97-445A-4E3B-B5CB-ED9F1A022603"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.3","matchCriteriaId":"3D425353-E13F-4877-B0CC-B939F4FC9233"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13292.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/228629","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/922456","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13292.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/228629","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/922456","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2020-13293","sourceIdentifier":"cve@gitlab.com","published":"2020-08-10T14:15:12.907","lastModified":"2026-06-17T02:52:52.353","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In GitLab before 13.0.12, 13.1.6 and 13.2.3 using a branch with a hexadecimal name could override an existing hash."},{"lang":"es","value":"En GitLab versiones anteriores a 13.0.12, 13.1.6 y 13.2.3, el uso de una rama con un nombre hexadecimal podría anular un hash existente"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=1.0, <13.0.12","status":"affected"},{"version":">=13.1, <13.1.6","status":"affected"},{"version":">=13.2, <13.2.3","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:L","baseScore":6.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":2.1,"impactScore":4.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":4.2}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:P","baseScore":5.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"1.0.0","versionEndExcluding":"13.0.12","matchCriteriaId":"79210184-C2B7-47BB-86E8-6706DCBDA224"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.6","matchCriteriaId":"B611BD97-445A-4E3B-B5CB-ED9F1A022603"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.3","matchCriteriaId":"3D425353-E13F-4877-B0CC-B939F4FC9233"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13293.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/202690","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/790634","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13293.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/202690","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/790634","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2020-13294","sourceIdentifier":"cve@gitlab.com","published":"2020-08-10T14:15:12.987","lastModified":"2026-06-17T02:52:52.497","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In GitLab before 13.0.12, 13.1.6 and 13.2.3, access grants were not revoked when a user revoked access to an application."},{"lang":"es","value":"En GitLab versiones anteriores a 13.0.12, 13.1.6 y 13.2.3, los otorgamientos de acceso no fueron revocados cuando un usuario revocaba el acceso a una aplicación"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=7.7, <13.0.12","status":"affected"},{"version":">=13.1, <13.1.6","status":"affected"},{"version":">=13.2, <13.2.3","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","baseScore":4.2,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":2.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.5}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:N","baseScore":5.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"7.7.0","versionEndExcluding":"13.0.12","matchCriteriaId":"9A98EAE0-961F-4F12-9C26-D71E4EDF3A66"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.6","matchCriteriaId":"B611BD97-445A-4E3B-B5CB-ED9F1A022603"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.3","matchCriteriaId":"3D425353-E13F-4877-B0CC-B939F4FC9233"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13294.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/26147","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/469728","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13294.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/26147","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/469728","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2020-13288","sourceIdentifier":"cve@gitlab.com","published":"2020-08-12T15:15:12.167","lastModified":"2026-06-17T02:52:51.807","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In GitLab before 13.0.12, 13.1.6, and 13.2.3, a stored XSS vulnerability exists in the CI/CD Jobs page"},{"lang":"es","value":"En GitLab versiones anteriores a 13.0.12, 13.1.6 y 13.2.3, se presenta una vulnerabilidad de tipo XSS almacenada en la página CI/CD Jobs"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.0, <13.0.12","status":"affected"},{"version":">=13.1, <13.1.6","status":"affected"},{"version":">=13.2, <13.2.3","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":4.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N","baseScore":4.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.7,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.0.0","versionEndExcluding":"13.0.12","matchCriteriaId":"D37F3B2C-2703-4FDA-A579-41AD9AA6EBF9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.0.0","versionEndExcluding":"13.0.12","matchCriteriaId":"0563B69A-C09F-495C-884C-85DD316193BD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.6","matchCriteriaId":"DC6A5402-14DA-41D5-8243-A8EA266DB153"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.6","matchCriteriaId":"1919DB61-4D51-44D2-9748-962FDB2FE223"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.3","matchCriteriaId":"E7239ECA-86C0-43B6-A690-D6CABF8A72AD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.3","matchCriteriaId":"E011BE63-A400-4E88-8363-FE2CDDA1D4ED"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13288.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/215538","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/856554","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13288.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/215538","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/856554","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2020-13290","sourceIdentifier":"cve@gitlab.com","published":"2020-08-12T15:15:12.230","lastModified":"2026-06-17T02:52:52.027","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In GitLab before 13.0.12, 13.1.6, and 13.2.3, improper access control was used on the Applications page"},{"lang":"es","value":"En GitLab versiones anteriores a 13.0.12, 13.1.6, y 13.2.3, se usó un control de acceso inadecuado en la página de Aplicaciones"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=8.4, <13.0.12","status":"affected"},{"version":">=13.1, <13.1.6","status":"affected"},{"version":">=13.2, <13.2.3","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:L","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":1.0,"impactScore":6.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-287"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.4.0","versionEndExcluding":"13.0.12","matchCriteriaId":"59192DBB-07E8-4BAA-9225-9A46B8365158"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.4.0","versionEndExcluding":"13.0.12","matchCriteriaId":"160067B1-5EA8-4F8A-96EF-F27B511A706C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.6","matchCriteriaId":"DC6A5402-14DA-41D5-8243-A8EA266DB153"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.6","matchCriteriaId":"1919DB61-4D51-44D2-9748-962FDB2FE223"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.3","matchCriteriaId":"E7239ECA-86C0-43B6-A690-D6CABF8A72AD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.3","matchCriteriaId":"E011BE63-A400-4E88-8363-FE2CDDA1D4ED"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13290.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/32291","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/691477","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13290.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/32291","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/691477","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2020-13291","sourceIdentifier":"cve@gitlab.com","published":"2020-08-12T15:15:12.307","lastModified":"2026-06-17T02:52:52.140","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In GitLab before 13.2.3, project sharing could temporarily allow too permissive access."},{"lang":"es","value":"En GitLab versiones anteriores a 13.2.3, compartir proyectos podría permitir temporalmente un acceso muy permisivo"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.2, <13.2.3","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":5.2}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:N","baseScore":5.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.3","matchCriteriaId":"E7239ECA-86C0-43B6-A690-D6CABF8A72AD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.3","matchCriteriaId":"E011BE63-A400-4E88-8363-FE2CDDA1D4ED"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13291.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/230521","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13291.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/230521","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2020-13280","sourceIdentifier":"cve@gitlab.com","published":"2020-08-13T13:15:16.763","lastModified":"2026-06-17T02:52:50.890","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"For GitLab before 13.0.12, 13.1.6, 13.2.3 a memory exhaustion flaw exists due to excessive logging of an invite email error message."},{"lang":"es","value":"Para GitLab versiones anteriores a 13.0.12, 13.1.6, 13.2.3, se presenta un fallo de agotamiento de memoria debido al registro excesivo de un mensaje de error de un correo electrónico de invitación"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":"<13.0.12","status":"affected"},{"version":">=13.1, <13.1.6","status":"affected"},{"version":">=13.2, <13.2.3","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:N/A:P","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-400"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"13.0.12","matchCriteriaId":"4582FB06-9821-401F-9272-0326C3457B31"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"13.0.12","matchCriteriaId":"4D4AE74E-A837-4624-B76D-1FD30E07B3D0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.6","matchCriteriaId":"DC6A5402-14DA-41D5-8243-A8EA266DB153"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.6","matchCriteriaId":"1919DB61-4D51-44D2-9748-962FDB2FE223"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.3","matchCriteriaId":"E7239ECA-86C0-43B6-A690-D6CABF8A72AD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.3","matchCriteriaId":"E011BE63-A400-4E88-8363-FE2CDDA1D4ED"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13280.json","source":"cve@gitlab.com","tags":["Exploit","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/28291","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13280.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/28291","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2020-13282","sourceIdentifier":"cve@gitlab.com","published":"2020-08-13T13:15:16.840","lastModified":"2026-06-17T02:52:51.113","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"For GitLab before 13.0.12, 13.1.6, 13.2.3 after a group transfer occurs, members from a parent group keep their access level on the subgroup leading to improper access."},{"lang":"es","value":"Para GitLab versiones anteriores a 13.0.12, 13.1.6, 13.2.3 después que ocurre una transferencia de grupo, los miembros de un grupo principal mantienen su nivel de acceso en el subgrupo conllevando a un acceso inapropiado"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=10.5, <13.0.12","status":"affected"},{"version":">=13.1, <13.1.6","status":"affected"},{"version":">=13.2, <13.2.3","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:N","baseScore":3.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":0.5,"impactScore":2.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N","baseScore":3.5,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":0.9,"impactScore":2.5}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:P/I:P/A:N","baseScore":4.9,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":6.8,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-281"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.5.0","versionEndExcluding":"13.0.12","matchCriteriaId":"96B41AA1-3E4A-40D1-BE1B-CE23ABBD7851"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.5.0","versionEndExcluding":"13.0.12","matchCriteriaId":"976E7CE0-9D8F-48BC-AEA5-E31A367350AF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.6","matchCriteriaId":"DC6A5402-14DA-41D5-8243-A8EA266DB153"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.6","matchCriteriaId":"1919DB61-4D51-44D2-9748-962FDB2FE223"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.3","matchCriteriaId":"E7239ECA-86C0-43B6-A690-D6CABF8A72AD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.3","matchCriteriaId":"E011BE63-A400-4E88-8363-FE2CDDA1D4ED"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13282.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/202687","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/790786","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13282.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/202687","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/790786","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2020-13283","sourceIdentifier":"cve@gitlab.com","published":"2020-08-13T13:15:16.920","lastModified":"2026-06-17T02:52:51.223","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"For GitLab before 13.0.12, 13.1.6, 13.2.3 a cross-site scripting vulnerability exists in the issues list via milestone title."},{"lang":"es","value":"Para GitLab versiones anteriores a 13.0.12, 13.1.6, 13.2.3, se presenta una vulnerabilidad de tipo cross-site scripting en la lista de problemas por medio del título milestone"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=10.8","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.8.0","versionEndExcluding":"13.0.12","matchCriteriaId":"87F78E6D-F9C5-4C00-BEC1-AB7B72B72758"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.8.0","versionEndExcluding":"13.0.12","matchCriteriaId":"E191BC72-5AE4-4E4A-AC6A-23BBB0AF9E0D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.6","matchCriteriaId":"DC6A5402-14DA-41D5-8243-A8EA266DB153"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.6","matchCriteriaId":"1919DB61-4D51-44D2-9748-962FDB2FE223"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.3","matchCriteriaId":"E7239ECA-86C0-43B6-A690-D6CABF8A72AD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.3","matchCriteriaId":"E011BE63-A400-4E88-8363-FE2CDDA1D4ED"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13283.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/218448","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/877065","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13283.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/218448","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/877065","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2020-13285","sourceIdentifier":"cve@gitlab.com","published":"2020-08-13T13:15:17.013","lastModified":"2026-06-17T02:52:51.447","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"For GitLab before 13.0.12, 13.1.6, 13.2.3 a cross-site scripting (XSS) vulnerability exists in the issue reference number tooltip."},{"lang":"es","value":"Para GitLab versiones anteriores a 13.0.12, 13.1.6, 13.2.3 se presenta una vulnerabilidad de cross-site scripting (XSS) en el tooltip del número de referencia de la incidencia."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.9, <13.0.12","status":"affected"},{"version":">=13.1, <13.1.6","status":"affected"},{"version":">=13.2, <13.2.3","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.9.0","versionEndExcluding":"13.0.12","matchCriteriaId":"F7A35686-4F33-4601-80F6-5896EF2A4818"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.9.0","versionEndExcluding":"13.0.12","matchCriteriaId":"DBBDF7C7-5E24-4AC3-A6E6-FE750869E508"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.6","matchCriteriaId":"DC6A5402-14DA-41D5-8243-A8EA266DB153"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.6","matchCriteriaId":"1919DB61-4D51-44D2-9748-962FDB2FE223"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.3","matchCriteriaId":"E7239ECA-86C0-43B6-A690-D6CABF8A72AD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.3","matchCriteriaId":"E011BE63-A400-4E88-8363-FE2CDDA1D4ED"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13285.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/212626","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/831962","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13285.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/212626","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/831962","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2020-13281","sourceIdentifier":"cve@gitlab.com","published":"2020-08-13T14:15:20.453","lastModified":"2026-06-17T02:52:51.000","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"For GitLab before 13.0.12, 13.1.6, 13.2.3 a denial of service exists in the project import feature"},{"lang":"es","value":"Para GitLab versiones anteriores a 13.0.12, 13.1.6, 13.2.3, se presenta una denegación de servicio en la funcionalidad project import"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=8.9, <13.0.12","status":"affected"},{"version":">=13.1, <13.1.6","status":"affected"},{"version":">=13.2, <13.2.3","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:N/A:P","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-400"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.9.0","versionEndExcluding":"13.0.12","matchCriteriaId":"42D24A4F-E647-43DF-9355-9B050CA37AD0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.9.0","versionEndExcluding":"13.0.12","matchCriteriaId":"3535F020-05C5-4CDD-9091-AFDE9B47EB0B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.6","matchCriteriaId":"DC6A5402-14DA-41D5-8243-A8EA266DB153"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.6","matchCriteriaId":"1919DB61-4D51-44D2-9748-962FDB2FE223"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.3","matchCriteriaId":"E7239ECA-86C0-43B6-A690-D6CABF8A72AD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.3","matchCriteriaId":"E011BE63-A400-4E88-8363-FE2CDDA1D4ED"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13281.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/31564","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/687730","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13281.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/31564","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/687730","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2020-13286","sourceIdentifier":"cve@gitlab.com","published":"2020-08-13T14:15:20.533","lastModified":"2026-06-17T02:52:51.570","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"For GitLab before 13.0.12, 13.1.6, 13.2.3 user controlled git configuration settings can be modified to result in Server Side Request Forgery."},{"lang":"es","value":"Para GitLab versiones anteriores a 13.0.12, 13.1.6, 13.2.3, los ajustes de configuración de git controlados por el usuario pueden ser modificados para resultar en un ataque de tipo Server Side Request Forgery"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.7.0, <13.0.12","status":"affected"},{"version":">=13.1, <13.1.6","status":"affected"},{"version":">=13.2, <13.2.3","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.7.0","versionEndExcluding":"13.0.12","matchCriteriaId":"3FDA80CC-A783-410E-955F-84B1B95529BF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.7.0","versionEndExcluding":"13.0.12","matchCriteriaId":"7E4003A6-E9BC-4E97-8C16-67648C6C91DD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.6","matchCriteriaId":"DC6A5402-14DA-41D5-8243-A8EA266DB153"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.6","matchCriteriaId":"1919DB61-4D51-44D2-9748-962FDB2FE223"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.3","matchCriteriaId":"E7239ECA-86C0-43B6-A690-D6CABF8A72AD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.3","matchCriteriaId":"E011BE63-A400-4E88-8363-FE2CDDA1D4ED"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13286.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/215212","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/855276","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13286.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/215212","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/855276","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2020-13284","sourceIdentifier":"cve@gitlab.com","published":"2020-09-14T19:15:10.647","lastModified":"2026-06-17T02:52:51.333","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. API Authorization Using Outdated CI Job Token"},{"lang":"es","value":"Se detectó una vulnerabilidad en GitLab versiones anteriores a 13.1.10, 13.2.8 y 13.3.4.&#xa0;Una Autorización de la API Usa un Token de Trabajo de CI Obsoleto"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=11.3, <13.1.10","status":"affected"},{"version":">=13.2, <13.2.8","status":"affected"},{"version":">=13.3, <13.3.4","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":5.2}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:N","baseScore":5.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.10","matchCriteriaId":"6C57CC9D-03EF-4F8C-8CC0-689B297DD258"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.10","matchCriteriaId":"3C4FC79E-B27D-4985-9B5C-CDC65AE26A58"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.8","matchCriteriaId":"44781956-BDA5-4C3D-9458-75168CB71CA3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.8","matchCriteriaId":"1DD1E032-7913-4CAD-9974-1EFC7B468BA8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.4","matchCriteriaId":"CE11E630-53C8-43AF-9F81-EA4AD52D8241"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.4","matchCriteriaId":"5044D423-9351-4840-BAD4-43EFB42FC527"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13284.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/221040","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13284.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/221040","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2020-13287","sourceIdentifier":"cve@gitlab.com","published":"2020-09-14T19:15:10.723","lastModified":"2026-06-17T02:52:51.683","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Project reporters and above could see confidential EPIC attached to confidential issues"},{"lang":"es","value":"Se detectó una vulnerabilidad en GitLab versiones anteriores a 13.1.10, 13.2.8 y 13.3.4.&#xa0;Los reporteros del proyecto y superiores podrían ver un EPIC confidencial adjunto a temas confidenciales"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.0, <13.1.10","status":"affected"},{"version":">=13.2, <13.2.8","status":"affected"},{"version":">=13.3, <13.3.4","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.10","matchCriteriaId":"6C57CC9D-03EF-4F8C-8CC0-689B297DD258"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.10","matchCriteriaId":"3C4FC79E-B27D-4985-9B5C-CDC65AE26A58"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.8","matchCriteriaId":"44781956-BDA5-4C3D-9458-75168CB71CA3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.8","matchCriteriaId":"1DD1E032-7913-4CAD-9974-1EFC7B468BA8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.4","matchCriteriaId":"CE11E630-53C8-43AF-9F81-EA4AD52D8241"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.4","matchCriteriaId":"5044D423-9351-4840-BAD4-43EFB42FC527"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13287.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/227820","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/919468","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13287.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/227820","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/919468","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2020-13289","sourceIdentifier":"cve@gitlab.com","published":"2020-09-14T19:15:10.787","lastModified":"2026-06-17T02:52:51.917","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. In certain cases an invalid username could be accepted when 2FA is activated."},{"lang":"es","value":"Se detectó una vulnerabilidad en GitLab versiones anteriores a 13.1.10, 13.2.8 y 13.3.4.&#xa0;En determinados casos, podría ser aceptado un nombre de usuario no válido cuando se activa 2FA"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=8.7, <13.1.10","status":"affected"},{"version":">=13.2, <13.2.8","status":"affected"},{"version":">=13.3, <13.3.4","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.5}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:N","baseScore":5.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-306"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.10","matchCriteriaId":"6C57CC9D-03EF-4F8C-8CC0-689B297DD258"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.10","matchCriteriaId":"3C4FC79E-B27D-4985-9B5C-CDC65AE26A58"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.8","matchCriteriaId":"44781956-BDA5-4C3D-9458-75168CB71CA3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.8","matchCriteriaId":"1DD1E032-7913-4CAD-9974-1EFC7B468BA8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.4","matchCriteriaId":"CE11E630-53C8-43AF-9F81-EA4AD52D8241"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.4","matchCriteriaId":"5044D423-9351-4840-BAD4-43EFB42FC527"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13289.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/20302","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13289.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/20302","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2020-13299","sourceIdentifier":"cve@gitlab.com","published":"2020-09-14T19:15:10.880","lastModified":"2026-06-17T02:52:54.653","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. The revocation feature was not revoking all session tokens and one could re-use it to obtain a valid session."},{"lang":"es","value":"Se detectó una vulnerabilidad en GitLab versiones anteriores a 13.1.10, 13.2.8 y 13.3.4.&#xa0;La funcionalidad revocation no estaba revocando todos los tokens de sesión y se podían reutilizar para obtener una sesión válida"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=1.0, <13.1.10","status":"affected"},{"version":">=13.2, <13.2.8","status":"affected"},{"version":">=13.3, <13.3.4","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":5.2}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:N","baseScore":5.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-613"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.10","matchCriteriaId":"6C57CC9D-03EF-4F8C-8CC0-689B297DD258"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.10","matchCriteriaId":"3C4FC79E-B27D-4985-9B5C-CDC65AE26A58"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.8","matchCriteriaId":"44781956-BDA5-4C3D-9458-75168CB71CA3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.8","matchCriteriaId":"1DD1E032-7913-4CAD-9974-1EFC7B468BA8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.4","matchCriteriaId":"CE11E630-53C8-43AF-9F81-EA4AD52D8241"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.4","matchCriteriaId":"5044D423-9351-4840-BAD4-43EFB42FC527"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13299.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/222508","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/896225","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13299.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/222508","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/896225","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2020-13300","sourceIdentifier":"cve@gitlab.com","published":"2020-09-14T19:15:10.957","lastModified":"2026-06-17T02:52:54.767","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab CE/EE version 13.3 prior to 13.3.4 was vulnerable to an OAuth authorization scope change without user consent in the middle of the authorization flow."},{"lang":"es","value":"La versión 13.3 de GitLab CE/EE anterior a la 13.3.4 era vulnerable a un cambio de ámbito de autorización OAuth sin el consentimiento del usuario en medio del flujo de autorización"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.3, <13.3.4","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N","baseScore":8.0,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N","baseScore":10.0,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":5.8}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:N","baseScore":6.4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.4","matchCriteriaId":"CE11E630-53C8-43AF-9F81-EA4AD52D8241"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.4","matchCriteriaId":"5044D423-9351-4840-BAD4-43EFB42FC527"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13300.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/219931","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/884766","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13300.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/219931","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/884766","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2020-13316","sourceIdentifier":"cve@gitlab.com","published":"2020-09-14T19:15:11.037","lastModified":"2026-06-17T02:52:56.637","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was not validating a Deploy-Token and allowed a disabled repository be accessible via a git command line."},{"lang":"es","value":"Se detectó una vulnerabilidad en GitLab versiones anteriores a 13.1.10, 13.2.8 y 13.3.4.&#xa0;GitLab no estaba comprobando un Deploy-Token y permitía a un repositorio deshabilitado acceder por medio de una línea de comandos git"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=1.0, <13.1.10","status":"affected"},{"version":">=13.2, <13.2.8","status":"affected"},{"version":">=13.3, <13.3.4","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.10","matchCriteriaId":"6C57CC9D-03EF-4F8C-8CC0-689B297DD258"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.10","matchCriteriaId":"3C4FC79E-B27D-4985-9B5C-CDC65AE26A58"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.8","matchCriteriaId":"44781956-BDA5-4C3D-9458-75168CB71CA3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.8","matchCriteriaId":"1DD1E032-7913-4CAD-9974-1EFC7B468BA8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.4","matchCriteriaId":"CE11E630-53C8-43AF-9F81-EA4AD52D8241"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.4","matchCriteriaId":"5044D423-9351-4840-BAD4-43EFB42FC527"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13316.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/220137","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/884174","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13316.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/220137","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/884174","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2020-13318","sourceIdentifier":"cve@gitlab.com","published":"2020-09-14T19:15:11.113","lastModified":"2026-06-17T02:52:56.863","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability was discovered in GitLab versions before 13.0.12, 13.1.10, 13.2.8 and 13.3.4. GitLabs EKS integration was vulnerable to a cross-account assume role attack."},{"lang":"es","value":"Se detectó una vulnerabilidad en GitLab versiones anteriores a 13.0.12, 13.1.10, 13.2.8 y 13.3.4.&#xa0;La integración EKS de GitLab era vulnerable a un ataque de  tipo cross-account assume role"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.6, <13.0.12","status":"affected"},{"version":">=13.1, <13.1.10","status":"affected"},{"version":">=13.2, <13.2.8","status":"affected"},{"version":">=13.3, <13.3.4","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":5.2}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:P/I:P/A:N","baseScore":4.9,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":6.8,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.0.0","versionEndExcluding":"13.0.12","matchCriteriaId":"D37F3B2C-2703-4FDA-A579-41AD9AA6EBF9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.0.0","versionEndExcluding":"13.0.12","matchCriteriaId":"0563B69A-C09F-495C-884C-85DD316193BD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.10","matchCriteriaId":"6C57CC9D-03EF-4F8C-8CC0-689B297DD258"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.10","matchCriteriaId":"3C4FC79E-B27D-4985-9B5C-CDC65AE26A58"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.8","matchCriteriaId":"44781956-BDA5-4C3D-9458-75168CB71CA3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.8","matchCriteriaId":"1DD1E032-7913-4CAD-9974-1EFC7B468BA8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.4","matchCriteriaId":"CE11E630-53C8-43AF-9F81-EA4AD52D8241"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.4","matchCriteriaId":"5044D423-9351-4840-BAD4-43EFB42FC527"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13318.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/228915","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13318.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/228915","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2020-13311","sourceIdentifier":"cve@gitlab.com","published":"2020-09-14T20:15:11.017","lastModified":"2026-06-17T02:52:56.037","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Wiki was vulnerable to a parser attack that prohibits anyone from accessing the Wiki functionality through the user interface."},{"lang":"es","value":"Se detectó una vulnerabilidad en GitLab versiones anteriores a 13.1.10, 13.2.8 y 13.3.4.&#xa0;Wiki era vulnerable a un ataque del analizador que prohíbe a cualquier persona acceder a la funcionalidad Wiki por medio de la interfaz de usuario"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=1.0, <13.1.10","status":"affected"},{"version":">=13.2, <13.2.8","status":"affected"},{"version":">=13.3, <13.3.4","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:N/A:P","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-706"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.10","matchCriteriaId":"6C57CC9D-03EF-4F8C-8CC0-689B297DD258"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.10","matchCriteriaId":"3C4FC79E-B27D-4985-9B5C-CDC65AE26A58"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.8","matchCriteriaId":"44781956-BDA5-4C3D-9458-75168CB71CA3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.8","matchCriteriaId":"1DD1E032-7913-4CAD-9974-1EFC7B468BA8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.4","matchCriteriaId":"CE11E630-53C8-43AF-9F81-EA4AD52D8241"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.4","matchCriteriaId":"5044D423-9351-4840-BAD4-43EFB42FC527"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13311.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/208682","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/224496","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13311.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/208682","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/224496","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2020-13312","sourceIdentifier":"cve@gitlab.com","published":"2020-09-14T20:15:11.080","lastModified":"2026-06-17T02:52:56.153","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab OAuth endpoint was vulnerable to brute-force attacks through a specific parameter."},{"lang":"es","value":"Se detectó una vulnerabilidad en GitLab versiones anteriores a 13.1.10, 13.2.8 y 13.3.4.&#xa0;El endpoint Oauth de GitLab era vulnerable a unos ataques de fuerza bruta por medio de un parámetro específico"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=7.7, <13.1.10","status":"affected"},{"version":">=13.2, <13.2.8","status":"affected"},{"version":">=13.3, <13.3.4","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":2.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-307"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.10","matchCriteriaId":"6C57CC9D-03EF-4F8C-8CC0-689B297DD258"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.10","matchCriteriaId":"3C4FC79E-B27D-4985-9B5C-CDC65AE26A58"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.8","matchCriteriaId":"44781956-BDA5-4C3D-9458-75168CB71CA3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.8","matchCriteriaId":"1DD1E032-7913-4CAD-9974-1EFC7B468BA8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.4","matchCriteriaId":"CE11E630-53C8-43AF-9F81-EA4AD52D8241"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.4","matchCriteriaId":"5044D423-9351-4840-BAD4-43EFB42FC527"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13312.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/29746","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13312.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/29746","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2020-13313","sourceIdentifier":"cve@gitlab.com","published":"2020-09-14T20:15:11.140","lastModified":"2026-06-17T02:52:56.273","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. An unauthorized project maintainer could edit the subgroup badges due to the lack of authorization control."},{"lang":"es","value":"Se detectó una vulnerabilidad en GitLab versiones anteriores a 13.1.10, 13.2.8 y 13.3.4.&#xa0;Un mantenedor de proyecto no autorizado podría editar las insignias de subgrupo debido a una falta de control de autorización"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=1.0, <13.1.10","status":"affected"},{"version":">=13.2, <13.2.8","status":"affected"},{"version":">=13.3, <13.3.4","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.10","matchCriteriaId":"6C57CC9D-03EF-4F8C-8CC0-689B297DD258"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.10","matchCriteriaId":"3C4FC79E-B27D-4985-9B5C-CDC65AE26A58"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.8","matchCriteriaId":"44781956-BDA5-4C3D-9458-75168CB71CA3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.8","matchCriteriaId":"1DD1E032-7913-4CAD-9974-1EFC7B468BA8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.4","matchCriteriaId":"CE11E630-53C8-43AF-9F81-EA4AD52D8241"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.4","matchCriteriaId":"5044D423-9351-4840-BAD4-43EFB42FC527"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13313.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/118536","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/751264","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13313.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/118536","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/751264","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2020-13314","sourceIdentifier":"cve@gitlab.com","published":"2020-09-14T20:15:11.220","lastModified":"2026-06-17T02:52:56.390","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab Omniauth endpoint allowed a malicious user to submit content to be displayed back to the user within error messages."},{"lang":"es","value":"Se detectó una vulnerabilidad en GitLab versiones anteriores a 13.1.10, 13.2.8 y 13.3.4.&#xa0;El endpoint Omniauth de GitLab permitió a un usuario malicioso enviar contenido para ser mostrado al usuario dentro de los mensajes de error"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=7.1, <13.1.10","status":"affected"},{"version":">=13.2, <13.2.8","status":"affected"},{"version":">=13.3, <13.3.4","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":3.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.10","matchCriteriaId":"6C57CC9D-03EF-4F8C-8CC0-689B297DD258"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.10","matchCriteriaId":"3C4FC79E-B27D-4985-9B5C-CDC65AE26A58"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.8","matchCriteriaId":"44781956-BDA5-4C3D-9458-75168CB71CA3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.8","matchCriteriaId":"1DD1E032-7913-4CAD-9974-1EFC7B468BA8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.4","matchCriteriaId":"CE11E630-53C8-43AF-9F81-EA4AD52D8241"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.4","matchCriteriaId":"5044D423-9351-4840-BAD4-43EFB42FC527"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13314.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/25201","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/438746","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13314.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/25201","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/438746","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2020-13317","sourceIdentifier":"cve@gitlab.com","published":"2020-09-14T20:15:11.297","lastModified":"2026-06-17T02:52:56.750","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8, and 13.3.4. An insufficient check in the GraphQL api allowed a maintainer to delete a repository."},{"lang":"es","value":"Se detectó una vulnerabilidad en GitLab versiones anteriores a 13.1.10, 13.2.8 y 13.3.4.&#xa0;Una comprobación insuficiente en la API GraphQL permitió a un mantenedor eliminar un repositorio"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.6, <13.1.10","status":"affected"},{"version":">=13.2, <13.2.8","status":"affected"},{"version":">=13.3, <13.3.4","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-20"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.10","matchCriteriaId":"6C57CC9D-03EF-4F8C-8CC0-689B297DD258"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.10","matchCriteriaId":"3C4FC79E-B27D-4985-9B5C-CDC65AE26A58"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.8","matchCriteriaId":"44781956-BDA5-4C3D-9458-75168CB71CA3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.8","matchCriteriaId":"1DD1E032-7913-4CAD-9974-1EFC7B468BA8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.4","matchCriteriaId":"CE11E630-53C8-43AF-9F81-EA4AD52D8241"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.4","matchCriteriaId":"5044D423-9351-4840-BAD4-43EFB42FC527"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13317.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/215703","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/858671","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13317.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/215703","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/858671","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2020-13297","sourceIdentifier":"cve@gitlab.com","published":"2020-09-14T22:15:10.787","lastModified":"2026-06-17T02:52:54.367","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. When 2 factor authentication was enabled for groups, a malicious user could bypass that restriction by sending a specific query to the API endpoint."},{"lang":"es","value":"Se detectó una vulnerabilidad en GitLab versiones anteriores a 13.1.10, 13.2.8 y 13.3.4.&#xa0;Cuando era habilitada la autenticación de 2 factores para grupos, un usuario malicioso podría omitir esa restricción mediante el envío de una consulta específica hacia el endpoint de la API"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=1.0, <13.1.10","status":"affected"},{"version":">=13.2, <13.2.8","status":"affected"},{"version":">=13.3, <13.3.4","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N","baseScore":3.8,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":2.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.5}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:P/I:P/A:N","baseScore":4.9,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":6.8,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionEndExcluding":"13.1.10","matchCriteriaId":"5679F06E-96ED-4A34-AF94-2532C22B465B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.8","matchCriteriaId":"724E2186-FCF8-4082-9603-06609EFA4157"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.4","matchCriteriaId":"EBD4843F-FD1E-497A-A95F-B7F4C1B8BDA3"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13297.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/32215","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/691592","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13297.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/32215","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/691592","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2020-13298","sourceIdentifier":"cve@gitlab.com","published":"2020-09-14T22:15:10.863","lastModified":"2026-06-17T02:52:54.533","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Conan package upload functionality was not properly validating the supplied parameters, which resulted in the limited files disclosure."},{"lang":"es","value":"Se detectó una vulnerabilidad en GitLab versiones anteriores a 13.1.10, 13.2.8 y 13.3.4.&#xa0;La funcionalidad de carga de paquetes Conan no validaba correctamente los parámetros suministrados, resultando en la divulgación limitada de archivos"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.3, <13.3.4","status":"affected"},{"version":">=13.2, <13.2.8","status":"affected"},{"version":">=13.1, <13.1.10","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N","baseScore":5.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionEndExcluding":"13.1.10","matchCriteriaId":"5679F06E-96ED-4A34-AF94-2532C22B465B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.8","matchCriteriaId":"724E2186-FCF8-4082-9603-06609EFA4157"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.4","matchCriteriaId":"EBD4843F-FD1E-497A-A95F-B7F4C1B8BDA3"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13298.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/228841","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/923027","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13298.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/228841","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/923027","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2020-13301","sourceIdentifier":"cve@gitlab.com","published":"2020-09-14T22:15:10.927","lastModified":"2026-06-17T02:52:54.877","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was vulnerable to a stored XSS on the standalone vulnerability page."},{"lang":"es","value":"Se detectó una vulnerabilidad en GitLab versiones anteriores a 13.1.10, 13.2.8 y 13.3.4.&#xa0;GitLab era vulnerable a un ataque de tipo XSS almacenado en la página standalone vulnerability"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.10, <13.1.10","status":"affected"},{"version":">=13.2, <13.2.8","status":"affected"},{"version":">=13.3, <13.3.4","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":4.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N","baseScore":4.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.7,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionEndExcluding":"13.1.10","matchCriteriaId":"5679F06E-96ED-4A34-AF94-2532C22B465B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.8","matchCriteriaId":"724E2186-FCF8-4082-9603-06609EFA4157"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.4","matchCriteriaId":"EBD4843F-FD1E-497A-A95F-B7F4C1B8BDA3"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13301.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/219378","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/882988","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13301.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/219378","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/882988","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2020-13302","sourceIdentifier":"cve@gitlab.com","published":"2020-09-14T22:15:10.987","lastModified":"2026-06-17T02:52:54.990","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Under certain conditions GitLab was not properly revoking user sessions and allowed a malicious user to access a user account with an old password."},{"lang":"es","value":"Se detectó una vulnerabilidad en GitLab versiones anteriores a 13.1.10, 13.2.8 y 13.3.4.&#xa0;Bajo determinadas condiciones, GitLab no revocaba apropiadamente las sesiones de usuarios y permitía a un usuario malicioso acceder a una cuenta de usuario con una contraseña antigua"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=7.11, <13.1.10","status":"affected"},{"version":">=13.2, <13.2.8","status":"affected"},{"version":">=13.3, <13.3.4","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N","baseScore":3.8,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":2.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-613"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionEndExcluding":"13.1.10","matchCriteriaId":"5679F06E-96ED-4A34-AF94-2532C22B465B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.8","matchCriteriaId":"724E2186-FCF8-4082-9603-06609EFA4157"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.4","matchCriteriaId":"EBD4843F-FD1E-497A-A95F-B7F4C1B8BDA3"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13302.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/25195","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/437194","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13302.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/25195","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/437194","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2020-13304","sourceIdentifier":"cve@gitlab.com","published":"2020-09-14T22:15:11.067","lastModified":"2026-06-17T02:52:55.210","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Same 2 factor Authentication secret code was generated which resulted an attacker to maintain access under certain conditions."},{"lang":"es","value":"Se detectó una vulnerabilidad en GitLab versiones anteriores a 13.1.10, 13.2.8 y 13.3.4.&#xa0;El mismo código secreto de autenticación de 2 factores era generado, lo que resultaba en que un atacante mantuviera el acceso bajo determinadas condiciones"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=1.0, <13.1.10","status":"affected"},{"version":">=13.2, <13.2.8","status":"affected"},{"version":">=13.3, <13.3.4","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N","baseScore":3.8,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":2.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-330"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionEndExcluding":"13.1.10","matchCriteriaId":"5679F06E-96ED-4A34-AF94-2532C22B465B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.8","matchCriteriaId":"724E2186-FCF8-4082-9603-06609EFA4157"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.4","matchCriteriaId":"EBD4843F-FD1E-497A-A95F-B7F4C1B8BDA3"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13304.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/27686","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/511260","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13304.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/27686","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/511260","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2020-13305","sourceIdentifier":"cve@gitlab.com","published":"2020-09-14T22:15:11.147","lastModified":"2026-06-17T02:52:55.323","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was not invalidating project invitation link upon removing a user from a project."},{"lang":"es","value":"Se detectó una vulnerabilidad en GitLab versiones anteriores a 13.1.10, 13.2.8 y 13.3.4.&#xa0;GitLab no invalidaba el enlace de invitación al proyecto al eliminar a un usuario de un proyecto"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=1.0, <13.1.10","status":"affected"},{"version":">=13.2, <13.2.8","status":"affected"},{"version":">=13.3, <13.3.4","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N","baseScore":3.5,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-613"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionEndExcluding":"13.1.10","matchCriteriaId":"5679F06E-96ED-4A34-AF94-2532C22B465B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.8","matchCriteriaId":"724E2186-FCF8-4082-9603-06609EFA4157"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.4","matchCriteriaId":"EBD4843F-FD1E-497A-A95F-B7F4C1B8BDA3"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13305.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/26801","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/492621","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13305.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/26801","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/492621","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2020-13306","sourceIdentifier":"cve@gitlab.com","published":"2020-09-14T22:15:11.207","lastModified":"2026-06-17T02:52:55.437","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab Webhook feature could be abused to perform denial of service attacks due to the lack of rate limitation."},{"lang":"es","value":"Se detectó una vulnerabilidad en GitLab versiones anteriores a 13.1.10, 13.2.8 y 13.3.4.&#xa0;La funcionalidad Webhook de GitLab podría ser abusada para llevar a cabo ataques de denegación de servicio debido a una falta de limitación de velocidad"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=1.0, <13.1.10","status":"affected"},{"version":">=13.2, <13.2.8","status":"affected"},{"version":">=13.3, <13.3.4","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":3.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.2,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionEndExcluding":"13.1.10","matchCriteriaId":"5679F06E-96ED-4A34-AF94-2532C22B465B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.8","matchCriteriaId":"724E2186-FCF8-4082-9603-06609EFA4157"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.4","matchCriteriaId":"EBD4843F-FD1E-497A-A95F-B7F4C1B8BDA3"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13306.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/223681","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/904134","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13306.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/223681","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/904134","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2020-13309","sourceIdentifier":"cve@gitlab.com","published":"2020-09-14T22:15:11.287","lastModified":"2026-06-17T02:52:55.803","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was vulnerable to a blind SSRF attack through the repository mirroring feature."},{"lang":"es","value":"Se detectó una vulnerabilidad en GitLab versiones anteriores a 13.1.10, 13.2.8 y 13.3.4.&#xa0;GitLab era vulnerable a un ataque de tipo SSRF ciego por medio de la funcionalidad repository mirroring"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=1.0, <13.1.10","status":"affected"},{"version":">=13.2, <13.2.8","status":"affected"},{"version":">=13.3, <13.3.4","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":2.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionEndExcluding":"13.1.10","matchCriteriaId":"5679F06E-96ED-4A34-AF94-2532C22B465B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.8","matchCriteriaId":"724E2186-FCF8-4082-9603-06609EFA4157"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.4","matchCriteriaId":"EBD4843F-FD1E-497A-A95F-B7F4C1B8BDA3"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13309.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/215879","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/860196","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13309.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/215879","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/860196","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2020-13310","sourceIdentifier":"cve@gitlab.com","published":"2020-09-14T22:15:11.347","lastModified":"2026-06-17T02:52:55.917","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability was discovered in GitLab runner versions before 13.1.3, 13.2.3 and 13.3.1. It was possible to make the gitlab-runner process crash by sending malformed queries, resulting in a denial of service."},{"lang":"es","value":"Se detectó una vulnerabilidad en GitLab versiones anteriores a 13.1.3, 13.2.3 y 13.3.1.&#xa0;Era posible hacer que el proceso gitlab-runner se bloqueara mediante el envío de consultas malformadas resultando en una denegación de servicio"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=1.0, <13.1.3","status":"affected"},{"version":">=13.2, <13.2.3","status":"affected"},{"version":">=13.3, <13.3.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:N/A:P","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionEndExcluding":"13.1.3","matchCriteriaId":"83D3CD19-3D8C-40EB-A93E-179A64D5757A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.3","matchCriteriaId":"3D425353-E13F-4877-B0CC-B939F4FC9233"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.1","matchCriteriaId":"BAC83C29-8010-4DCD-9327-DCB8AB8B56A4"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13310.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-runner/-/issues/25857","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/gitlab-runner/-/issues/26819","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13310.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-runner/-/issues/25857","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/gitlab-runner/-/issues/26819","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2020-13315","sourceIdentifier":"cve@gitlab.com","published":"2020-09-14T22:15:11.427","lastModified":"2026-06-17T02:52:56.510","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. The profile activity page was not restricting the amount of results one could request, potentially resulting in a denial of service."},{"lang":"es","value":"Se detectó una vulnerabilidad en GitLab versiones anteriores a 13.1.10, 13.2.8 y 13.3.4.&#xa0;La página profile activity no estaba restringiendo la cantidad de resultados que uno podía requerir, resultando potencialmente en una denegación de servicio"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=11.4, <13.1.10","status":"affected"},{"version":">=13.2, <13.2.8","status":"affected"},{"version":">=13.3, <13.3.4","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":3.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.2,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionEndExcluding":"13.1.10","matchCriteriaId":"5679F06E-96ED-4A34-AF94-2532C22B465B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.8","matchCriteriaId":"724E2186-FCF8-4082-9603-06609EFA4157"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.4","matchCriteriaId":"EBD4843F-FD1E-497A-A95F-B7F4C1B8BDA3"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13315.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/25825","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/463010","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13315.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/25825","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/463010","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2020-13303","sourceIdentifier":"cve@gitlab.com","published":"2020-09-15T13:15:12.330","lastModified":"2026-06-17T02:52:55.097","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Due to improper verification of permissions, an unauthorized user can access a private repository within a public project."},{"lang":"es","value":"Se detectó una vulnerabilidad en GitLab versiones anteriores a 13.1.10, 13.2.8 y 13.3.4.&#xa0;Debido a una comprobación inapropiada de los permisos, un usuario no autorizado puede acceder a un repositorio privado dentro de un proyecto público"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=1.0, <13.1.10","status":"affected"},{"version":">=13.2, <13.2.8","status":"affected"},{"version":">=13.3, <13.3.4","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":4.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-287"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.10","matchCriteriaId":"6C57CC9D-03EF-4F8C-8CC0-689B297DD258"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.10","matchCriteriaId":"3C4FC79E-B27D-4985-9B5C-CDC65AE26A58"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.8","matchCriteriaId":"44781956-BDA5-4C3D-9458-75168CB71CA3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.8","matchCriteriaId":"1DD1E032-7913-4CAD-9974-1EFC7B468BA8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.4","matchCriteriaId":"CE11E630-53C8-43AF-9F81-EA4AD52D8241"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.4","matchCriteriaId":"5044D423-9351-4840-BAD4-43EFB42FC527"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13303.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/238887","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/962231","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13303.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/238887","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/962231","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2020-13307","sourceIdentifier":"cve@gitlab.com","published":"2020-09-15T13:15:12.407","lastModified":"2026-06-17T02:52:55.553","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was not revoking current user sessions when 2 factor authentication was activated allowing a malicious user to maintain their access."},{"lang":"es","value":"Se detectó una vulnerabilidad en GitLab versiones anteriores a 13.1.10, 13.2.8 y 13.3.4.&#xa0;GitLab no revocaba las sesiones de los usuarios actuales cuando se activaba la autenticación de 2 factores, permitiendo a un usuario malicioso mantener su acceso"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=1.0, <13.1.10","status":"affected"},{"version":">=13.2, <13.2.8","status":"affected"},{"version":">=13.3, <13.3.4","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N","baseScore":3.8,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":2.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L","baseScore":4.7,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":1.2,"impactScore":3.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:P/I:P/A:P","baseScore":6.0,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":6.8,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-613"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.10","matchCriteriaId":"6C57CC9D-03EF-4F8C-8CC0-689B297DD258"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.10","matchCriteriaId":"3C4FC79E-B27D-4985-9B5C-CDC65AE26A58"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.8","matchCriteriaId":"44781956-BDA5-4C3D-9458-75168CB71CA3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.8","matchCriteriaId":"1DD1E032-7913-4CAD-9974-1EFC7B468BA8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.4","matchCriteriaId":"CE11E630-53C8-43AF-9F81-EA4AD52D8241"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.4","matchCriteriaId":"5044D423-9351-4840-BAD4-43EFB42FC527"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13307.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/31307","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/676772","source":"cve@gitlab.com","tags":["Patch","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13307.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/31307","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/676772","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2020-13308","sourceIdentifier":"cve@gitlab.com","published":"2020-09-15T13:15:12.470","lastModified":"2026-06-17T02:52:55.683","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. A user without 2 factor authentication enabled could be prohibited from accessing GitLab by being invited into a project that had 2 factor authentication inheritance."},{"lang":"es","value":"Se detectó una vulnerabilidad en GitLab versiones anteriores a 13.1.10, 13.2.8 y 13.3.4.&#xa0;A un usuario sin la autenticación de 2 factores habilitada se le podría prohibir el acceso a GitLab al ser invitado a un proyecto que tenía una herencia de autenticación de 2 factores"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=1.0, <13.1.10","status":"affected"},{"version":">=13.2, <13.2.8","status":"affected"},{"version":">=13.3, <13.3.4","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L","baseScore":2.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":1.2,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L","baseScore":2.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":1.2,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:N/A:P","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-281"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.10","matchCriteriaId":"6C57CC9D-03EF-4F8C-8CC0-689B297DD258"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.10","matchCriteriaId":"3C4FC79E-B27D-4985-9B5C-CDC65AE26A58"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.8","matchCriteriaId":"44781956-BDA5-4C3D-9458-75168CB71CA3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.8","matchCriteriaId":"1DD1E032-7913-4CAD-9974-1EFC7B468BA8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.4","matchCriteriaId":"CE11E630-53C8-43AF-9F81-EA4AD52D8241"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.4","matchCriteriaId":"5044D423-9351-4840-BAD4-43EFB42FC527"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13308.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/29989","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/637675","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13308.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/29989","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/637675","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2020-13296","sourceIdentifier":"cve@gitlab.com","published":"2020-09-30T18:15:19.117","lastModified":"2026-06-17T02:52:52.807","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting versions >=10.7 <13.0.14, >=13.1.0 <13.1.8, >=13.2.0 <13.2.6. Improper Access Control for Deploy Tokens"},{"lang":"es","value":"Se ha detectado un problema en GitLab que afecta a versiones posteriores e incluyendo a 10.7 anteriores a 13.0.14, posteriores e incluyendo a 13.1.0 anteriores a 13.1.8, posteriores e incluyendo a 13.2.0 anteriores a 13.2.6.&#xa0;Un Control de Acceso Inapropiado para los Tokens de Implementación"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=10.7 <13.0.14","status":"affected"},{"version":">=13.1.0 <13.1.8","status":"affected"},{"version":">=13.2.0 <13.2.6","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionEndIncluding":"10.7","matchCriteriaId":"82FAECC7-99D4-4234-BC8F-06BE791F2709"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.0.0","versionEndExcluding":"13.0.14","matchCriteriaId":"89FE6BCE-6E8A-4498-B0B1-5716BF49D2DB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.8","matchCriteriaId":"6FD99B2E-72FA-428B-AD01-C084D62E79CD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.2.6","matchCriteriaId":"F7360C9C-27FC-462B-8939-877583510DA8"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13296.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/235996","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/957459","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13296.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/235996","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/957459","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2020-13319","sourceIdentifier":"cve@gitlab.com","published":"2020-09-30T18:15:19.227","lastModified":"2026-06-17T02:52:56.977","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting versions prior to 13.1.2, 13.0.8 and 12.10.13. Missing permission check for adding time spent on an issue."},{"lang":"es","value":"Se ha detectado un problema en GitLab que afecta a  versiones anteriores a 13.1.2, 13.0.8 y 12.10.13.&#xa0;Una falta de comprobación de permisos para agregar tiempo dedicado a un problema"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=8.16, <12.10.13","status":"affected"},{"version":">=13.0, <13.0.8","status":"affected"},{"version":">=13.1, <13.1.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionEndExcluding":"12.10.13","matchCriteriaId":"EBCF24FA-F5AD-4DAF-AB4B-C6EE47F29804"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.0.0","versionEndExcluding":"13.0.8","matchCriteriaId":"B6B20419-B111-41E2-8752-44D63640C2D7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.2","matchCriteriaId":"DDFEC3A6-60E1-4C86-B200-91320A8BA60D"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13319.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/201806","source":"cve@gitlab.com","tags":["Exploit","Vendor Advisory"]},{"url":"https://hackerone.com/reports/755188","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13319.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/201806","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]},{"url":"https://hackerone.com/reports/755188","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2020-13320","sourceIdentifier":"cve@gitlab.com","published":"2020-09-30T18:15:19.303","lastModified":"2026-06-17T02:52:57.093","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab before version 12.10.13 that allowed a project member with limited permissions to view the project security dashboard."},{"lang":"es","value":"Se detectó un problema en GitLab versiones anteriores a 12.10.13, que permitía a un miembro del proyecto con permisos limitados visualizar el panel de seguridad del proyecto"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.1.0, <13.1.2","status":"affected"},{"version":">=13.0.0, <13.0.8","status":"affected"},{"version":">=12.8, <12.10.13","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionEndExcluding":"12.10.13","matchCriteriaId":"EBCF24FA-F5AD-4DAF-AB4B-C6EE47F29804"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13320.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/215044","source":"cve@gitlab.com","tags":["Exploit","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13320.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/215044","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-13321","sourceIdentifier":"cve@gitlab.com","published":"2020-09-30T18:15:19.380","lastModified":"2026-06-17T02:52:57.200","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability was discovered in GitLab versions prior to 13.1. Username format restrictions could be bypassed allowing for html tags to be added."},{"lang":"es","value":"Se detectó una vulnerabilidad en GitLab versiones anteriores a 13.1.&#xa0;Unas restricciones de formato de nombre de usuario pueden omitidas, permitiendo agregar etiquetas html"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":"<12.10.13","status":"affected"},{"version":">=13.0, <13.0.8","status":"affected"},{"version":">=13.1, <13.1.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L","baseScore":8.3,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":5.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L","baseScore":8.3,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":5.5}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionEndExcluding":"12.10.13","matchCriteriaId":"EBCF24FA-F5AD-4DAF-AB4B-C6EE47F29804"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.0.0","versionEndExcluding":"13.0.8","matchCriteriaId":"B6B20419-B111-41E2-8752-44D63640C2D7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.2","matchCriteriaId":"DDFEC3A6-60E1-4C86-B200-91320A8BA60D"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13321.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/25751","source":"cve@gitlab.com","tags":["Exploit","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13321.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/25751","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-13322","sourceIdentifier":"cve@gitlab.com","published":"2020-09-30T18:15:19.460","lastModified":"2026-06-17T02:52:57.313","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability was discovered in GitLab versions after 12.9. Due to improper verification of permissions, an unauthorized user can create and delete deploy tokens."},{"lang":"es","value":"Se detectó una vulnerabilidad en de GitLab posteriores a 12.9.&#xa0;Debido a una comprobación de permisos inapropiada, un usuario no autorizado puede crear y eliminar tokens de implementación"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.9, <12.10.13","status":"affected"},{"version":">=13.0, <13.0.8","status":"affected"},{"version":">=13.1, <13.1.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.9},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"12.9.0","versionEndExcluding":"12.10.13","matchCriteriaId":"268E01AF-5C34-4F54-830E-25FED5892FF6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.0.0","versionEndExcluding":"13.0.8","matchCriteriaId":"B6B20419-B111-41E2-8752-44D63640C2D7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.2","matchCriteriaId":"DDFEC3A6-60E1-4C86-B200-91320A8BA60D"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13322.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/212469","source":"cve@gitlab.com","tags":["Exploit","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13322.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/212469","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-13323","sourceIdentifier":"cve@gitlab.com","published":"2020-09-30T18:15:19.537","lastModified":"2026-06-17T02:52:57.427","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability was discovered in GitLab versions prior 13.1. Under certain conditions private merge requests could be read via Todos"},{"lang":"es","value":"Se detectó una vulnerabilidad en GitLab versiones anteriores a 13.1.&#xa0;Bajo determinadas condiciones, las peticiones de fusión privadas pueden ser leídas mediante Todos"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=8.5, <12.10.13","status":"affected"},{"version":">=13.0, <13.0.8","status":"affected"},{"version":">=13.1, <13.1.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","baseScore":7.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":4.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","baseScore":7.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":4.0}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"8.5.0","versionEndExcluding":"12.10.13","matchCriteriaId":"FA49EF5E-4565-491E-933F-8B42E8A72200"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.0.0","versionEndExcluding":"13.0.8","matchCriteriaId":"B6B20419-B111-41E2-8752-44D63640C2D7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.2","matchCriteriaId":"DDFEC3A6-60E1-4C86-B200-91320A8BA60D"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13323.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/215175","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13323.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/215175","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2020-13324","sourceIdentifier":"cve@gitlab.com","published":"2020-09-30T18:15:19.617","lastModified":"2026-06-17T02:52:57.537","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability was discovered in GitLab versions prior to 13.1. Under certain conditions the private activity of a user could be exposed via the API."},{"lang":"es","value":"Se detectó una vulnerabilidad en GitLab versiones anteriores a 13.1.&#xa0;En determinadas condiciones, la actividad privada de un usuario podría ser expuesta por medio de la API"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=9.4, <12.10.13","status":"affected"},{"version":">=13.0, <13.0.8","status":"affected"},{"version":">=13.1, <13.1.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:P/I:N/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"9.4.0","versionEndExcluding":"12.10.13","matchCriteriaId":"D4CF0299-5FC5-4C1F-BBE1-BD43ACAAB1B7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.0.0","versionEndExcluding":"13.0.8","matchCriteriaId":"B6B20419-B111-41E2-8752-44D63640C2D7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.2","matchCriteriaId":"DDFEC3A6-60E1-4C86-B200-91320A8BA60D"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13324.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/24542","source":"cve@gitlab.com","tags":["Exploit","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13324.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/24542","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-13325","sourceIdentifier":"cve@gitlab.com","published":"2020-09-30T18:15:19.693","lastModified":"2026-06-17T02:52:57.663","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability was discovered in GitLab versions prior 13.1. The comment section of the issue page was not restricting the characters properly, potentially resulting in a denial of service."},{"lang":"es","value":"Se detectó una vulnerabilidad en GitLab versiones anteriores a 13.1.&#xa0;La sección de comentarios de la página de problemas no restringía los personajes apropiadamente, resultando en una denegación de servicio"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.9, <12.10.13","status":"affected"},{"version":">=13.0, <13.0.8","status":"affected"},{"version":">=13.1, <13.1.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":4.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":4.2}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:P","baseScore":5.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"12.9.0","versionEndExcluding":"12.10.13","matchCriteriaId":"268E01AF-5C34-4F54-830E-25FED5892FF6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.0.0","versionEndExcluding":"13.0.8","matchCriteriaId":"B6B20419-B111-41E2-8752-44D63640C2D7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.2","matchCriteriaId":"DDFEC3A6-60E1-4C86-B200-91320A8BA60D"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13325.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/215978","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13325.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/215978","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-13326","sourceIdentifier":"cve@gitlab.com","published":"2020-09-30T18:15:19.773","lastModified":"2026-06-17T02:52:57.770","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability was discovered in GitLab versions prior to 13.1. Under certain conditions the restriction for Github project import could be bypassed."},{"lang":"es","value":"Se detectó una vulnerabilidad en GitLab versiones anteriores a 13.1.&#xa0;Bajo determinadas condiciones, la restricción para la importación de proyectos de Github podrían ser omitidas"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=11.8, <12.10.13","status":"affected"},{"version":">=13.0, <13.0.8","status":"affected"},{"version":">=13.1, <13.1.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"12.10.13","matchCriteriaId":"1482F89E-BF7F-4ADB-83A8-D81E1AFEB508"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.0.0","versionEndExcluding":"13.0.8","matchCriteriaId":"B6B20419-B111-41E2-8752-44D63640C2D7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.2","matchCriteriaId":"DDFEC3A6-60E1-4C86-B200-91320A8BA60D"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13326.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/27221","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13326.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/27221","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2020-13328","sourceIdentifier":"cve@gitlab.com","published":"2020-09-30T18:15:19.833","lastModified":"2026-06-17T02:52:58.007","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting versions prior to 13.1.2, 13.0.8 and 12.10.13. GitLab was vulnerable to a stored XSS by using the PyPi files API."},{"lang":"es","value":"Se ha detectado un problema en GitLab que afecta a versiones anteriores a 13.1.2, 13.0.8 y 12.10.13.&#xa0;GitLab era vulnerable a un ataque de tipo XSS almacenado por medio del uso de la API de archivos PyPi"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.0, <12.10.13","status":"affected"},{"version":">=13.0, <13.0.8","status":"affected"},{"version":">=13.1, <13.1.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N","baseScore":4.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.7,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N","baseScore":4.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.7,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"12.0.0","versionEndExcluding":"12.10.13","matchCriteriaId":"BCDC19B4-F488-4EDB-BFF2-748222D7E8CC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.0.0","versionEndExcluding":"13.0.8","matchCriteriaId":"B6B20419-B111-41E2-8752-44D63640C2D7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.2","matchCriteriaId":"DDFEC3A6-60E1-4C86-B200-91320A8BA60D"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13328.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/215640","source":"cve@gitlab.com","tags":["Exploit","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13328.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/215640","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-13329","sourceIdentifier":"cve@gitlab.com","published":"2020-09-30T18:15:19.913","lastModified":"2026-06-17T02:52:58.120","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting versions from 12.6.2 prior to 12.10.13. GitLab was vulnerable to a stored XSS by in the blob view feature."},{"lang":"es","value":"Se ha detectado un problema en GitLab que afecta a versiones de 12.6.2 anteriores a 12.10.13.&#xa0;GitLab era vulnerable a un ataque de tipo XSS almacenado en la funcionalidad blob view"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.6.2, <12.10.13","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":2.3,"impactScore":3.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":2.3,"impactScore":3.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionEndExcluding":"12.6.2","matchCriteriaId":"D7165069-E6D1-4F5E-858C-A1FEAA45F7C6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"12.10.0","versionEndExcluding":"12.10.13","matchCriteriaId":"769EF352-9467-45CD-A39A-B31770341B23"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13329.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/208685","source":"cve@gitlab.com","tags":["Exploit","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13329.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/208685","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-13330","sourceIdentifier":"cve@gitlab.com","published":"2020-09-30T18:15:19.990","lastModified":"2026-06-17T02:52:58.230","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting versions prior to 12.10.13. GitLab was vulnerable to a stored XSS in import the Bitbucket project feature."},{"lang":"es","value":"Se ha detectado un problema en GitLab que afecta a versiones anteriores a 12.10.13.&#xa0;GitLab era vulnerable a un ataque de tipo XSS almacenado al importar la funcionalidad de proyecto Bitbucket"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=11.2, <12.10.13","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":4.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.3,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionEndIncluding":"11.2.0","matchCriteriaId":"C4E4A6BD-F1A3-49C9-AA1A-AB5491DC9E1E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"12.10.0","versionEndExcluding":"12.10.13","matchCriteriaId":"769EF352-9467-45CD-A39A-B31770341B23"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13330.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/issues/30017","source":"cve@gitlab.com","tags":["Exploit","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13330.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/issues/30017","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-13331","sourceIdentifier":"cve@gitlab.com","published":"2020-09-30T18:15:20.083","lastModified":"2026-06-17T02:52:58.340","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting versions prior to 12.10.13. GitLab was vulnerable to a stored XSS by in the Wiki pasges."},{"lang":"es","value":"Se ha detectado un problema en GitLab que afecta a versiones anteriores a 12.10.13.&#xa0;GitLab era vulnerable a un ataque de tipo XSS almacenado mediante los pasajes de Wiki"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":"<12.10.13","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionEndExcluding":"12.10.13","matchCriteriaId":"EBCF24FA-F5AD-4DAF-AB4B-C6EE47F29804"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13331.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/219010","source":"cve@gitlab.com","tags":["Exploit","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13331.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/219010","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-13336","sourceIdentifier":"cve@gitlab.com","published":"2020-09-30T21:15:12.730","lastModified":"2026-06-17T02:52:58.820","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting versions from 11.8 before 12.10.13. GitLab was vulnerable to a stored XSS by in the error tracking feature."},{"lang":"es","value":"Se ha detectado un problema en GitLab que afecta a las versiones 11.8 anteriores a 12.10.13.&#xa0;GitLab era susceptible a una vulnerabilidad de tipo XSS almacenado en la funcionalidad error tracking"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=11.8, <12.10.13","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:N","baseScore":4.0,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.0,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N","baseScore":4.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.7,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"12.10.13","matchCriteriaId":"ACE19048-6379-45A9-939F-A35C1FA55F7A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"12.10.13","matchCriteriaId":"0924F68B-B129-415D-AF08-BBF08874F4F8"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13336.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/215970","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13336.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/215970","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2020-13337","sourceIdentifier":"cve@gitlab.com","published":"2020-10-02T20:15:12.393","lastModified":"2026-06-17T02:52:58.930","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting versions from 12.10 to 12.10.12 that allowed for a stored XSS payload to be added as a group name."},{"lang":"es","value":"Se ha detectado un problema en GitLab que afecta a las versiones de 12.10 hasta 12.10.12, que permitía que una carga útil de tipo XSS almacenado sea agregada como un nombre de grupo"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.10, <12.10.13","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.9},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N","baseScore":4.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.7,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.10.0","versionEndExcluding":"12.10.12","matchCriteriaId":"A5787CC0-3D64-4B6F-B390-E6D71A20FF3B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.10.0","versionEndExcluding":"12.10.12","matchCriteriaId":"4ADE3104-F846-46EF-803A-667C0653885A"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13337.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/199049","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13337.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/199049","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2020-13338","sourceIdentifier":"cve@gitlab.com","published":"2020-10-02T20:15:12.470","lastModified":"2026-06-17T02:52:59.040","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting versions prior to 12.10.13, 13.0.8, 13.1.2. A stored cross-site scripting vulnerability was discovered when editing references."},{"lang":"es","value":"Se ha detectado un problema en GitLab que afecta a versiones anteriores a 12.10.13, 13.0.8, 13.1.2.&#xa0;Se detectó una vulnerabilidad de tipo cross-site scripting almacenado cuando se editan referencias"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=8.10.0, <12.10.13","status":"affected"},{"version":">=13.0, <13.0.8","status":"affected"},{"version":">=13.1, <13.1.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.10.0","versionEndExcluding":"12.10.13","matchCriteriaId":"44B1D7E7-35A3-4855-9E33-BC991BE6A6B0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.10.0","versionEndExcluding":"12.10.13","matchCriteriaId":"E7F08570-76D9-4A40-A1A7-2A2AF5D8EF78"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.0.0","versionEndExcluding":"13.0.8","matchCriteriaId":"6C2D99CC-CB24-43D8-A231-C76A2DAE1CFA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.0.0","versionEndExcluding":"13.0.8","matchCriteriaId":"21BF96AA-827E-4CB3-943B-478C141917D2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.2","matchCriteriaId":"51809B8F-141D-43B9-BAC5-328E9F4DD7BF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.1.2","matchCriteriaId":"54A7E410-0F0C-414A-98AA-C3DA9B5191A5"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13338.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/213273","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13338.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/213273","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2020-13333","sourceIdentifier":"cve@gitlab.com","published":"2020-10-06T19:15:13.257","lastModified":"2026-06-17T02:52:58.463","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A potential DOS vulnerability was discovered in GitLab versions 13.1, 13.2 and 13.3. The api to update an asset as a link from a release had a regex check which caused exponential number of backtracks for certain user supplied values resulting in high CPU usage."},{"lang":"es","value":"Se detectó una potencial vulnerabilidad de DOS en GitLab versiones 13.1, 13.2 y 13.3.&#xa0;La API para actualizar un activo como un enlace desde una versión que tenía una comprobación de expresiones regulares que causó un número exponencial de retrocesos para determinados valores suministrados por el usuario, resultando en un alto uso de la CPU"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.1, <13.2.10","status":"affected"},{"version":">=13.3.0, <13.3.7","status":"affected"},{"version":">=13.4.0, <13.4.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:N/A:P","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-400"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:13.1.0:*:*:*:community:*:*:*","matchCriteriaId":"2FBE37DE-E9C5-40DC-8339-200551D68184"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:13.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"89B666E9-BE49-44A5-8FE0-1DF2A370A983"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:13.2.0:*:*:*:community:*:*:*","matchCriteriaId":"82900A58-AAF4-4D9C-A91A-3C86DE7A46F4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:13.2.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"F7C9C545-5519-492A-81D7-AC1EC365167A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:13.3.0:*:*:*:community:*:*:*","matchCriteriaId":"3A4E3640-AED5-4318-85B9-91F41264FB09"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:13.3.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"1CF330C9-F018-4F2C-B673-8A38B9434C99"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13333.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/218753","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/870820","source":"cve@gitlab.com","tags":["Exploit","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13333.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/218753","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/870820","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2020-13343","sourceIdentifier":"cve@gitlab.com","published":"2020-10-06T19:15:13.320","lastModified":"2026-06-17T02:52:59.613","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 11.2. Unauthorized Users Can View Custom Project Template"},{"lang":"es","value":"Se ha detectado un problema en GitLab que afecta a todas las versiones a partir de la 11.2.&#xa0;Los Usuarios No Autorizados pueden Visualizar la Plantilla de Proyecto Personalizada"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=11.2, <13.2.10","status":"affected"},{"version":">=13.3.0, <13.3.7","status":"affected"},{"version":">=13.4.0, <13.4.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.6,"impactScore":5.9},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-668"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.2.0","versionEndIncluding":"13.4.3","matchCriteriaId":"E39E490B-C1F6-446B-944E-EFF211B16BA6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.2.0","versionEndIncluding":"13.4.3","matchCriteriaId":"25F45B80-2015-40A3-B7E3-EE37CC6393F5"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13343.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/14861","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/689314","source":"cve@gitlab.com","tags":["Exploit","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13343.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/14861","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/689314","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2020-13345","sourceIdentifier":"cve@gitlab.com","published":"2020-10-06T19:15:13.417","lastModified":"2026-06-17T02:52:59.847","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 10.8. Reflected XSS on Multiple Routes"},{"lang":"es","value":"Se ha detectado un problema en GitLab que afecta a todas las versiones a partir de la 10.8.&#xa0;Un vulnerabilidad de tipo XSS reflejado en Múltiples Rutas"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=10.8, <13.2.10","status":"affected"},{"version":">=13.3.0, <13.3.7","status":"affected"},{"version":">=13.4.0, <13.4.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":2.1,"impactScore":3.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.8.0","versionEndExcluding":"13.2.10","matchCriteriaId":"8E89BB6C-E3B7-441D-9416-08FB408D8AB6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.8.0","versionEndExcluding":"13.2.10","matchCriteriaId":"ACC0DB27-83B5-4E81-BF03-64D9994873FC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.7","matchCriteriaId":"7FFA9C80-2AE2-4B82-9CFC-3324B0865BE0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.7","matchCriteriaId":"D21B677B-F35D-4448-AE7A-6EE4FE757DB7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.4.0","versionEndExcluding":"13.4.2","matchCriteriaId":"BC792133-E5C7-44D0-8553-32BC175077A8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.4.0","versionEndExcluding":"13.4.2","matchCriteriaId":"E592579D-2152-4A79-8AEC-21D2119FB7E7"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13345.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/232829","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/946728","source":"cve@gitlab.com","tags":["Exploit","Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13345.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/232829","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/946728","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2020-13334","sourceIdentifier":"cve@gitlab.com","published":"2020-10-07T14:15:11.607","lastModified":"2026-06-17T02:52:58.580","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, improper authorization checks allow a non-member of a project/group to change the confidentiality attribute of issue via mutation GraphQL query"},{"lang":"es","value":"En GitLab versiones anteriores a 13.2.10, 13.3.7 y 13.4.2, unas comprobaciones inapropiadas de autorización permiten a un no miembro de un proyecto y de un grupo cambiar el atributo de confidencialidad del problema por medio de una consulta GraphQL de mutación"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=8.6, <13.2.10","status":"affected"},{"version":">=13.3.0, <13.3.7","status":"affected"},{"version":">=13.4.0, <13.4.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.6.0","versionEndExcluding":"13.2.10","matchCriteriaId":"EF379E1E-A919-4A64-9A21-4F9AD7881FB8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.6.0","versionEndExcluding":"13.2.10","matchCriteriaId":"CAEE8EFC-3089-4A72-8F26-375540F6E986"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.7","matchCriteriaId":"7FFA9C80-2AE2-4B82-9CFC-3324B0865BE0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.7","matchCriteriaId":"D21B677B-F35D-4448-AE7A-6EE4FE757DB7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.4.0","versionEndExcluding":"13.4.2","matchCriteriaId":"BC792133-E5C7-44D0-8553-32BC175077A8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.4.0","versionEndExcluding":"13.4.2","matchCriteriaId":"E592579D-2152-4A79-8AEC-21D2119FB7E7"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13334.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/195327","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/762271","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13334.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/195327","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/762271","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2020-13335","sourceIdentifier":"cve@gitlab.com","published":"2020-10-07T14:15:11.670","lastModified":"2026-06-17T02:52:58.707","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Improper group membership validation when deleting a user account in GitLab >=7.12 allows a user to delete own account without deleting/transferring their group."},{"lang":"es","value":"Una comprobación inapropiada de la membresía de un grupo al eliminar una cuenta de usuario en GitLab versiones posteriores e incluyendo a 7.12, permite a un usuario eliminar su propia cuenta sin eliminar y transferir su grupo"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=7.12, <13.2.10","status":"affected"},{"version":">=13.3.0, <13.3.7","status":"affected"},{"version":">=13.4.0, <13.4.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"7.12.0","versionEndExcluding":"13.2.10","matchCriteriaId":"7B51EB70-225A-4E07-9864-F782976A0BDC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"7.12.0","versionEndExcluding":"13.2.10","matchCriteriaId":"A77A8F03-B0C3-4588-B146-304EEA44671D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.7","matchCriteriaId":"7FFA9C80-2AE2-4B82-9CFC-3324B0865BE0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.7","matchCriteriaId":"D21B677B-F35D-4448-AE7A-6EE4FE757DB7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.4.0","versionEndExcluding":"13.4.2","matchCriteriaId":"BC792133-E5C7-44D0-8553-32BC175077A8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.4.0","versionEndExcluding":"13.4.2","matchCriteriaId":"E592579D-2152-4A79-8AEC-21D2119FB7E7"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13335.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/27231","source":"cve@gitlab.com","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/503823","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13335.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/27231","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/503823","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2020-13346","sourceIdentifier":"cve@gitlab.com","published":"2020-10-07T14:15:11.747","lastModified":"2026-06-17T02:52:59.963","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Membership changes are not reflected in ToDo subscriptions in GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, allowing guest users to access confidential issues through API."},{"lang":"es","value":"Unos cambios de membresía no están reflejados en las suscripciones ToDo en GitLab versiones anteriores a 13.2.10, 13.3.7 y 13.4.2, permitiendo a usuarios invitados acceder a problemas confidenciales por medio de la API"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=11.2, <13.2.10","status":"affected"},{"version":">=13.3.0, <13.3.7","status":"affected"},{"version":">=13.4.0, <13.4.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-459"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.2.0","versionEndExcluding":"13.2.10","matchCriteriaId":"20FBFDF8-7AB9-49A0-9BE7-8A2F1E689B12"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.2.0","versionEndExcluding":"13.2.10","matchCriteriaId":"02DFDA88-C1C9-4DA5-B1F3-0039F3255712"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.7","matchCriteriaId":"7FFA9C80-2AE2-4B82-9CFC-3324B0865BE0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.7","matchCriteriaId":"D21B677B-F35D-4448-AE7A-6EE4FE757DB7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.4.0","versionEndExcluding":"13.4.2","matchCriteriaId":"BC792133-E5C7-44D0-8553-32BC175077A8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.4.0","versionEndExcluding":"13.4.2","matchCriteriaId":"E592579D-2152-4A79-8AEC-21D2119FB7E7"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13346.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/219496","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/880863","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13346.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/219496","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/880863","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2020-13347","sourceIdentifier":"cve@gitlab.com","published":"2020-10-07T14:15:11.827","lastModified":"2026-06-17T02:53:00.080","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A command injection vulnerability was discovered in Gitlab runner versions prior to 13.2.4, 13.3.2 and 13.4.1. When the runner is configured on a Windows system with a docker executor, which allows the attacker to run arbitrary commands on Windows host, via DOCKER_AUTH_CONFIG build variable."},{"lang":"es","value":"Se detectó una vulnerabilidad de inyección de comandos en el ejecutor de Gitlab versiones anteriores a 13.2.4, 13.3.2 y 13.4.1.&#xa0;Cuando el ejecutor está configurado en un sistema Windows con un ejecutor docker, permitiendo al atacante ejecutar comandos arbitrarios en el host de Windows, por medio de la variable de compilación DOCKER_AUTH_CONFIG"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab Runner","versions":[{"version":">=12.0.0, <13.2.4","status":"affected"},{"version":">=13.3.0, <13.3.2","status":"affected"},{"version":">=13.4.0, <13.4.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.3,"impactScore":6.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.3,"impactScore":6.0}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:C/I:C/A:C","baseScore":9.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.0,"impactScore":10.0,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-22"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.0.0","versionEndExcluding":"13.2.4","matchCriteriaId":"CA7D66F8-0E12-4063-83C1-06CBCD8D0001"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.0.0","versionEndExcluding":"13.2.4","matchCriteriaId":"51687A1F-1E2E-4FCF-AA2F-4B5800F53996"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.2","matchCriteriaId":"F87394D4-69DE-4BFB-A83E-5D5AB69A4393"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.2","matchCriteriaId":"A201A36B-5D81-4D1D-BE92-F06CD9009C4F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.4.0","versionEndExcluding":"13.4.1","matchCriteriaId":"2FEB2D55-423B-4CE6-9A38-CFABD960DBDF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.4.0","versionEndExcluding":"13.4.1","matchCriteriaId":"D28DF4FF-6C22-4212-9889-83997BE787D9"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13347.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-runner/-/issues/26725","source":"cve@gitlab.com","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/955016","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13347.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-runner/-/issues/26725","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/955016","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2020-13342","sourceIdentifier":"cve@gitlab.com","published":"2020-10-07T16:15:16.047","lastModified":"2026-06-17T02:52:59.500","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting versions prior to 13.2.10, 13.3.7 and 13.4.2: Lack of Rate Limiting at Re-Sending Confirmation Email"},{"lang":"es","value":"Se ha detectado un problema en GitLab que afecta a las versiones anteriores a 13.2.10, 13.3.7 y 13.4.2: Una Falta de Límitación de Velocidad en el Reenvío del Email de Confirmación"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=10.1.0, <13.2.10","status":"affected"},{"version":">=13.3, <13.3.7","status":"affected"},{"version":">=13.4, <13.4.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L","baseScore":2.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":1.2,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L","baseScore":2.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":1.2,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:N/A:P","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.1.0","versionEndExcluding":"13.2.10","matchCriteriaId":"87A3692E-CB25-4D16-8E72-023D90FDD557"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.1.0","versionEndExcluding":"13.2.10","matchCriteriaId":"9A279ABA-C91D-496F-81CC-DF91C02E21C6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.7","matchCriteriaId":"7FFA9C80-2AE2-4B82-9CFC-3324B0865BE0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.7","matchCriteriaId":"D21B677B-F35D-4448-AE7A-6EE4FE757DB7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.4.0","versionEndExcluding":"13.4.2","matchCriteriaId":"BC792133-E5C7-44D0-8553-32BC175077A8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.4.0","versionEndExcluding":"13.4.2","matchCriteriaId":"E592579D-2152-4A79-8AEC-21D2119FB7E7"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13342.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/222966","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13342.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/222966","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2020-13339","sourceIdentifier":"cve@gitlab.com","published":"2020-10-08T14:15:11.670","lastModified":"2026-06-17T02:52:59.153","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions before 13.2.10, 13.3.7 and 13.4.2: XSS in SVG File Preview. Overall impact is limited due to the current user only being impacted."},{"lang":"es","value":"Se ha detectado un problema en GitLab afectando a todas las versiones anteriores a 13.2.10, 13.3.7 y 13.4.2:  Una vulnerabilidad de tipo XSS en SVG File Preview.&#xa0;El impacto general es limitado debido a que solo el usuario actual esta siendo impactado"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.10, <13.2.10","status":"affected"},{"version":">=13.3, <13.3.7","status":"affected"},{"version":">=13.4, <13.4.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":1.3,"impactScore":3.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":2.3,"impactScore":3.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:P/I:P/A:P","baseScore":6.0,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":6.8,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"13.2.10","matchCriteriaId":"88546E39-836D-4F9B-9809-AD7F0D6AF38C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"13.2.10","matchCriteriaId":"2E09C6B1-AA17-4FAC-91DC-C71F829A8AEF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.7","matchCriteriaId":"7FFA9C80-2AE2-4B82-9CFC-3324B0865BE0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.7","matchCriteriaId":"D21B677B-F35D-4448-AE7A-6EE4FE757DB7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.4.0","versionEndExcluding":"13.4.2","matchCriteriaId":"BC792133-E5C7-44D0-8553-32BC175077A8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.4.0","versionEndExcluding":"13.4.2","matchCriteriaId":"E592579D-2152-4A79-8AEC-21D2119FB7E7"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13339.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/118477","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/758653","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13339.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/118477","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/758653","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2020-13340","sourceIdentifier":"cve@gitlab.com","published":"2020-10-08T14:15:11.780","lastModified":"2026-06-17T02:52:59.270","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2: Stored XSS in CI Job Log"},{"lang":"es","value":"Se ha detectado un problema en GitLab afectando a todas las versiones anteriores a 13.2.10, 13.3.7 y 13.4.2: Una vulnerabilidad de tipo XSS almacenado en CI Job Log"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.4, <13.2.10","status":"affected"},{"version":">=13.3, <13.3.7","status":"affected"},{"version":">=13.4, <13.4.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":5.8}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"13.2.10","matchCriteriaId":"88546E39-836D-4F9B-9809-AD7F0D6AF38C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"13.2.10","matchCriteriaId":"2E09C6B1-AA17-4FAC-91DC-C71F829A8AEF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.7","matchCriteriaId":"7FFA9C80-2AE2-4B82-9CFC-3324B0865BE0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.7","matchCriteriaId":"D21B677B-F35D-4448-AE7A-6EE4FE757DB7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.4.0","versionEndExcluding":"13.4.2","matchCriteriaId":"BC792133-E5C7-44D0-8553-32BC175077A8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.4.0","versionEndExcluding":"13.4.2","matchCriteriaId":"E592579D-2152-4A79-8AEC-21D2119FB7E7"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13340.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/233473","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/950190","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13340.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/233473","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/950190","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2020-13344","sourceIdentifier":"cve@gitlab.com","published":"2020-10-08T14:15:12.170","lastModified":"2026-06-17T02:52:59.730","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2. Sessions keys are stored in plain-text in Redis which allows attacker with Redis access to authenticate as any user that has a session stored in Redis"},{"lang":"es","value":"Se ha detectado un problema en GitLab afectando a todas las versiones anteriores a 13.2.10, 13.3.7 y 13.4.2.&#xa0;Las claves de las sesiones son almacenadas en texto plano en Redis, lo que permite al atacante con acceso a Redis autenticarse como cualquier usuario que tenga una sesión almacenada en Redis"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=10.8, <13.2.10","status":"affected"},{"version":">=13.3.0, <13.3.7","status":"affected"},{"version":">=13.4.0, <13.4.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N","baseScore":5.7,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":0.5,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","baseScore":4.4,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":0.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:N/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-522"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.8.0","versionEndExcluding":"13.2.10","matchCriteriaId":"8E89BB6C-E3B7-441D-9416-08FB408D8AB6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.8.0","versionEndExcluding":"13.2.10","matchCriteriaId":"ACC0DB27-83B5-4E81-BF03-64D9994873FC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.7","matchCriteriaId":"7FFA9C80-2AE2-4B82-9CFC-3324B0865BE0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.7","matchCriteriaId":"D21B677B-F35D-4448-AE7A-6EE4FE757DB7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.4.0","versionEndExcluding":"13.4.2","matchCriteriaId":"BC792133-E5C7-44D0-8553-32BC175077A8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.4.0","versionEndExcluding":"13.4.2","matchCriteriaId":"E592579D-2152-4A79-8AEC-21D2119FB7E7"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13344.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/17817","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13344.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/17817","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2020-13341","sourceIdentifier":"cve@gitlab.com","published":"2020-10-12T14:15:12.090","lastModified":"2026-06-17T02:52:59.383","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2. Insufficient permission check allows attacker with developer role to perform various deletions."},{"lang":"es","value":"Se ha detectado un problema en GitLab afectando a todas las versiones anteriores a 13.2.10, 13.3.7 y 13.4.2.&#xa0;Una comprobación insuficiente de permisos permite a un atacante con rol de desarrollador llevar a cabo varias eliminaciones"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.1, <13.2.10","status":"affected"},{"version":">=13.3, <13.3.7","status":"affected"},{"version":">=13.4, <13.4.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-843"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.2.10","matchCriteriaId":"6C70DB0C-8948-49A3-8B44-B40F6ECF122A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.2.10","matchCriteriaId":"93D2C778-1A69-447C-B564-2880E062FD8D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.7","matchCriteriaId":"7FFA9C80-2AE2-4B82-9CFC-3324B0865BE0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.7","matchCriteriaId":"D21B677B-F35D-4448-AE7A-6EE4FE757DB7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.4.0","versionEndExcluding":"13.4.2","matchCriteriaId":"BC792133-E5C7-44D0-8553-32BC175077A8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.4.0","versionEndExcluding":"13.4.2","matchCriteriaId":"E592579D-2152-4A79-8AEC-21D2119FB7E7"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13341.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/239348","source":"cve@gitlab.com","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/960244","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13341.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/239348","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/960244","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2020-13352","sourceIdentifier":"cve@gitlab.com","published":"2020-11-17T01:15:13.200","lastModified":"2026-06-17T02:53:00.660","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Private group info is leaked leaked in GitLab CE/EE version 10.2 and above, when the project is moved from private to public group. Affected versions are: >=10.2, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2."},{"lang":"es","value":"Una información de grupo privado es filtrada en GitLab CE/EE versiones 10.2 y por debajo, cuando el proyecto se mueve de un grupo privado a público. Las versiones afectadas son: versiones posteriores a 10.2 e incluyéndola, versiones anteriores a 13.3.9, versiones posteriores a 13.4 e incluyéndola, versiones anteriores a 13.4.5, versiones posteriores a 13.5 e incluyéndola, versiones anteriores a 13.5.2"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab CE/EE","versions":[{"version":">=10.2","status":"affected"},{"version":"<13.3.9","status":"affected"},{"version":">=13.4","status":"affected"},{"version":"<13.4.5","status":"affected"},{"version":">=13.5","status":"affected"},{"version":"<13.5.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":3.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.2.0","versionEndExcluding":"13.3.9","matchCriteriaId":"B6C911E8-73C6-49A2-AF8D-2C519B1D90A4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.2.0","versionEndExcluding":"13.3.9","matchCriteriaId":"2113DA11-1D6A-42D6-B740-6ACE3FA8147E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.4.0","versionEndExcluding":"13.4.5","matchCriteriaId":"C7D38168-5E74-4B9C-B0DA-9757D19DA5D5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.4.0","versionEndExcluding":"13.4.5","matchCriteriaId":"E04A3096-9883-4120-ADE4-8CEBE811E242"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.5.0","versionEndExcluding":"13.5.2","matchCriteriaId":"46B55443-7215-4998-A3D7-6B1014513756"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.5.0","versionEndExcluding":"13.5.2","matchCriteriaId":"59FA227C-599B-4636-8FD9-71A60D0C8ABC"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13352.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/38281","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/748315","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13352.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/38281","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/748315","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2020-13354","sourceIdentifier":"cve@gitlab.com","published":"2020-11-17T01:15:13.420","lastModified":"2026-06-17T02:53:00.917","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A potential DOS vulnerability was discovered in GitLab CE/EE starting with version 12.6. The container registry name check could cause exponential number of backtracks for certain user supplied values resulting in high CPU usage. Affected versions are: >=12.6, <13.3.9."},{"lang":"es","value":"Se detectó una posible vulnerabilidad de DOS en GitLab CE/EE desde la versión 12.6. La comprobación del nombre del registro del contenedor podría causar un número exponencial de retrocesos para determinados valores suministrados por el usuario  resultando en un uso elevado de la CPU. Las versiones afectadas son: versiones posteriores a 12.6 e incluyéndola, versiones anteriores a 13.3.9"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab CE/EE","versions":[{"version":">=12.6","status":"affected"},{"version":"<13.3.9","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:N/A:P","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-400"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.6.0","versionEndExcluding":"13.3.9","matchCriteriaId":"108520A6-EA3D-4AC8-999F-287E12FBC8E1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.6.0","versionEndExcluding":"13.3.9","matchCriteriaId":"951CFD1B-2B32-428E-9290-F7D89A319B96"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13354.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/220019","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/869875","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13354.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/220019","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/869875","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2020-13358","sourceIdentifier":"cve@gitlab.com","published":"2020-11-17T01:15:13.497","lastModified":"2026-06-17T02:53:01.380","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability in the internal Kubernetes agent api in GitLab CE/EE version 13.3 and above allows unauthorized access to private projects. Affected versions are: >=13.4, <13.4.5,>=13.3, <13.3.9,>=13.5, <13.5.2."},{"lang":"es","value":"Una vulnerabilidad en la api del agente Kubernetes interno en GitLab CE/EE versiones 13.3 y por debajo, permite el acceso no autorizado a proyectos privados. Las versiones afectadas son: versiones posteriores a 13.4 e incluyéndola, versiones anteriores a 13.4.5, versiones posteriores a 13.3 e incluyéndola, versiones anteriores a 13.3.9, versiones posteriores a 13.5 e incluyéndola, versiones anteriores a 13.5.2"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"Gitlab CE/EE","versions":[{"version":">=13.4","status":"affected"},{"version":"<13.4.5","status":"affected"},{"version":">=13.3","status":"affected"},{"version":"<13.3.9","status":"affected"},{"version":">=13.5","status":"affected"},{"version":"<13.5.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":4.7,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.0,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:N/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.9","matchCriteriaId":"526A67DD-AC5B-41B1-9D93-8068178879D9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.3.0","versionEndIncluding":"13.3.9","matchCriteriaId":"21266050-8461-4C9D-A737-2F2FBAAA2E2B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.4.0","versionEndExcluding":"13.4.5","matchCriteriaId":"C7D38168-5E74-4B9C-B0DA-9757D19DA5D5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.4.0","versionEndExcluding":"13.4.5","matchCriteriaId":"E04A3096-9883-4120-ADE4-8CEBE811E242"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.5.0","versionEndExcluding":"13.5.2","matchCriteriaId":"46B55443-7215-4998-A3D7-6B1014513756"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.5.0","versionEndExcluding":"13.5.2","matchCriteriaId":"59FA227C-599B-4636-8FD9-71A60D0C8ABC"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13358.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/241674","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13358.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/241674","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2020-26406","sourceIdentifier":"cve@gitlab.com","published":"2020-11-17T01:15:13.717","lastModified":"2026-06-17T03:08:04.807","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Certain SAST CiConfiguration information could be viewed by unauthorized users in GitLab EE starting with 13.3. This information was exposed through GraphQL to non-members of public projects with repository visibility restricted as well as guest members on private projects. Affected versions are: >=13.3, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2."},{"lang":"es","value":"Determinada información de SAST CiConfiguration podría ser visualizada por usuarios no autorizados en GitLab EE a partir de la versión 13.3. Esta información fue expuesta por medio de GraphQL a no miembros de proyectos públicos con visibilidad del repositorio restringida, así como a miembros invitados en proyectos privados. Las versiones afectadas son: versiones posteriores a 13.3 e incluyéndola, versiones anteriores a 13.3.9, versiones posteriores a 13.4 e incluyéndola, versiones anteriores a 13.4.5, versiones posteriores a 13.5 incluyéndola, versiones anteriores a 13.5.2"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab EE","versions":[{"version":">=13.3, <13.3.9","status":"affected"},{"version":">=13.4, <13.4.5","status":"affected"},{"version":">=13.5, <13.5.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.9","matchCriteriaId":"526A67DD-AC5B-41B1-9D93-8068178879D9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.3.9","matchCriteriaId":"3E0B9C1A-0B59-4A24-822F-0D72D9835894"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.4.0","versionEndExcluding":"13.4.5","matchCriteriaId":"C7D38168-5E74-4B9C-B0DA-9757D19DA5D5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.4.0","versionEndExcluding":"13.4.5","matchCriteriaId":"E04A3096-9883-4120-ADE4-8CEBE811E242"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.5.0","versionEndExcluding":"13.5.2","matchCriteriaId":"46B55443-7215-4998-A3D7-6B1014513756"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.5.0","versionEndExcluding":"13.5.2","matchCriteriaId":"59FA227C-599B-4636-8FD9-71A60D0C8ABC"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-26406.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/244921","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/965602","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-26406.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/244921","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/965602","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2020-13350","sourceIdentifier":"cve@gitlab.com","published":"2020-11-17T18:15:12.207","lastModified":"2026-06-17T02:53:00.417","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"CSRF in runner administration page in all versions of GitLab CE/EE allows an attacker who's able to target GitLab instance administrators to pause/resume runners. Affected versions are >=13.5.0, <13.5.2,>=13.4.0, <13.4.5,<13.3.9."},{"lang":"es","value":"Un CSRF en la página de administración del ejecutor en todas las versiones de GitLab CE/EE, permite a un atacante que pueda apuntar a administradores de instancias de GitLab pausar y reanudar los ejecutores.&#xa0;Las versiones afectadas son las versiones posteriores a  13.5.0 e incluyéndola, versiones anteriores a 13.5.2, versiones posteriores a 13.4.0 e incluyéndola, versiones anteriores a 13.4.5, versiones anteriores  a 13.3.9"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab CE/EE","versions":[{"version":">=13.5.0","status":"affected"},{"version":"<13.5.2","status":"affected"},{"version":">=13.4.0","status":"affected"},{"version":"<13.4.5","status":"affected"},{"version":"<13.3.9","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","baseScore":3.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":1.6,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:N/A:P","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-352"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"13.3.9","matchCriteriaId":"A34E81CE-A7A0-44E1-9AE6-31C1EA9C2721"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"13.3.9","matchCriteriaId":"3E956D22-F491-4DEB-A995-808A926A4C8B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.4.0","versionEndExcluding":"13.4.5","matchCriteriaId":"C7D38168-5E74-4B9C-B0DA-9757D19DA5D5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.4.0","versionEndExcluding":"13.4.5","matchCriteriaId":"E04A3096-9883-4120-ADE4-8CEBE811E242"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.5.0","versionEndExcluding":"13.5.2","matchCriteriaId":"46B55443-7215-4998-A3D7-6B1014513756"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.5.0","versionEndExcluding":"13.5.2","matchCriteriaId":"59FA227C-599B-4636-8FD9-71A60D0C8ABC"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13350.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/24416","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/415238","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13350.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/24416","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/415238","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2020-13351","sourceIdentifier":"cve@gitlab.com","published":"2020-11-17T18:15:12.380","lastModified":"2026-06-17T02:53:00.533","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Insufficient permission checks in scheduled pipeline API in GitLab CE/EE 13.0+ allows an attacker to read variable names and values for scheduled pipelines on projects visible to the attacker. Affected versions are >=13.0, <13.3.9,>=13.4.0, <13.4.5,>=13.5.0, <13.5.2."},{"lang":"es","value":"Unas comprobaciones insuficientes de permisos en la API de tubería programada en GitLab CE/EE versión 13.0+, permiten a un atacante leer nombres y valores de variables para tuberías programadas en proyectos visibles para el atacante.&#xa0;Las versiones afectadas son las versiones posteriores a 13.0 e incluyéndola, versiones anteriores a 13.3.9, versiones posteriores  a 13.4.0 e incluyéndola, versiones anteriores 13.4.5, versiones posteriores a 13.5.0 e incluyéndola, versiones anteriores a 13.5.2"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab CE/EE","versions":[{"version":">=13.0","status":"affected"},{"version":"<13.3.9","status":"affected"},{"version":">=13.4.0","status":"affected"},{"version":"<13.4.5","status":"affected"},{"version":">=13.5.0","status":"affected"},{"version":"<13.5.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-276"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.0.0","versionEndExcluding":"13.3.9","matchCriteriaId":"39A7C652-3863-4720-9B93-A42890DC208F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.0.0","versionEndExcluding":"13.3.9","matchCriteriaId":"A240CF07-7ED9-4D5A-BAF6-BE8EEACD3AED"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.4.0","versionEndExcluding":"13.4.5","matchCriteriaId":"C7D38168-5E74-4B9C-B0DA-9757D19DA5D5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.4.0","versionEndExcluding":"13.4.5","matchCriteriaId":"E04A3096-9883-4120-ADE4-8CEBE811E242"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.5.0","versionEndExcluding":"13.5.2","matchCriteriaId":"46B55443-7215-4998-A3D7-6B1014513756"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.5.0","versionEndExcluding":"13.5.2","matchCriteriaId":"59FA227C-599B-4636-8FD9-71A60D0C8ABC"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13351.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/239369","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/962462","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13351.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/239369","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/962462","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2020-13348","sourceIdentifier":"cve@gitlab.com","published":"2020-11-17T19:15:11.107","lastModified":"2026-06-17T02:53:00.193","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions starting from 10.2. Required CODEOWNERS approval could be bypassed by targeting a branch without the CODEOWNERS file. Affected versions are >=10.2, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2."},{"lang":"es","value":"Ha sido detectado un problema en GitLab EE que afecta a todas las versiones desde 10.2.&#xa0;La aprobación de CODEOWNERS requerida podría omitirse al apuntar a una sucursal sin el archivo CODEOWNERS.&#xa0;Las versiones afectadas son las versiones posteriores a 10.2 e incluyéndola, versiones anteriores a 13.3.9, versiones posteriores  a 13.4 e incluyéndola, versiones anteriores a 13.4.5, versiones posteriores a 13.5 e incluyéndola, versiones anteriores a 13.5.2"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab EE","versions":[{"version":">=10.2, <13.3.9","status":"affected"},{"version":">=13.4, <13.4.5","status":"affected"},{"version":">=13.5, <13.5.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N","baseScore":5.7,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N","baseScore":5.7,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.2.0","versionEndExcluding":"13.3.9","matchCriteriaId":"2113DA11-1D6A-42D6-B740-6ACE3FA8147E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.4.0","versionEndExcluding":"13.4.5","matchCriteriaId":"E04A3096-9883-4120-ADE4-8CEBE811E242"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.5.0","versionEndExcluding":"13.5.2","matchCriteriaId":"59FA227C-599B-4636-8FD9-71A60D0C8ABC"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13348.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/246928","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13348.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/246928","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2020-13349","sourceIdentifier":"cve@gitlab.com","published":"2020-11-17T19:15:11.200","lastModified":"2026-06-17T02:53:00.307","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions starting from 8.12. A regular expression related to a file path resulted in the Advanced Search feature susceptible to catastrophic backtracking. Affected versions are >=8.12, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2."},{"lang":"es","value":"Ha sido detectado un problema en GitLab EE que afecta a todas las versiones desde 8.12.&#xa0;Una expresión regular relacionada con una ruta de archivo resultó en la funcionalidad Advanced Search susceptible a un retroceso catastrófico.&#xa0;Las versiones afectadas son las versiones posteriores a 8.12 e incluyéndola, versiones anteriores a 13.3.9, versiones posteriores a 13.4 e incluyéndola, versiones anteriores a 13.4.5, versiones posteriores a 13.5 e incluyéndola, versiones anteriores a 13.5.2"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab EE","versions":[{"version":">=8.12","status":"affected"},{"version":"<13.3.9","status":"affected"},{"version":">=13.4","status":"affected"},{"version":"<13.4.5","status":"affected"},{"version":">=13.5","status":"affected"},{"version":"<13.5.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:N/A:P","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-400"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.12.0","versionEndExcluding":"13.3.9","matchCriteriaId":"72502307-0B19-406D-9D9C-0E9D919591BA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.4.0","versionEndExcluding":"13.4.5","matchCriteriaId":"E04A3096-9883-4120-ADE4-8CEBE811E242"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.5.0","versionEndExcluding":"13.5.2","matchCriteriaId":"59FA227C-599B-4636-8FD9-71A60D0C8ABC"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13349.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/257497","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13349.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/257497","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2020-26405","sourceIdentifier":"cve@gitlab.com","published":"2020-11-17T19:15:11.280","lastModified":"2026-06-17T03:08:04.693","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Path traversal vulnerability in package upload functionality in GitLab CE/EE starting from 12.8 allows an attacker to save packages in arbitrary locations. Affected versions are >=12.8, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2."},{"lang":"es","value":"Una vulnerabilidad de salto de ruta en la funcionalidad package upload en GitLab CE/EE desde la versión 12.8, permite a un atacante guardar paquetes en ubicaciones arbitrarias.&#xa0;Las versiones afectadas son las versiones posteriores a 12.8 e incluyéndola, versiones anteriores a 13.3.9, versiones posteriores a 13.4 e incluyéndola, versiones anteriores a 13.4.5, versiones posteriores a 13.5 e incluyéndola, versiones anteriores a 13.5.2"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab CE/EE","versions":[{"version":">=12.8","status":"affected"},{"version":"<13.3.9","status":"affected"},{"version":">=13.4","status":"affected"},{"version":"<13.4.5","status":"affected"},{"version":">=13.5","status":"affected"},{"version":"<13.5.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":4.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":4.2}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:P","baseScore":5.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-22"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.8.0","versionEndExcluding":"13.3.9","matchCriteriaId":"BD497389-F89F-4AB3-8417-3773E1DF5039"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.8.0","versionEndExcluding":"13.3.9","matchCriteriaId":"F76268C4-31A9-4534-BA5D-58E2ABC78766"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.4.0","versionEndExcluding":"13.4.5","matchCriteriaId":"C7D38168-5E74-4B9C-B0DA-9757D19DA5D5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.4.0","versionEndExcluding":"13.4.5","matchCriteriaId":"E04A3096-9883-4120-ADE4-8CEBE811E242"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.5.0","versionEndExcluding":"13.5.2","matchCriteriaId":"46B55443-7215-4998-A3D7-6B1014513756"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.5.0","versionEndExcluding":"13.5.2","matchCriteriaId":"59FA227C-599B-4636-8FD9-71A60D0C8ABC"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-26405.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/247371","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/835427","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-26405.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/247371","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/835427","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2020-13355","sourceIdentifier":"cve@gitlab.com","published":"2020-11-19T00:15:11.980","lastModified":"2026-06-17T02:53:01.027","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.14. A path traversal is found in LFS Upload that allows attacker to overwrite certain specific paths on the server. Affected versions are: >=8.14, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2."},{"lang":"es","value":"Se ha detectado un problema en GitLab CE/EE que afecta a todas las versiones a partir de 8.14.&#xa0;En LFS Upload se encuentra un salto de ruta que permite a un atacante sobrescribir determinadas rutas específicas en el servidor.&#xa0;Las versiones afectadas son: versiones posteriores a 8.14 incluyéndola, versiones anteriores a 13.3.9, versiones posteriores a 13.4 incluyéndola, versiones anteriores a 13.4.5, versiones posteriores a 13.5 incluyéndola, versiones anteriores a 13.5.2"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab CE/EE","versions":[{"version":">=8.14","status":"affected"},{"version":"<13.3.9","status":"affected"},{"version":">=13.4","status":"affected"},{"version":"<13.4.5","status":"affected"},{"version":">=13.5","status":"affected"},{"version":"<13.5.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.6,"impactScore":5.9},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.2}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:P","baseScore":5.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-22"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.14.0","versionEndExcluding":"13.3.9","matchCriteriaId":"F337007C-1FF4-4D3D-9AAB-65878B4DF686"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.14.0","versionEndExcluding":"13.3.9","matchCriteriaId":"1CE4A418-394B-48C9-876F-C6AEC857B3D6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.4.0","versionEndExcluding":"13.4.5","matchCriteriaId":"C7D38168-5E74-4B9C-B0DA-9757D19DA5D5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.4.0","versionEndExcluding":"13.4.5","matchCriteriaId":"E04A3096-9883-4120-ADE4-8CEBE811E242"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.5.0","versionEndExcluding":"13.5.2","matchCriteriaId":"46B55443-7215-4998-A3D7-6B1014513756"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.5.0","versionEndExcluding":"13.5.2","matchCriteriaId":"59FA227C-599B-4636-8FD9-71A60D0C8ABC"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13355.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/255886","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/990800","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13355.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/255886","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/990800","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2020-13356","sourceIdentifier":"cve@gitlab.com","published":"2020-11-19T00:15:12.120","lastModified":"2026-06-17T02:53:01.147","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.8.9. A specially crafted request could bypass Multipart protection and read files in certain specific paths on the server. Affected versions are: >=8.8.9, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2."},{"lang":"es","value":"Se ha detectado un problema en GitLab CE/EE que afecta a todas las versiones a partir de 8.8.9.&#xa0;Una petición especialmente diseñada podría omitir una protección Multipart y leer archivos en determinadas rutas específicas en el servidor.&#xa0;Las versiones afectadas son: versiones posteriores a  8.8.9 incluyéndola, versiones anteriores a 13.3.9, versiones posteriores a 13.4 incluyéndola, versiones anteriores a 13.4.5, versiones posteriores a 13.5 incluyéndola, versiones anteriores a 13.5.2"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab CE/EE","versions":[{"version":">=8.8.9","status":"affected"},{"version":"<13.3.9","status":"affected"},{"version":">=13.4","status":"affected"},{"version":"<13.4.5","status":"affected"},{"version":">=13.5","status":"affected"},{"version":"<13.5.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N","baseScore":8.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":4.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N","baseScore":8.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":4.2}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:N","baseScore":6.4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.8.9","versionEndExcluding":"13.3.9","matchCriteriaId":"3887890C-DF41-40FF-B498-9F5C48F9D7AA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.8.9","versionEndExcluding":"13.3.9","matchCriteriaId":"37BFF24E-E7CE-4FA5-879C-CD78D3047714"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.4.0","versionEndExcluding":"13.4.5","matchCriteriaId":"C7D38168-5E74-4B9C-B0DA-9757D19DA5D5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.4.0","versionEndExcluding":"13.4.5","matchCriteriaId":"E04A3096-9883-4120-ADE4-8CEBE811E242"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.5.0","versionEndExcluding":"13.5.2","matchCriteriaId":"46B55443-7215-4998-A3D7-6B1014513756"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.5.0","versionEndExcluding":"13.5.2","matchCriteriaId":"59FA227C-599B-4636-8FD9-71A60D0C8ABC"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13356.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/230878","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/927953","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13356.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/230878","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/927953","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2020-13359","sourceIdentifier":"cve@gitlab.com","published":"2020-11-19T00:15:12.277","lastModified":"2026-06-17T02:53:01.493","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"The Terraform API in GitLab CE/EE 12.10+ exposed the object storage signed URL on the delete operation allowing a malicious project maintainer to overwrite the Terraform state, bypassing audit and other business controls. Affected versions are >=12.10, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2."},{"lang":"es","value":"la API Terraform en GitLab CE/EE versión superior a 12.10, expuso la URL firmada de almacenamiento de objetos en la operación de borrado permitiendo a un mantenedor de proyectos malicioso sobrescribir el estado de Terraform, omitiendo una auditoría y otros controles de negocios. Las versiones afectadas son versiones posteriores a 12.10 incluyéndola, versiones anteriores a 13.3.9, versiones posteriores a 13.4 incluyéndola, versiones anteriores a 13.4.5, versiones posteriores a 13.5 incluyéndola, versiones anteriores a 13.5.2"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab CE/EE","versions":[{"version":">=12.10","status":"affected"},{"version":"<13.3.9","status":"affected"},{"version":">=13.4","status":"affected"},{"version":"<13.4.5","status":"affected"},{"version":">=13.5","status":"affected"},{"version":"<13.5.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:N","baseScore":7.6,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":4.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:N","baseScore":7.6,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":4.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:N","baseScore":5.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.10.0","versionEndExcluding":"13.3.9","matchCriteriaId":"93E08F95-81D5-4B75-8B33-34339D59ECCC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.10.0","versionEndExcluding":"13.3.9","matchCriteriaId":"A29D5B2B-05B3-47EE-9519-CBD914002E94"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.4.0","versionEndExcluding":"13.4.5","matchCriteriaId":"C7D38168-5E74-4B9C-B0DA-9757D19DA5D5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.4.0","versionEndExcluding":"13.4.5","matchCriteriaId":"E04A3096-9883-4120-ADE4-8CEBE811E242"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.5.0","versionEndExcluding":"13.5.2","matchCriteriaId":"46B55443-7215-4998-A3D7-6B1014513756"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.5.0","versionEndExcluding":"13.5.2","matchCriteriaId":"59FA227C-599B-4636-8FD9-71A60D0C8ABC"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13359.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/250266","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13359.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/250266","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2020-26407","sourceIdentifier":"cve@gitlab.com","published":"2020-12-10T06:15:13.750","lastModified":"2026-06-17T03:08:04.923","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A XSS vulnerability exists in Gitlab CE/EE from 12.4 before 13.4.7, 13.5 before 13.5.5, and 13.6 before 13.6.2 that allows an attacker to perform cross-site scripting to other users via importing a malicious project"},{"lang":"es","value":"Se presenta una vulnerabilidad de tipo XSS en Gitlab CE/EE desde versiones 12.4 anteriores a 13.4.7, versiones 13.5 anteriores a 13.5.5 y versiones 13.6 anteriores a 13.6.2, que permite a un atacante llevar a cabo ataques de tipo cross-site scripting para otros usuarios por medio de la importación de un proyecto malicioso."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"Gitlab CE/EE","versions":[{"version":">=12.4","status":"affected"},{"version":"<13.4.7","status":"affected"},{"version":">=13.5","status":"affected"},{"version":"<13.5.5","status":"affected"},{"version":">=13.6","status":"affected"},{"version":"<13.6.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":1.3,"impactScore":3.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.4.0","versionEndExcluding":"13.4.7","matchCriteriaId":"A9F5AA4C-A72D-49D1-BE93-FD01CCC1EAB4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.4.0","versionEndExcluding":"13.4.7","matchCriteriaId":"2DDA04AC-DF77-4203-8EF4-2F3822FE8C4C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.5.0","versionEndExcluding":"13.5.5","matchCriteriaId":"468AFC4C-4AFE-4502-AE04-CEC567CC9454"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.5.0","versionEndExcluding":"13.5.5","matchCriteriaId":"C03EE1D3-7824-43A8-ACA2-7EE7EA9B638E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.6.0","versionEndExcluding":"13.6.2","matchCriteriaId":"8A470CCF-C038-44D4-AB14-B9134C0E7ABC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.6.0","versionEndExcluding":"13.6.2","matchCriteriaId":"63A5C9B5-F86B-4066-8042-865AB4DD4859"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-26407.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/212630","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/832117","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-26407.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/212630","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/832117","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2020-26409","sourceIdentifier":"cve@gitlab.com","published":"2020-12-11T02:15:11.490","lastModified":"2026-06-17T03:08:05.143","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A DOS vulnerability exists in Gitlab CE/EE >=10.3, <13.4.7,>=13.5, <13.5.5,>=13.6, <13.6.2 that allows an attacker to trigger uncontrolled resource by bypassing input validation in markdown fields."},{"lang":"es","value":"Se presenta una vulnerabilidad de DOS en Gitlab CE/EE versiones posteriores a 10.3 incluyéndola, versiones anteriores a 13.4.7, versiones posteriores a 13.5 incluyéndola, versiones anteriores a 13.5.5,  versiones posteriores a 13.6 incluyéndola, versiones anteriores 13.6.2, que permite a un atacante activar un recurso no controlado al omitir la comprobación de entrada en los campos markdown"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab CE/EE","versions":[{"version":">=10.3","status":"affected"},{"version":"<13.4.7","status":"affected"},{"version":">=13.5","status":"affected"},{"version":"<13.5.5","status":"affected"},{"version":">=13.6","status":"affected"},{"version":"<13.6.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:N/A:P","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-20"},{"lang":"en","value":"CWE-400"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.3.0","versionEndExcluding":"13.4.7","matchCriteriaId":"BD344029-BC42-4233-AA0F-37DC87F8AB1F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.3.0","versionEndExcluding":"13.4.7","matchCriteriaId":"512D9B32-3BDA-49DD-BB42-EAD4270B5FDD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.5.0","versionEndExcluding":"13.5.5","matchCriteriaId":"468AFC4C-4AFE-4502-AE04-CEC567CC9454"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.5.0","versionEndExcluding":"13.5.5","matchCriteriaId":"C03EE1D3-7824-43A8-ACA2-7EE7EA9B638E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.6.0","versionEndExcluding":"13.6.2","matchCriteriaId":"8A470CCF-C038-44D4-AB14-B9134C0E7ABC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.6.0","versionEndExcluding":"13.6.2","matchCriteriaId":"63A5C9B5-F86B-4066-8042-865AB4DD4859"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-26409.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/259626","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/990461","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-26409.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/259626","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/990461","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2020-13357","sourceIdentifier":"cve@gitlab.com","published":"2020-12-11T04:15:11.080","lastModified":"2026-06-17T02:53:01.263","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in Gitlab CE/EE versions >= 13.1 to <13.4.7, >= 13.5 to <13.5.5, and >= 13.6 to <13.6.2 allowed an unauthorized user to access the user list corresponding to a feature flag in a project."},{"lang":"es","value":"Se detectó un problema en Gitlab CE/EE versiones posteriores a 13.1 incluyéndola hasta versiones anteriores a 13.4.7, versiones posteriores a 13.5 incluyéndola hasta versiones anteriores a 13.5.5 y versiones posteriores 13.6 incluyéndola hasta versiones anteriores a 13.6.2, permitieron a un usuario no autorizado acceder a la lista de usuarios correspondiente a un flag feature en un proyecto"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab CE/EE","versions":[{"version":">= 13.1 to <13.4.7","status":"affected"},{"version":">= 13.5 to <13.5.5","status":"affected"},{"version":">= 13.6 to <13.6.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-639"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.4.7","matchCriteriaId":"2C4CD49E-C8FF-4830-B28D-E2FADE748F81"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.4.7","matchCriteriaId":"A46662D9-9CD8-4BA5-B539-D608C34BEBE7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.5.0","versionEndExcluding":"13.5.5","matchCriteriaId":"468AFC4C-4AFE-4502-AE04-CEC567CC9454"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.5.0","versionEndExcluding":"13.5.5","matchCriteriaId":"C03EE1D3-7824-43A8-ACA2-7EE7EA9B638E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.6.0","versionEndExcluding":"13.6.2","matchCriteriaId":"8A470CCF-C038-44D4-AB14-B9134C0E7ABC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.6.0","versionEndExcluding":"13.6.2","matchCriteriaId":"63A5C9B5-F86B-4066-8042-865AB4DD4859"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13357.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/241132","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/962408","source":"cve@gitlab.com","tags":["Press/Media Coverage"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13357.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/241132","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/962408","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Press/Media Coverage"]}]}},{"cve":{"id":"CVE-2020-26408","sourceIdentifier":"cve@gitlab.com","published":"2020-12-11T04:15:11.407","lastModified":"2026-06-17T03:08:05.033","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A limited information disclosure vulnerability exists in Gitlab CE/EE from >= 12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2 that allows an attacker to view limited information in user's private profile"},{"lang":"es","value":"Se presenta una vulnerabilidad de divulgación de información limitada en Gitlab CE/EE desde versiones posteriores a 12.2 incluyéndola hasta versiones anteriores a 13.4.7 incluyéndola, versiones posteriores a 13.5 incluyéndola hasta versiones anteriores a 13.5.5 y versiones posteriores a 13.6 incluyéndola hasta versiones anteriores a 13.6.2, que permite a un atacante visualizar información limitada en un usuario de perfil privado"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab CE/EE","versions":[{"version":">= 12.2 to <13.4.7","status":"affected"},{"version":">=13.5 to <13.5.5","status":"affected"},{"version":">=13.6 to <13.6.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"13.4.7","matchCriteriaId":"5EF2F42F-4351-448E-9101-8236F08886F8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"13.4.7","matchCriteriaId":"38B64489-A58E-4B6A-9088-762519BCB07D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.5.0","versionEndExcluding":"13.5.5","matchCriteriaId":"468AFC4C-4AFE-4502-AE04-CEC567CC9454"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.5.0","versionEndExcluding":"13.5.5","matchCriteriaId":"C03EE1D3-7824-43A8-ACA2-7EE7EA9B638E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.6.0","versionEndExcluding":"13.6.2","matchCriteriaId":"8A470CCF-C038-44D4-AB14-B9134C0E7ABC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.6.0","versionEndExcluding":"13.6.2","matchCriteriaId":"63A5C9B5-F86B-4066-8042-865AB4DD4859"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-26408.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/33563","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/703894","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-26408.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/33563","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/703894","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2020-26412","sourceIdentifier":"cve@gitlab.com","published":"2020-12-11T04:15:11.487","lastModified":"2026-06-17T03:08:05.360","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Removed group members were able to use the To-Do functionality to retrieve updated information on confidential epics starting in GitLab EE 13.2 before 13.6.2."},{"lang":"es","value":"Los miembros del grupo eliminados fueron capaces de usar la funcionalidad To-Do para recuperar información actualizada sobre epics confidenciales a partir de GitLab EE versiones 13.2 anteriores a 13.6.2"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab EE","versions":[{"version":">=13.2, <13.4.7","status":"affected"},{"version":">=13.5, <13.5.5","status":"affected"},{"version":">=13.6, <13.6.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":3.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.6.2","matchCriteriaId":"360040AA-F5B9-4EB0-B125-A5F7C3121372"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-26412.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/228670","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-26412.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/228670","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2020-26413","sourceIdentifier":"cve@gitlab.com","published":"2020-12-11T04:15:11.547","lastModified":"2026-06-17T03:08:05.467","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 13.6.2. Information disclosure via GraphQL results in user email being unexpectedly visible."},{"lang":"es","value":"Se ha detectado un problema en GitLab CE/EE afectando a todas las versiones desde la 13.4 anteriores a 13.6.2.&#xa0;Una divulgación de información por medio de GraphQL resulta en que el correo electrónico del usuario sea visible inesperadamente"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab CE/EE","versions":[{"version":">=13.4, <13.4.7","status":"affected"},{"version":">=13.5, <13.5.5","status":"affected"},{"version":">=13.6, <13.6.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-200"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.4.0","versionEndExcluding":"13.6.2","matchCriteriaId":"6BB95C58-D7E1-4D81-AC53-73B41CF44328"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.4.0","versionEndExcluding":"13.6.2","matchCriteriaId":"CF17A83E-56AA-4BDD-9EFE-DD805FD14362"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-26413.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/244275","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/972355","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-26413.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/244275","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/972355","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2020-26415","sourceIdentifier":"cve@gitlab.com","published":"2020-12-11T04:15:11.610","lastModified":"2026-06-17T03:08:05.680","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Information about the starred projects for private user profiles was exposed via the GraphQL API starting from 12.2 via the REST API. This affects GitLab >=12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2."},{"lang":"es","value":"La información sobre los proyectos destacados para perfiles de usuarios privados fue expuesta por medio de la API GraphQL a partir de la versión 12.2, por medio de la API REST.&#xa0;Esto afecta a GitLab versiones posteriores a 12.2 incluyéndola hasta versiones anteriores a 13.4.7, versiones posteriores a 13.5 incluyéndola hasta versiones anteriores a 13.5.5 y versiones posteriores a 13.6 incluyéndola hasta versiones anteriores a 13.6.2"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.2 to <13.4.7","status":"affected"},{"version":">=13.5 to <13.5.5","status":"affected"},{"version":">=13.6 to <13.6.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-200"},{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"13.4.7","matchCriteriaId":"5EF2F42F-4351-448E-9101-8236F08886F8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"13.4.7","matchCriteriaId":"38B64489-A58E-4B6A-9088-762519BCB07D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.5.0","versionEndExcluding":"13.5.5","matchCriteriaId":"468AFC4C-4AFE-4502-AE04-CEC567CC9454"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.5.0","versionEndExcluding":"13.5.5","matchCriteriaId":"C03EE1D3-7824-43A8-ACA2-7EE7EA9B638E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.6.0","versionEndExcluding":"13.6.2","matchCriteriaId":"8A470CCF-C038-44D4-AB14-B9134C0E7ABC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.6.0","versionEndExcluding":"13.6.2","matchCriteriaId":"63A5C9B5-F86B-4066-8042-865AB4DD4859"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-26415.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/277337","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-26415.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/277337","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2020-26416","sourceIdentifier":"cve@gitlab.com","published":"2020-12-11T04:15:11.690","lastModified":"2026-06-17T03:08:05.787","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Information disclosure in Advanced Search component of GitLab EE starting from 8.4 results in exposure of search terms via Rails logs. This affects versions >=8.4 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2."},{"lang":"es","value":"Una divulgación de información en el componente Advanced Search de GitLab EE a partir de la versión 8.4, resulta en la exposición de los términos de búsqueda por medio de los registros Rails.&#xa0;Esto afecta a las versiones posteriores a 8.4 incluyéndola hasta versiones anteriores a 13.4.7, versiones posteriores a 13.5 incluyéndola, hasta versiones anteriores a 13.5.5 y versiones posteriores a 13.6 incluyéndola hasta versiones anteriores a 13.6.2"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab EE","versions":[{"version":">=8.4 to <13.4.7","status":"affected"},{"version":">=13.5 to <13.5.5","status":"affected"},{"version":">=13.6 to <13.6.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N","baseScore":4.0,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":0.3,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","baseScore":4.4,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":0.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:N/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-532"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.4.0","versionEndExcluding":"13.4.7","matchCriteriaId":"B22CC5B9-347B-4F4C-B6EF-BEB2F1259922"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.4.0","versionEndExcluding":"13.4.7","matchCriteriaId":"C8C24A26-7966-4E25-B05D-C74BC5A3A516"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.5.0","versionEndExcluding":"13.5.5","matchCriteriaId":"468AFC4C-4AFE-4502-AE04-CEC567CC9454"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.5.0","versionEndExcluding":"13.5.5","matchCriteriaId":"C03EE1D3-7824-43A8-ACA2-7EE7EA9B638E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.6.0","versionEndExcluding":"13.6.2","matchCriteriaId":"8A470CCF-C038-44D4-AB14-B9134C0E7ABC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.6.0","versionEndExcluding":"13.6.2","matchCriteriaId":"63A5C9B5-F86B-4066-8042-865AB4DD4859"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-26416.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/244495","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-26416.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/244495","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2020-26417","sourceIdentifier":"cve@gitlab.com","published":"2020-12-11T04:15:11.767","lastModified":"2026-06-17T03:08:05.897","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Information disclosure via GraphQL in GitLab CE/EE 13.1 and later exposes private group and project membership. This affects versions >=13.6 to <13.6.2, >=13.5 to <13.5.5, and >=13.1 to <13.4.7."},{"lang":"es","value":"Una divulgación de información por medio de GraphQL en GitLab CE/EE versiones 13.1 y posteriores, expone la membresía a grupos privados y proyectos.&#xa0;Esto afecta a las versiones posteriores a 13.6 incluyéndola hasta versiones anteriores a 13.6.2, versiones anteriores a 13.5 incluyéndola hasta versiones anteriores a 13.5.5 y versiones posteriores a 13.1 incluyéndola hasta versiones anteriores a 13.4.7"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab CE/EE","versions":[{"version":">=13.6 to <13.6.2","status":"affected"},{"version":">=13.5 to <13.5.5","status":"affected"},{"version":">=13.1 to <13.4.7","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-200"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.4.7","matchCriteriaId":"2C4CD49E-C8FF-4830-B28D-E2FADE748F81"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.4.7","matchCriteriaId":"A46662D9-9CD8-4BA5-B539-D608C34BEBE7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.5.0","versionEndExcluding":"13.5.5","matchCriteriaId":"468AFC4C-4AFE-4502-AE04-CEC567CC9454"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.5.0","versionEndExcluding":"13.5.5","matchCriteriaId":"C03EE1D3-7824-43A8-ACA2-7EE7EA9B638E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.6.0","versionEndExcluding":"13.6.2","matchCriteriaId":"8A470CCF-C038-44D4-AB14-B9134C0E7ABC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.6.0","versionEndExcluding":"13.6.2","matchCriteriaId":"63A5C9B5-F86B-4066-8042-865AB4DD4859"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-26417.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/282539","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-26417.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/282539","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2020-26411","sourceIdentifier":"cve@gitlab.com","published":"2020-12-11T05:15:12.027","lastModified":"2026-06-17T03:08:05.257","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A potential DOS vulnerability was discovered in all versions of Gitlab starting from 13.4.x (>=13.4 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2). Using a specific query name for a project search can cause statement timeouts that can lead to a potential DOS if abused."},{"lang":"es","value":"Se detectó una posible vulnerabilidad de DOS en todas las versiones de Gitlab desde 13.4.x (versiones anteriores 13.4 e incluyéndola a versiones posteriores 13.4.7, versiones anteriores a 13.5 incluyéndola a versiones posteriores a 13.5.5 y versiones anteriores a 13.6 incluyéndola a versiones posteriores a 13.6.2).&#xa0;Usando un nombre de consulta específico para la búsqueda de un proyecto puede causar tiempos de espera de sentencia que pueden conllevar a un DOS potencial si es abusado"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.4, <13.4.7","status":"affected"},{"version":">=13.5, <13.5.5","status":"affected"},{"version":">=13.6, <13.6.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:N/A:P","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-404"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.4.0","versionEndExcluding":"13.4.7","matchCriteriaId":"E109E54E-DEBC-4131-84EC-5A27368AB9C5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.5.0","versionEndExcluding":"13.5.5","matchCriteriaId":"78AFDCAB-13A6-46A1-9A11-A679A46C2F78"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.6.0","versionEndExcluding":"13.6.2","matchCriteriaId":"3140B8A5-834B-4213-9E93-CB040F0079C0"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-26411.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/260330","source":"cve@gitlab.com","tags":["Broken Link","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-26411.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/260330","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2020-26414","sourceIdentifier":"cve@gitlab.com","published":"2021-01-15T16:15:12.967","lastModified":"2026-06-17T03:08:05.573","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 12.4. The regex used for package names is written in a way that makes execution time have quadratic growth based on the length of the malicious input string."},{"lang":"es","value":"Se ha detectado un problema en GitLab afectando a todas las versiones desde 12.4.&#xa0;La expresión regular utilizada para los nombres de paquetes está escrita de una manera que hace que el tiempo de ejecución tenga un crecimiento cuadrático en la longitud de la cadena de entrada maliciosa"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.4, <13.5.6","status":"affected"},{"version":">=13.6.0, <13.6.4","status":"affected"},{"version":">=13.7.0, <13.7.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:N/A:P","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.4.0","versionEndExcluding":"13.5.6","matchCriteriaId":"9FE265FB-A11B-4ED8-AE7E-C39C19285DB2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.4.0","versionEndExcluding":"13.5.6","matchCriteriaId":"E4F73C29-33EB-419D-8301-1C4F3CDB05B4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.6.0","versionEndExcluding":"13.6.4","matchCriteriaId":"F36EF782-E1B3-4C84-8EC6-A3A159C3AB02"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.6.0","versionEndExcluding":"13.6.4","matchCriteriaId":"1D008652-E883-44CA-987F-A1B64F1B4349"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"13.7.2","matchCriteriaId":"E11B3DE6-9F69-44A1-A8C6-5747F07466AE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"13.7.2","matchCriteriaId":"CA1FA034-49A4-49AF-95CC-8447B0F24C89"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-26414.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/270199","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-26414.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/270199","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2021-22166","sourceIdentifier":"cve@gitlab.com","published":"2021-01-15T16:15:13.217","lastModified":"2026-06-17T03:36:43.643","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An attacker could cause a Prometheus denial of service in GitLab 13.7+ by sending an HTTP request with a malformed method"},{"lang":"es","value":"Un atacante podría causar una denegación de servicio de Prometheus en GitLab versiones 13.7+, mediante el envío de una petición HTTP con un método malformado"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.7, <13.7.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-400"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"13.7.2","matchCriteriaId":"E11B3DE6-9F69-44A1-A8C6-5747F07466AE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"13.7.2","matchCriteriaId":"CA1FA034-49A4-49AF-95CC-8447B0F24C89"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22166.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/labkit/-/issues/29","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22166.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/labkit/-/issues/29","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2021-22167","sourceIdentifier":"cve@gitlab.com","published":"2021-01-15T16:15:13.390","lastModified":"2026-06-17T03:36:43.750","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 12.1. Incorrect headers in specific project page allows attacker to have a temporary read access to the private repository"},{"lang":"es","value":"Se ha detectado un problema en GitLab afectando a todas las versiones desde la 12.1.&#xa0;Los encabezados incorrectos en la página del proyecto específico permiten a un atacante tener un acceso de lectura temporal al repositorio privado"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.1, <13.5.6","status":"affected"},{"version":">=13.6, <13.6.4","status":"affected"},{"version":">=13.7, <13.7.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"13.5.6","matchCriteriaId":"B9959AF1-1970-4108-A7D7-7C4E8F67033E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"13.5.6","matchCriteriaId":"3402E3D1-B367-4186-BBED-2003CE8749EC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.6.0","versionEndExcluding":"13.6.4","matchCriteriaId":"F36EF782-E1B3-4C84-8EC6-A3A159C3AB02"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.6.0","versionEndExcluding":"13.6.4","matchCriteriaId":"1D008652-E883-44CA-987F-A1B64F1B4349"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"13.7.2","matchCriteriaId":"E11B3DE6-9F69-44A1-A8C6-5747F07466AE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"13.7.2","matchCriteriaId":"CA1FA034-49A4-49AF-95CC-8447B0F24C89"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22167.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/289944","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1043480","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22167.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/289944","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1043480","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-22168","sourceIdentifier":"cve@gitlab.com","published":"2021-01-15T16:15:13.453","lastModified":"2026-06-17T03:36:43.860","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A regular expression denial of service issue has been discovered in NuGet API affecting all versions of GitLab starting from version 12.8."},{"lang":"es","value":"Se ha detectado un problema de denegación de servicio de una expresión regular en la API de NuGet afectando a todas las versiones de GitLab desde la versión 12.8"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.8, <13.5.6","status":"affected"},{"version":">=13.6.0, <13.6.4","status":"affected"},{"version":">=13.7.0, <13.7.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:N/A:P","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-400"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.8.0","versionEndExcluding":"13.5.6","matchCriteriaId":"BC2B68FC-295B-4246-8985-2949FC4AAC6F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.8.0","versionEndExcluding":"13.5.6","matchCriteriaId":"CD23C4BC-7E72-4073-A6FE-74BC6DE0C940"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.6.0","versionEndExcluding":"13.6.4","matchCriteriaId":"F36EF782-E1B3-4C84-8EC6-A3A159C3AB02"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.6.0","versionEndExcluding":"13.6.4","matchCriteriaId":"1D008652-E883-44CA-987F-A1B64F1B4349"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"13.7.2","matchCriteriaId":"E11B3DE6-9F69-44A1-A8C6-5747F07466AE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"13.7.2","matchCriteriaId":"CA1FA034-49A4-49AF-95CC-8447B0F24C89"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22168.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/289950","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22168.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/289950","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2021-22171","sourceIdentifier":"cve@gitlab.com","published":"2021-01-15T16:15:13.517","lastModified":"2026-06-17T03:36:44.180","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Insufficient validation of authentication parameters in GitLab Pages for GitLab 11.5+ allows an attacker to steal a victim's API token if they click on a maliciously crafted link"},{"lang":"es","value":"Una comprobación insuficiente de los parámetros de autenticación en GitLab Pages para GitLab versiones 11.5+, permite a un atacante robar el token de la API de una víctima si hace clic en un enlace diseñado con fines maliciosos"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=11.5.0, <13.5.6","status":"affected"},{"version":">=13.6.0, <13.6.4","status":"affected"},{"version":">=13.7.0, <13.7.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-287"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"13.5.6","matchCriteriaId":"19F956E7-EBA6-4BA2-83A9-95E3492BD74C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"13.5.6","matchCriteriaId":"564FCF94-928E-44C8-83BC-DEA308BA28C0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.6.0","versionEndExcluding":"13.6.4","matchCriteriaId":"F36EF782-E1B3-4C84-8EC6-A3A159C3AB02"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.6.0","versionEndExcluding":"13.6.4","matchCriteriaId":"1D008652-E883-44CA-987F-A1B64F1B4349"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"13.7.2","matchCriteriaId":"E11B3DE6-9F69-44A1-A8C6-5747F07466AE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"13.7.2","matchCriteriaId":"CA1FA034-49A4-49AF-95CC-8447B0F24C89"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22171.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-pages/-/issues/262","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/718460","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22171.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-pages/-/issues/262","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/718460","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-22187","sourceIdentifier":"cve@gitlab.com","published":"2021-03-02T19:15:12.957","lastModified":"2026-06-17T03:36:45.983","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions of Gitlab EE/CE before 13.6.7. A potential resource exhaustion issue that allowed running or pending jobs to continue even after project was deleted."},{"lang":"es","value":"Se ha detectado un problema en GitLab que afecta a todas las versiones de Gitlab EE/CE anteriores a 13.6.7. Un posible problema de agotamiento de los recursos que permitía que los trabajos en ejecución o pendientes continuaran incluso después de eliminar el proyecto"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":"<13.6.7","status":"affected"},{"version":">=13.7, <13.7.7","status":"affected"},{"version":">=13.8, <13.8.4","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:N/A:P","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-400"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"13.6.7","matchCriteriaId":"9076F10B-CB03-48F3-A973-26318C55E912"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"13.6.7","matchCriteriaId":"387DD48F-9C0A-40DA-9628-057C606A13BC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartExcluding":"13.7","versionEndExcluding":"13.7.7","matchCriteriaId":"CABA0E78-399E-4030-918A-6DF11945CD61"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartExcluding":"13.7","versionEndExcluding":"13.7.7","matchCriteriaId":"7C31673F-2649-4471-BD20-E237DA2FC70D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartExcluding":"13.8","versionEndExcluding":"13.8.4","matchCriteriaId":"F57F2103-8262-44C4-AFEA-4F4DCF541BB9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartExcluding":"13.8","versionEndExcluding":"13.8.4","matchCriteriaId":"B664E39E-647A-46FD-92BC-537AABD0F101"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22187.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/300452","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22187.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/300452","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2021-22182","sourceIdentifier":"cve@gitlab.com","published":"2021-03-03T18:15:14.237","lastModified":"2026-06-17T03:36:45.453","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting with 13.7. GitLab was vulnerable to a stored XSS in merge request."},{"lang":"es","value":"Se ha detectado un problema en GitLab que afecta a todas las versiones desde la versión 13.7.&#xa0;GitLab era vulnerable a un ataque de tipo XSS almacenado en una petición de fusión"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.8, <13.8.2","status":"affected"},{"version":">=13.7, <13.7.6","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N","baseScore":3.5,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"13.7.6","matchCriteriaId":"AC1152B0-9CC9-4AAB-B183-5B01A49E9170"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"13.7.6","matchCriteriaId":"6309AD47-AB37-45DB-B807-42EC523473D5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.8.0","versionEndExcluding":"13.8.2","matchCriteriaId":"0BE6D29D-CC1A-44D2-B91D-05396FE6F0F2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.8.0","versionEndExcluding":"13.8.2","matchCriteriaId":"0EA203BF-FD91-40B7-800A-19259A37FFD3"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22182.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/280779","source":"cve@gitlab.com","tags":["Exploit","Third Party Advisory"]},{"url":"https://hackerone.com/reports/1030189","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22182.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/280779","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]},{"url":"https://hackerone.com/reports/1030189","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-22188","sourceIdentifier":"cve@gitlab.com","published":"2021-03-03T18:15:14.550","lastModified":"2026-06-17T03:36:46.090","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting with 13.0. Confidential issue titles in Gitlab were readable by an unauthorised user via branch logs."},{"lang":"es","value":"Se ha detectado un problema en GitLab, que afecta a todas las versiones desde la versión 13.0.&#xa0;Los títulos de problemas confidenciales en Gitlab eran legibles por un usuario no autorizado por medio de los registros de ramas"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.8, <13.8.4","status":"affected"},{"version":">=13.7, <13.7.7","status":"affected"},{"version":">=13.0, <13.6.7","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.0.0","versionEndExcluding":"13.6.7","matchCriteriaId":"DB80F7C8-5F75-458C-A879-0BB48554C572"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.0.0","versionEndExcluding":"13.6.7","matchCriteriaId":"5ADE6D80-B46F-4F13-849C-A220B7714877"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"13.7.7","matchCriteriaId":"4BBAF21A-84DD-4987-B4BE-2A8CAA44210A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"13.7.7","matchCriteriaId":"9AE735A5-FC67-4B16-B27B-86C51C8771C1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.8.0","versionEndExcluding":"13.8.4","matchCriteriaId":"D3009669-C930-4517-914D-5DB9A0E40B59"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.8.0","versionEndExcluding":"13.8.4","matchCriteriaId":"9F7976E8-BDA5-4104-AC3E-38C02CC613A7"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22188.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/227040","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/916340","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22188.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/227040","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/916340","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-22183","sourceIdentifier":"cve@gitlab.com","published":"2021-03-04T15:15:13.157","lastModified":"2026-06-17T03:36:45.560","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting with 11.8. GitLab was vulnerable to a stored XSS in the epics page, which could be exploited with user interactions."},{"lang":"es","value":"Se ha detectado un problema en GitLab que afecta a todas las versiones a partir de 11.8.&#xa0;GitLab era vulnerable a un XSS almacenado en la página epics, que podría haber sido explotado con las interacciones del usuario"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.8, <13.8.2","status":"affected"},{"version":">=13.7, <13.7.6","status":"affected"},{"version":">=11.8, <13.6.6","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N","baseScore":4.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.8","versionEndExcluding":"13.6.6","matchCriteriaId":"359C600F-1715-4882-A852-07C19802E1B6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.8","versionEndExcluding":"13.6.6","matchCriteriaId":"3C3DAEDC-3DFB-4450-A946-7C29D94DE5CE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"13.7.6","matchCriteriaId":"AC1152B0-9CC9-4AAB-B183-5B01A49E9170"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"13.7.6","matchCriteriaId":"6309AD47-AB37-45DB-B807-42EC523473D5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.8.0","versionEndExcluding":"13.8.2","matchCriteriaId":"0BE6D29D-CC1A-44D2-B91D-05396FE6F0F2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.8.0","versionEndExcluding":"13.8.2","matchCriteriaId":"0EA203BF-FD91-40B7-800A-19259A37FFD3"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22183.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/294176","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1055814","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22183.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/294176","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1055814","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-22189","sourceIdentifier":"cve@gitlab.com","published":"2021-03-04T15:15:13.283","lastModified":"2026-06-17T03:36:46.197","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Starting with version 13.7 the Gitlab CE/EE editions were affected by a security issue related to the validation of the certificates for the Fortinet OTP that could result in authentication issues."},{"lang":"es","value":"A partir de la versión 13.7, las ediciones de Gitlab CE/EE, estaban afectadas por un problema de seguridad relacionado a la comprobación de los certificados para Fortinet OTP que podría resultar en problemas de autenticación"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.8.0, <13.8.4","status":"affected"},{"version":">=13.7.0, <13.7.7","status":"affected"},{"version":">=13.6, <13.6.7","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":0.7,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-295"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"13.6.7","matchCriteriaId":"9076F10B-CB03-48F3-A973-26318C55E912"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"13.6.7","matchCriteriaId":"387DD48F-9C0A-40DA-9628-057C606A13BC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"13.7.7","matchCriteriaId":"4BBAF21A-84DD-4987-B4BE-2A8CAA44210A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"13.7.7","matchCriteriaId":"9AE735A5-FC67-4B16-B27B-86C51C8771C1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.8.0","versionEndExcluding":"13.8.4","matchCriteriaId":"D3009669-C930-4517-914D-5DB9A0E40B59"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.8.0","versionEndExcluding":"13.8.4","matchCriteriaId":"9F7976E8-BDA5-4104-AC3E-38C02CC613A7"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22189.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/296557","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22189.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/296557","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2021-22176","sourceIdentifier":"cve@gitlab.com","published":"2021-03-24T17:15:13.727","lastModified":"2026-06-17T03:36:44.790","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting with 3.0.1. Improper access control allows demoted project members to access details on authored merge requests"},{"lang":"es","value":"Se ha detectado un problema en GitLab que afecta a todas las versiones a partir de 3.0.1.&#xa0;El control de acceso inapropiado permite a miembros del proyecto degradados acceder a los detalles de las peticiones de fusión creadas"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.8.0, <13.8.4","status":"affected"},{"version":">=13.7.0, <13.7.7","status":"affected"},{"version":">=3.0.1, <13.6.7","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"3.0.1","versionEndExcluding":"13.6.7","matchCriteriaId":"8D8EAB17-5FD9-4E8C-9109-826E86529170"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"3.0.1","versionEndExcluding":"13.6.7","matchCriteriaId":"749861FF-00DB-4176-ACE9-F53E7E6E3412"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"13.7.7","matchCriteriaId":"4BBAF21A-84DD-4987-B4BE-2A8CAA44210A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"13.7.7","matchCriteriaId":"9AE735A5-FC67-4B16-B27B-86C51C8771C1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.8.0","versionEndExcluding":"13.8.4","matchCriteriaId":"D3009669-C930-4517-914D-5DB9A0E40B59"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.8.0","versionEndExcluding":"13.8.4","matchCriteriaId":"9F7976E8-BDA5-4104-AC3E-38C02CC613A7"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22176.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/243491","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://hackerone.com/reports/962604","source":"cve@gitlab.com","tags":["Issue Tracking","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22176.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/243491","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://hackerone.com/reports/962604","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-22178","sourceIdentifier":"cve@gitlab.com","published":"2021-03-24T17:15:13.820","lastModified":"2026-06-17T03:36:45.017","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 13.2. Gitlab was vulnerable to SRRF attack through the Prometheus integration."},{"lang":"es","value":"Se ha detectado un problema en GitLab que afecta a todas las versiones a partir de 13.2.&#xa0;Gitlab era vulnerable a un ataque de tipo SRRF por medio de la integración de Prometheus"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.2, <13.6.7","status":"affected"},{"version":">=13.7, <13.7.7","status":"affected"},{"version":">=13.8, <13.8.4","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N","baseScore":5.0,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N","baseScore":5.0,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.6.7","matchCriteriaId":"9E95D786-857F-4BF8-AA9D-1B14DC066626"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.6.7","matchCriteriaId":"1520C7D6-AE99-43F6-9C06-F1C83D29AA5A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"13.7.7","matchCriteriaId":"4BBAF21A-84DD-4987-B4BE-2A8CAA44210A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"13.7.7","matchCriteriaId":"9AE735A5-FC67-4B16-B27B-86C51C8771C1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.8.0","versionEndExcluding":"13.8.4","matchCriteriaId":"D3009669-C930-4517-914D-5DB9A0E40B59"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.8.0","versionEndExcluding":"13.8.4","matchCriteriaId":"9F7976E8-BDA5-4104-AC3E-38C02CC613A7"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22178.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/284819","source":"cve@gitlab.com","tags":["Exploit","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1037411","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22178.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/284819","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1037411","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-22179","sourceIdentifier":"cve@gitlab.com","published":"2021-03-24T17:15:13.930","lastModified":"2026-06-17T03:36:45.127","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability was discovered in GitLab versions before 12.2. GitLab was vulnerable to a SSRF attack through the Outbound Requests feature."},{"lang":"es","value":"Se detectó una vulnerabilidad en GitLab versiones anteriores a 12.2.&#xa0;GitLab era vulnerable a un ataque de tipo SSRF por medio de la funcionalidad Outbound Requests"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.8, <13.8.2","status":"affected"},{"version":">=13.7, <13.7.6","status":"affected"},{"version":">=12.2, <13.6.6","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":2.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":2.5}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:P","baseScore":5.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"13.6.6","matchCriteriaId":"7DFCFDDF-2CA7-45E9-89A8-7A167EC4EB05"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"13.6.6","matchCriteriaId":"2715BEAE-AF6C-47E8-B811-D06219344A2B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"13.7.6","matchCriteriaId":"AC1152B0-9CC9-4AAB-B183-5B01A49E9170"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"13.7.6","matchCriteriaId":"6309AD47-AB37-45DB-B807-42EC523473D5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.8.0","versionEndExcluding":"13.8.2","matchCriteriaId":"0BE6D29D-CC1A-44D2-B91D-05396FE6F0F2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.8.0","versionEndExcluding":"13.8.2","matchCriteriaId":"0EA203BF-FD91-40B7-800A-19259A37FFD3"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22179.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/293733","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1055816","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22179.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/293733","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1055816","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-22185","sourceIdentifier":"cve@gitlab.com","published":"2021-03-24T17:15:14.023","lastModified":"2026-06-17T03:36:45.773","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Insufficient input sanitization in wikis in GitLab version 13.8 and up allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted commit to a wiki"},{"lang":"es","value":"Un saneamiento insuficiente de la entrada en wikis en GitLab versiones 13.8 y posteriores, permite a un atacante explotar una vulnerabilidad de tipo cross-site scripting almacenada por medio de un commit especialmente diseñado para un wiki"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.8, <13.8.5","status":"affected"},{"version":">=13.9, <13.9.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.8.0","versionEndExcluding":"13.8.5","matchCriteriaId":"26177756-A7AE-432F-8379-9752EC65E090"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.8.0","versionEndExcluding":"13.8.5","matchCriteriaId":"EA4DB41D-BB15-4B41-A00F-D4AD1C20115D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.9.0","versionEndExcluding":"13.9.2","matchCriteriaId":"02A4523B-FA8E-42C6-B291-C8F7811F7216"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.9.0","versionEndExcluding":"13.9.2","matchCriteriaId":"E2A84D4C-6526-43AD-9FEF-01435CF17B9F"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22185.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/299143","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1087061","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22185.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/299143","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1087061","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-22186","sourceIdentifier":"cve@gitlab.com","published":"2021-03-24T17:15:14.087","lastModified":"2026-06-17T03:36:45.880","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An authorization issue in GitLab CE/EE version 9.4 and up allowed a group maintainer to modify group CI/CD variables which should be restricted to group owners"},{"lang":"es","value":"Un problema de autorización en GitLab CE/EE versiones 9.4 y posteriores, permitió a un mantenedor de grupo modificar unas variables de CI/CD de grupo que deberían estar restringidas a los propietarios del grupo"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=9.4, <13.7.8","status":"affected"},{"version":">=13.8, <13.8.5","status":"affected"},{"version":">=13.9, <13.9.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"9.4.0","versionEndExcluding":"13.7.8","matchCriteriaId":"3BB86AD8-CCFA-46D2-ADF4-FD4EE6D1ED2E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"9.4.0","versionEndExcluding":"13.7.8","matchCriteriaId":"54A4AD4D-8577-47DC-B235-3DD80658D23F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.8.0","versionEndExcluding":"13.8.5","matchCriteriaId":"26177756-A7AE-432F-8379-9752EC65E090"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.8.0","versionEndExcluding":"13.8.5","matchCriteriaId":"EA4DB41D-BB15-4B41-A00F-D4AD1C20115D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.9.0","versionEndExcluding":"13.9.2","matchCriteriaId":"02A4523B-FA8E-42C6-B291-C8F7811F7216"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.9.0","versionEndExcluding":"13.9.2","matchCriteriaId":"E2A84D4C-6526-43AD-9FEF-01435CF17B9F"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22186.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/321653","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22186.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/321653","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2021-22192","sourceIdentifier":"cve@gitlab.com","published":"2021-03-24T17:15:14.167","lastModified":"2026-06-17T03:36:46.547","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 allowing unauthorized authenticated users to execute arbitrary code on the server."},{"lang":"es","value":"Se ha detectado un problema en GitLab CE/EE que afecta a todas las versiones a partir de 13.2, permitiendo a usuarios autenticados no autorizados ejecutar código arbitrario en el servidor"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.2, <13.7.9","status":"affected"},{"version":">=13.8, <13.8.6","status":"affected"},{"version":">=13.9, <13.9.4","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":9.9,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.1,"impactScore":6.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.7.9","matchCriteriaId":"A9154BFC-CED7-4E1F-A298-CF837B54DF7A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.7.9","matchCriteriaId":"BCC130B0-5139-458D-BF47-1937CB3D6F8E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.8.0","versionEndExcluding":"13.8.6","matchCriteriaId":"77BF0B77-D9F8-45A2-8BA0-16E7B7F9C96F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.8.0","versionEndExcluding":"13.8.6","matchCriteriaId":"3517AD59-2E9F-41B8-B4F9-B0D6EA3B8E23"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.9.0","versionEndExcluding":"13.9.4","matchCriteriaId":"64FA7C82-24B6-4D9B-884B-F31F3A90F45B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.9.0","versionEndExcluding":"13.9.4","matchCriteriaId":"56748771-1CFA-4BD8-917A-D49E80675FF6"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22192.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/324452","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1125425","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22192.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/324452","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1125425","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-22193","sourceIdentifier":"cve@gitlab.com","published":"2021-03-24T17:15:14.260","lastModified":"2026-06-17T03:36:46.657","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting with 7.1. A member of a private group was able to validate the use of a specific name for private project."},{"lang":"es","value":"Se ha detectado un problema en GitLab que afecta a todas las versiones a partir de 7.1.&#xa0;Un miembro de un grupo privado pudo ser capaz de comprobar el uso de un nombre específico para un proyecto privado"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.8, <13.8.2","status":"affected"},{"version":">=13.7, <13.7.6","status":"affected"},{"version":">=7.1, <13.6.6","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N","baseScore":3.5,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N","baseScore":3.5,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:P/I:N/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-209"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"7.1.0","versionEndExcluding":"13.6.6","matchCriteriaId":"2FAE5EA5-A4E0-4605-A8BD-8AF7F005B161"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"7.1.0","versionEndExcluding":"13.6.6","matchCriteriaId":"8FB5CE7B-5237-4A32-B522-CD65DCD8001A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"13.7.6","matchCriteriaId":"AC1152B0-9CC9-4AAB-B183-5B01A49E9170"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"13.7.6","matchCriteriaId":"6309AD47-AB37-45DB-B807-42EC523473D5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.8.0","versionEndExcluding":"13.8.2","matchCriteriaId":"0BE6D29D-CC1A-44D2-B91D-05396FE6F0F2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.8.0","versionEndExcluding":"13.8.2","matchCriteriaId":"0EA203BF-FD91-40B7-800A-19259A37FFD3"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22193.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/12560","source":"cve@gitlab.com","tags":["Exploit","Third Party Advisory"]},{"url":"https://hackerone.com/reports/605608","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22193.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/12560","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]},{"url":"https://hackerone.com/reports/605608","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-22169","sourceIdentifier":"cve@gitlab.com","published":"2021-03-24T18:15:12.713","lastModified":"2026-06-17T03:36:43.967","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was identified in GitLab EE 13.4 or later which leaked internal IP address via error messages."},{"lang":"es","value":"Se identificó un problema en GitLab EE versiones 13.4 o posteriores, que filtró la dirección IP interna por medio de mensajes de error"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.4, <13.5.6","status":"affected"},{"version":">=13.6.0, <13.6.4","status":"affected"},{"version":">=13.7.0, <13.7.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-209"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.4.0","versionEndExcluding":"13.5.6","matchCriteriaId":"71F43AC6-51CF-42F3-9FB1-78EA333675FF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.6.0","versionEndExcluding":"13.6.4","matchCriteriaId":"1D008652-E883-44CA-987F-A1B64F1B4349"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"13.7.2","matchCriteriaId":"CA1FA034-49A4-49AF-95CC-8447B0F24C89"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22169.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/289930","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22169.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/289930","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2021-22172","sourceIdentifier":"cve@gitlab.com","published":"2021-03-26T20:15:12.127","lastModified":"2026-06-17T03:36:44.293","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Improper authorization in GitLab 12.8+ allows a guest user in a private project to view tag data that should be inaccessible on the releases page"},{"lang":"es","value":"Una autorización inapropiada en GitLab versión 12.8+, permite a un usuario invitado en un proyecto privado visualizar datos de etiquetas que deberían ser inaccesibles en la página de lanzamientos"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.8, <13.6.6","status":"affected"},{"version":">=13.7.0, <13.7.6","status":"affected"},{"version":">=13.8.0, <13.8.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-200"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.8.0","versionEndExcluding":"13.6.6","matchCriteriaId":"BFDED9F9-132A-41D2-AC91-2C29753D25C0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.8.0","versionEndExcluding":"13.6.6","matchCriteriaId":"A1AADA10-AD3D-417F-8B0C-FDDD9B1248E3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"13.7.6","matchCriteriaId":"AC1152B0-9CC9-4AAB-B183-5B01A49E9170"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"13.7.6","matchCriteriaId":"6309AD47-AB37-45DB-B807-42EC523473D5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.8.0","versionEndExcluding":"13.8.2","matchCriteriaId":"0BE6D29D-CC1A-44D2-B91D-05396FE6F0F2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.8.0","versionEndExcluding":"13.8.2","matchCriteriaId":"0EA203BF-FD91-40B7-800A-19259A37FFD3"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22172.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/212911","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking","Patch","Vendor Advisory"]},{"url":"https://hackerone.com/reports/833334","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22172.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/212911","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Patch","Vendor Advisory"]},{"url":"https://hackerone.com/reports/833334","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-22180","sourceIdentifier":"cve@gitlab.com","published":"2021-03-26T20:15:12.220","lastModified":"2026-06-17T03:36:45.237","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 13.4. Improper access control allows unauthorized users to access details on analytic pages."},{"lang":"es","value":"Se ha detectado un problema en GitLab que afecta a todas las versiones desde 13.4.&#xa0;Un control de acceso inapropiado permite a usuarios no autorizados acceder a los detalles de las páginas analíticas."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.8, <13.8.4","status":"affected"},{"version":">=13.7, <13.7.7","status":"affected"},{"version":">=13.6, <13.6.7","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-425"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.6.0","versionEndExcluding":"13.6.7","matchCriteriaId":"26DFE35C-07CA-4F21-85F1-C7C45F271D81"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.6.0","versionEndExcluding":"13.6.7","matchCriteriaId":"5372BB03-55E7-4694-8BA5-501AA62E47BF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"13.7.7","matchCriteriaId":"4BBAF21A-84DD-4987-B4BE-2A8CAA44210A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"13.7.7","matchCriteriaId":"9AE735A5-FC67-4B16-B27B-86C51C8771C1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.8.0","versionEndExcluding":"13.8.4","matchCriteriaId":"D3009669-C930-4517-914D-5DB9A0E40B59"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.8.0","versionEndExcluding":"13.8.4","matchCriteriaId":"9F7976E8-BDA5-4104-AC3E-38C02CC613A7"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22180.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/295662","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1064645","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22180.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/295662","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1064645","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-22184","sourceIdentifier":"cve@gitlab.com","published":"2021-03-26T20:15:12.297","lastModified":"2026-06-17T03:36:45.670","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An information disclosure issue in GitLab starting from version 12.8 allowed a user with access to the server logs to see sensitive information that wasn't properly redacted."},{"lang":"es","value":"Un problema de divulgación de información en GitLab desde la versión 12.8, permitió a un usuario con acceso a los registros del servidor visualizar información confidencial que no se redactó apropiadamente."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.8, <13.6.6","status":"affected"},{"version":">=13.7.0, <13.7.6","status":"affected"},{"version":">=13.8.0, <13.8.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":6.2,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.5,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:N/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-532"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.8.0","versionEndExcluding":"13.6.6","matchCriteriaId":"BFDED9F9-132A-41D2-AC91-2C29753D25C0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.8.0","versionEndExcluding":"13.6.6","matchCriteriaId":"A1AADA10-AD3D-417F-8B0C-FDDD9B1248E3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"13.7.6","matchCriteriaId":"AC1152B0-9CC9-4AAB-B183-5B01A49E9170"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"13.7.6","matchCriteriaId":"6309AD47-AB37-45DB-B807-42EC523473D5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.8.0","versionEndExcluding":"13.8.2","matchCriteriaId":"0BE6D29D-CC1A-44D2-B91D-05396FE6F0F2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.8.0","versionEndExcluding":"13.8.2","matchCriteriaId":"0EA203BF-FD91-40B7-800A-19259A37FFD3"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22184.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/281676","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22184.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/281676","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2021-22194","sourceIdentifier":"cve@gitlab.com","published":"2021-03-26T20:15:12.390","lastModified":"2026-06-17T03:36:46.760","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In all versions of GitLab, marshalled session keys were being stored in Redis."},{"lang":"es","value":"En todas las versiones de GitLab, las claves de sesión marshalled estaban siendo almacenadas en Redis"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":"<13.7.8","status":"affected"},{"version":">=13.8, <13.8.5","status":"affected"},{"version":">=13.9, <13.9.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N","baseScore":5.7,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":0.5,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","baseScore":4.4,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":0.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:N/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-312"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"13.7.8","matchCriteriaId":"CFF5D21B-B9A0-419A-B48E-0423EDDB5A6D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"13.7.8","matchCriteriaId":"193651E6-E501-4A55-B275-D25ED7C1DA46"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.8.0","versionEndExcluding":"13.8.5","matchCriteriaId":"26177756-A7AE-432F-8379-9752EC65E090"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.8.0","versionEndExcluding":"13.8.5","matchCriteriaId":"EA4DB41D-BB15-4B41-A00F-D4AD1C20115D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.9.0","versionEndExcluding":"13.9.2","matchCriteriaId":"02A4523B-FA8E-42C6-B291-C8F7811F7216"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.9.0","versionEndExcluding":"13.9.2","matchCriteriaId":"E2A84D4C-6526-43AD-9FEF-01435CF17B9F"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22194.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/262107","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22194.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/262107","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2021-22177","sourceIdentifier":"cve@gitlab.com","published":"2021-04-01T15:15:13.957","lastModified":"2026-06-17T03:36:44.907","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Potential DoS was identified in gitlab-shell in GitLab CE/EE version 12.6.0 or above, which allows an attacker to spike the server resource utilization via gitlab-shell command."},{"lang":"es","value":"Se identificó una DoS potencial en gitlab-shell en GitLab CE/EE versiones 12.6.0 o superiores, lo que permite a un atacante aumentar la utilización de recursos del servidor por medio del comando gitlab-shell."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.6, <13.6.7","status":"affected"},{"version":">=13.7, <13.7.7","status":"affected"},{"version":">=13.8, <13.8.4","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:N/A:P","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-400"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.6.0","versionEndExcluding":"13.6.7","matchCriteriaId":"C88743C3-C946-427D-A7A0-CE43356112A5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.6.0","versionEndExcluding":"13.6.7","matchCriteriaId":"F233F48C-70A3-4EE6-9BAF-705FAB25EBA8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"13.7.7","matchCriteriaId":"4BBAF21A-84DD-4987-B4BE-2A8CAA44210A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"13.7.7","matchCriteriaId":"9AE735A5-FC67-4B16-B27B-86C51C8771C1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.8.0","versionEndExcluding":"13.8.4","matchCriteriaId":"D3009669-C930-4517-914D-5DB9A0E40B59"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.8.0","versionEndExcluding":"13.8.4","matchCriteriaId":"9F7976E8-BDA5-4104-AC3E-38C02CC613A7"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22177.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/238988","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/953444","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22177.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/238988","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/953444","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-22196","sourceIdentifier":"cve@gitlab.com","published":"2021-04-02T17:15:12.583","lastModified":"2026-06-17T03:36:46.973","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4. It was possible to exploit a stored cross-site-scripting in merge request via a specifically crafted branch name."},{"lang":"es","value":"Se ha detectado un problema en GitLab CE/EE que afecta a todas las versiones a partir de la 13.4.&#xa0;Era posible explotar una vulnerabilidad de tipo cross-site-scripting almacenada en una petición de combinación por medio de un nombre de rama diseñado específicamente."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.4, <13.8.7","status":"affected"},{"version":">=13.9, <13.9.5","status":"affected"},{"version":">=13.10, <13.10.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N","baseScore":6.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":4.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.4.0","versionEndExcluding":"13.8.7","matchCriteriaId":"30F3AAC4-E18C-4F23-8C49-5F263B0084BC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.4.0","versionEndExcluding":"13.8.7","matchCriteriaId":"8AB6D80B-365B-4B2D-B63A-0EC5394F3656"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.9.0","versionEndExcluding":"13.9.5","matchCriteriaId":"92D30002-B702-42A1-A168-2F81BB39C293"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.9.0","versionEndExcluding":"13.9.5","matchCriteriaId":"DE6524B2-FF9C-48DA-8850-7A4FAE2C4DBC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.10.0","versionEndExcluding":"13.10.1","matchCriteriaId":"3FEE2C2F-791C-4C56-A069-663D85CE5448"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.10.0","versionEndExcluding":"13.10.1","matchCriteriaId":"3D4F2787-E776-4615-B8F9-486AFA754440"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22196.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/254710","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/977697","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22196.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/254710","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/977697","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-22197","sourceIdentifier":"cve@gitlab.com","published":"2021-04-02T17:15:12.677","lastModified":"2026-06-17T03:36:47.090","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.6 where an infinite loop exist when an authenticated user with specific rights access a MR having source and target branch pointing to each other"},{"lang":"es","value":"Se ha detectado un problema en GitLab CE/EE que afecta a todas las versiones a partir de la 10.6, donde se presenta un bucle infinito cuando un usuario autenticado con derechos específicos accede a un MR que tiene la rama de origen y de destino apuntando entre sí."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=10.6, <13.8.7","status":"affected"},{"version":">=13.9, <13.9.5","status":"affected"},{"version":">=13.10, <13.10.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L","baseScore":3.5,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.1,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:N/A:P","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-835"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.6.0","versionEndExcluding":"13.8.7","matchCriteriaId":"EC197906-EB26-47CA-B0D4-0DE46888F1C3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.6.0","versionEndExcluding":"13.8.7","matchCriteriaId":"E1FE1428-9F41-436B-838F-0BFBAD71686A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.9.0","versionEndExcluding":"13.9.5","matchCriteriaId":"92D30002-B702-42A1-A168-2F81BB39C293"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.9.0","versionEndExcluding":"13.9.5","matchCriteriaId":"DE6524B2-FF9C-48DA-8850-7A4FAE2C4DBC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.10.0","versionEndExcluding":"13.10.1","matchCriteriaId":"3FEE2C2F-791C-4C56-A069-663D85CE5448"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.10.0","versionEndExcluding":"13.10.1","matchCriteriaId":"3D4F2787-E776-4615-B8F9-486AFA754440"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22197.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/323198","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22197.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/323198","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2021-22198","sourceIdentifier":"cve@gitlab.com","published":"2021-04-02T17:15:12.773","lastModified":"2026-06-17T03:36:47.197","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 13.8 and above allowing an authenticated user to delete incident metric images of public projects."},{"lang":"es","value":"Se ha detectado un problema en GitLab CE/EE que afecta a todas las versiones desde 13.8 y superiores, permitiendo a un usuario autenticado eliminar imágenes de métricas de incidentes de proyectos públicos."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.8, <13.8.7","status":"affected"},{"version":">=13.9, <13.9.5","status":"affected"},{"version":">=13.10, <13.10.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.8.0","versionEndExcluding":"13.8.7","matchCriteriaId":"93302B94-B89A-47DA-A6BC-7076FDA90EB8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.8.0","versionEndExcluding":"13.8.7","matchCriteriaId":"3342605C-013F-4424-9A62-A30C37EEFD43"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.9.0","versionEndExcluding":"13.9.5","matchCriteriaId":"92D30002-B702-42A1-A168-2F81BB39C293"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.9.0","versionEndExcluding":"13.9.5","matchCriteriaId":"DE6524B2-FF9C-48DA-8850-7A4FAE2C4DBC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.10.0","versionEndExcluding":"13.10.1","matchCriteriaId":"3FEE2C2F-791C-4C56-A069-663D85CE5448"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.10.0","versionEndExcluding":"13.10.1","matchCriteriaId":"3D4F2787-E776-4615-B8F9-486AFA754440"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22198.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/323452","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1107281","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22198.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/323452","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1107281","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-22200","sourceIdentifier":"cve@gitlab.com","published":"2021-04-02T17:15:12.833","lastModified":"2026-06-17T03:36:47.437","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.6. Under a special condition it was possible to access data of an internal repository through a public project fork as an anonymous user."},{"lang":"es","value":"Se detecto un problema en GitLab CE/EE que afecta a todas las versiones a partir de la versión 12.6. Bajo una condición especial era posible acceder a los datos de un repositorio interno a través de un fork público del proyecto como usuario anónimo"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.6, <13.8.7","status":"affected"},{"version":">=13.9, <13.9.5","status":"affected"},{"version":">=13.10, <13.10.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.6.0","versionEndExcluding":"13.8.7","matchCriteriaId":"7C929FA6-403E-4FC3-A949-2C97D023F3F7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.6.0","versionEndExcluding":"13.8.7","matchCriteriaId":"240035E8-A239-428C-851F-D73F6FC68632"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.9.0","versionEndExcluding":"13.9.5","matchCriteriaId":"92D30002-B702-42A1-A168-2F81BB39C293"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.9.0","versionEndExcluding":"13.9.5","matchCriteriaId":"DE6524B2-FF9C-48DA-8850-7A4FAE2C4DBC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:13.10.0:*:*:*:community:*:*:*","matchCriteriaId":"6E683B09-3BF1-4939-A4C5-9D69246C6F48"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:13.10.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"C0874C00-16B2-402B-999B-DAA350BDBC45"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22200.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/247523","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22200.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/247523","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2021-22201","sourceIdentifier":"cve@gitlab.com","published":"2021-04-02T17:15:12.913","lastModified":"2026-06-17T03:36:47.543","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.9. A specially crafted import file could read files on the server."},{"lang":"es","value":"Se ha detectado un problema en GitLab CE/EE que afecta a todas las versiones a partir de la 13.9.&#xa0;Un archivo de importación especialmente diseñado podría leer archivos en el servidor."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.9, <13.9.5","status":"affected"},{"version":">=13.10, <13.10.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N","baseScore":9.6,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.9.0","versionEndExcluding":"13.9.5","matchCriteriaId":"92D30002-B702-42A1-A168-2F81BB39C293"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.9.0","versionEndExcluding":"13.9.5","matchCriteriaId":"DE6524B2-FF9C-48DA-8850-7A4FAE2C4DBC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.10.0","versionEndExcluding":"13.10.1","matchCriteriaId":"3FEE2C2F-791C-4C56-A069-663D85CE5448"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.10.0","versionEndExcluding":"13.10.1","matchCriteriaId":"3D4F2787-E776-4615-B8F9-486AFA754440"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22201.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/325562","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1132378","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22201.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/325562","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1132378","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-22202","sourceIdentifier":"cve@gitlab.com","published":"2021-04-02T17:15:13.007","lastModified":"2026-06-17T03:36:47.660","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all previous versions. If the victim is an admin, it was possible to issue a CSRF in System hooks through the API."},{"lang":"es","value":"Se ha detectado un problema en GitLab CE/EE que afecta a todas las versiones anteriores.&#xa0;Si la víctima es un administrador, es posible facilitar un ataque de tipo CSRF en los enlaces del Sistema por medio de la API."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.10, <13.10.1","status":"affected"},{"version":">=13.9, <13.9.5","status":"affected"},{"version":"<13.8.7","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N","baseScore":2.4,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":0.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-352"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndIncluding":"13.10.0","matchCriteriaId":"0645CA65-ED21-43B7-A839-93675D59C51C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndIncluding":"13.10.0","matchCriteriaId":"5390249A-524A-4EF4-AB45-2C32C87BD6DB"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22202.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/26017","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/471274","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22202.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/26017","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/471274","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-22203","sourceIdentifier":"cve@gitlab.com","published":"2021-04-02T17:15:13.083","lastModified":"2026-06-17T03:36:47.773","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7.9 before 13.8.7, all versions starting from 13.9 before 13.9.5, and all versions starting from 13.10 before 13.10.1. A specially crafted Wiki page allowed attackers to read arbitrary files on the server."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones a partir de la 13.7.9 antes de la 13.8.7, a todas las versiones a partir de la 13.9 antes de la 13.9.5 y a todas las versiones a partir de la 13.10 antes de la 13.10.1. Una página Wiki especialmente diseñada permitía a los atacantes leer archivos arbitrarios en el servidor"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.10, <13.10.1","status":"affected"},{"version":">=13.9, <13.9.5","status":"affected"},{"version":">=13.7.9, <13.8.7","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":4.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.7.9","versionEndExcluding":"13.8.7","matchCriteriaId":"6997BFA9-58D6-40F1-8FE0-0A6040E299C5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.7.9","versionEndExcluding":"13.8.7","matchCriteriaId":"B574A0D7-B02C-472A-BBC7-E04B357A6B3C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.9.0","versionEndExcluding":"13.9.5","matchCriteriaId":"92D30002-B702-42A1-A168-2F81BB39C293"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.9.0","versionEndExcluding":"13.9.5","matchCriteriaId":"DE6524B2-FF9C-48DA-8850-7A4FAE2C4DBC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:13.10.0:*:*:*:community:*:*:*","matchCriteriaId":"6E683B09-3BF1-4939-A4C5-9D69246C6F48"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:13.10.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"C0874C00-16B2-402B-999B-DAA350BDBC45"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22203.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/320919","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking","Patch","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1098793","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22203.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/320919","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Patch","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1098793","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-22190","sourceIdentifier":"cve@gitlab.com","published":"2021-04-12T15:15:14.517","lastModified":"2026-06-17T03:36:46.317","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A path traversal vulnerability via the GitLab Workhorse in all versions of GitLab could result in the leakage of a JWT token"},{"lang":"es","value":"Una vulnerabilidad de salto ruta por medio del GitLab Workhorse en todas las versiones de GitLab podría resultar en la fuga de un token JWT"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.7, <13.7.8","status":"affected"},{"version":">=13.8, <13.8.5","status":"affected"},{"version":">=13.9, <13.9.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":8.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":6.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-22"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"13.7.8","matchCriteriaId":"F1714BD0-B993-4753-B97D-AA2B5EA52E56"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"13.7.8","matchCriteriaId":"80EE110E-20B8-4801-AC5A-33F098265EE7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.8.0","versionEndExcluding":"13.8.5","matchCriteriaId":"26177756-A7AE-432F-8379-9752EC65E090"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.8.0","versionEndExcluding":"13.8.5","matchCriteriaId":"EA4DB41D-BB15-4B41-A00F-D4AD1C20115D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.9.0","versionEndExcluding":"13.9.2","matchCriteriaId":"02A4523B-FA8E-42C6-B291-C8F7811F7216"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.9.0","versionEndExcluding":"13.9.2","matchCriteriaId":"E2A84D4C-6526-43AD-9FEF-01435CF17B9F"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22190.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/300281","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1040786","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22190.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/300281","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1040786","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2021-22199","sourceIdentifier":"cve@gitlab.com","published":"2021-04-22T22:15:11.957","lastModified":"2026-06-17T03:36:47.307","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting with 12.9. GitLab was vulnerable to a stored XSS if scoped labels were used."},{"lang":"es","value":"Se ha detectado un problema en GitLab que afecta a todas las versiones a partir de la 12.9.&#xa0;GitLab era vulnerable a un ataque de tipo XSS almacenado si etiquetas de ámbito eran usadas"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.10, <13.10.1","status":"affected"},{"version":">=13.9.0, <13.9.5","status":"affected"},{"version":">=12.9, <13.8.7","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N","baseScore":3.5,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.9","versionEndExcluding":"13.8.7","matchCriteriaId":"6ABF2889-D7A6-44EE-8543-BECB01C213B1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.9","versionEndExcluding":"13.8.7","matchCriteriaId":"1F6A83E5-F5A5-4719-8166-A69C28166746"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.9.0","versionEndExcluding":"13.9.5","matchCriteriaId":"92D30002-B702-42A1-A168-2F81BB39C293"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.9.0","versionEndExcluding":"13.9.5","matchCriteriaId":"DE6524B2-FF9C-48DA-8850-7A4FAE2C4DBC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.10.0","versionEndExcluding":"13.10.1","matchCriteriaId":"3FEE2C2F-791C-4C56-A069-663D85CE5448"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.10.0","versionEndExcluding":"13.10.1","matchCriteriaId":"3D4F2787-E776-4615-B8F9-486AFA754440"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22199.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/291004","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1050189","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22199.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/291004","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1050189","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-22205","sourceIdentifier":"cve@gitlab.com","published":"2021-04-23T18:15:08.167","lastModified":"2026-08-06T05:16:35.427","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution."},{"lang":"es","value":"Se ha detectado un problema en GitLab CE/EE que afecta a todas las versiones a partir de 11.9.&#xa0;GitLab no estaba comprobado apropiadamente archivos de imagen que fueron pasados a un analizador de archivos, lo que resultó en una ejecución de comando remoto"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=11.9, <13.8.8","status":"affected"},{"version":">=13.9, <13.9.6","status":"affected"},{"version":">=13.10, <13.10.3","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","baseScore":10.0,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":6.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","baseScore":10.0,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":6.0}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2021-10-26T00:00:00+00:00","id":"CVE-2021-22205","options":[{"exploitation":"active"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"cisaExploitAdd":"2021-11-03","cisaActionDue":"2021-11-17","cisaRequiredAction":"Apply updates per vendor instructions.","cisaVulnerabilityName":"GitLab Community and Enterprise Editions Remote Code Execution Vulnerability","weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-94"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-94"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.9.0","versionEndExcluding":"13.8.8","matchCriteriaId":"01EAFA19-205A-4512-9B97-CAE6C5C9E150"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.9.0","versionEndExcluding":"13.8.8","matchCriteriaId":"E50A00D3-A0CA-4A2C-9863-DF3FDD03598F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.9.0","versionEndExcluding":"13.9.6","matchCriteriaId":"2A6892FA-6192-48DE-B3A6-E3992A95487D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.9.0","versionEndExcluding":"13.9.6","matchCriteriaId":"C38714A5-8AE4-432E-B67B-99F393E1D566"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.10.0","versionEndExcluding":"13.10.3","matchCriteriaId":"AD03F460-6E1E-4504-B924-D416AF98744B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.10.0","versionEndExcluding":"13.10.3","matchCriteriaId":"58904C4B-E763-4870-921D-65D6A7F6A0AF"}]}]}],"references":[{"url":"http://packetstormsecurity.com/files/164768/GitLab-Unauthenticated-Remote-ExifTool-Command-Injection.html","source":"cve@gitlab.com","tags":["Exploit","Third Party Advisory","VDB Entry"]},{"url":"http://packetstormsecurity.com/files/164994/GitLab-13.10.2-Remote-Code-Execution.html","source":"cve@gitlab.com","tags":["Exploit","Third Party Advisory","VDB Entry"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22205.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/327121","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1154542","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"http://packetstormsecurity.com/files/164768/GitLab-Unauthenticated-Remote-ExifTool-Command-Injection.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory","VDB Entry"]},{"url":"http://packetstormsecurity.com/files/164994/GitLab-13.10.2-Remote-Code-Execution.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory","VDB Entry"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22205.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/327121","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1154542","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-22205","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"]}]}},{"cve":{"id":"CVE-2021-22211","sourceIdentifier":"cve@gitlab.com","published":"2021-05-06T13:15:11.300","lastModified":"2026-06-17T03:36:48.810","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7. GitLab Dependency Proxy, under certain circumstances, can impersonate a user resulting in possibly incorrect access handling."},{"lang":"es","value":"Se ha detectado un problema en GitLab CE/EE que afecta a todas las versiones a partir de la 13.7.&#xa0;GitLab Dependency Proxy, bajo determinadas circunstancias, puede hacerse pasar por un usuario, resultando en un manejo de acceso incorrecto"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.11, <13.11.2","status":"affected"},{"version":">=13.10, <13.10.4","status":"affected"},{"version":">=13.7, <13.9.7","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":3.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":1.6,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"13.9.7","matchCriteriaId":"33DCAA9F-36B8-4CA8-85AF-36C602F86A2F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"13.9.7","matchCriteriaId":"5471243B-9BBA-41CD-9E39-0AD8417AEE81"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.10.0","versionEndExcluding":"13.10.4","matchCriteriaId":"6CF968F1-8F8D-49D6-995C-DC8366063DA8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.10.0","versionEndExcluding":"13.10.4","matchCriteriaId":"41CC3DA4-3515-4564-87F7-47478EB3DF27"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.11.0","versionEndExcluding":"13.11.2","matchCriteriaId":"CB870D06-315A-452D-B09C-9FDB8D426C89"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.11.0","versionEndExcluding":"13.11.2","matchCriteriaId":"811F3205-355F-463B-A050-7BA2010304E5"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22211.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/298847","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22211.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/298847","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2021-22206","sourceIdentifier":"cve@gitlab.com","published":"2021-05-06T14:15:07.943","lastModified":"2026-06-17T03:36:48.233","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 11.6. Pull mirror credentials are exposed that allows other maintainers to be able to view the credentials in plain-text,"},{"lang":"es","value":"Se ha detectado un problema en GitLab que afecta a todas las versiones a partir de la 11.6.&#xa0;Las credenciales de Pull Mirror están expuestas, permitiendo que otros mantenedores sean capaz de visualizar las credenciales en texto plano"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=11.6, <13.9.7","status":"affected"},{"version":">=13.10.0, <13.10.4","status":"affected"},{"version":">=13.11.0, <13.11.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N","baseScore":6.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":4.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-312"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"13.9.7","matchCriteriaId":"7E4895C6-9D65-409B-9236-A906C92E518B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"13.9.7","matchCriteriaId":"FD0C29D1-5D48-43DE-B0CD-129C407A4675"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.10.0","versionEndExcluding":"13.10.4","matchCriteriaId":"6CF968F1-8F8D-49D6-995C-DC8366063DA8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.10.0","versionEndExcluding":"13.10.4","matchCriteriaId":"41CC3DA4-3515-4564-87F7-47478EB3DF27"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.11.0","versionEndExcluding":"13.11.2","matchCriteriaId":"CB870D06-315A-452D-B09C-9FDB8D426C89"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.11.0","versionEndExcluding":"13.11.2","matchCriteriaId":"811F3205-355F-463B-A050-7BA2010304E5"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22206.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/230864","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/928074","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22206.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/230864","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/928074","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-22208","sourceIdentifier":"cve@gitlab.com","published":"2021-05-06T14:15:07.983","lastModified":"2026-06-17T03:36:48.493","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting versions starting with 13.5 up to 13.9.7. Improper permission check could allow the change of timestamp for issue creation or update."},{"lang":"es","value":"Se ha detectado un problema en GitLab que afecta a las versiones que comienzan con 13.5 hasta 13.9.7.&#xa0;Una comprobación inapropiada de permisos podría permitir el cambio de la marca de tiempo para la creación o actualización de problemas"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.5, <13.9.7","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.5.0","versionEndExcluding":"13.9.7","matchCriteriaId":"4F9BD936-EA52-4482-AECD-F40C34C90E5F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.5.0","versionEndExcluding":"13.9.7","matchCriteriaId":"000CBC82-0447-4454-B24D-DF805404E5C9"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22208.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/301212","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22208.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/301212","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2021-22209","sourceIdentifier":"cve@gitlab.com","published":"2021-05-06T14:15:08.017","lastModified":"2026-06-17T03:36:48.597","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.8. GitLab was not properly validating authorisation tokens which resulted in GraphQL mutation being executed."},{"lang":"es","value":"Se ha detectado un problema en GitLab CE/EE que afecta a todas las versiones a partir de la 13.8.&#xa0;GitLab no estaba comprobando apropiadamente los tokens de autorización, lo cual resultó en la ejecución de la mutación GraphQL"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.11, <13.11.12","status":"affected"},{"version":">=13.10, <13.10.4","status":"affected"},{"version":">=13.8, <13.9.7","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.8.0","versionEndExcluding":"13.9.7","matchCriteriaId":"91AE019D-FED5-413F-A9A8-760FFB33F446"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.8.0","versionEndExcluding":"13.9.7","matchCriteriaId":"AAA04573-1A26-43B0-8B4C-E6807C87F1CD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.10.0","versionEndExcluding":"13.10.4","matchCriteriaId":"6CF968F1-8F8D-49D6-995C-DC8366063DA8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.10.0","versionEndExcluding":"13.10.4","matchCriteriaId":"41CC3DA4-3515-4564-87F7-47478EB3DF27"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.11.0","versionEndExcluding":"13.11.2","matchCriteriaId":"CB870D06-315A-452D-B09C-9FDB8D426C89"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.11.0","versionEndExcluding":"13.11.2","matchCriteriaId":"811F3205-355F-463B-A050-7BA2010304E5"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22209.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/327155","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22209.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/327155","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2021-22210","sourceIdentifier":"cve@gitlab.com","published":"2021-05-06T14:15:08.053","lastModified":"2026-06-17T03:36:48.703","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2. When querying the repository branches through API, GitLab was ignoring a query parameter and returning a considerable amount of results."},{"lang":"es","value":"Se ha detectado un problema en GitLab CE/EE que afecta a todas las versiones a partir de la 13.2.&#xa0;Al consultar las ramas del repositorio por medio de API, GitLab ignoraba un parámetro de consulta y devolvía una cantidad considerable de resultados"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.11, <13.11.2","status":"affected"},{"version":">=13.10, <13.10.4","status":"affected"},{"version":">=13.2, <13.9.7","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.9.7","matchCriteriaId":"FE5FFF9D-8164-4089-845D-2A31EDD42BDC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"13.9.7","matchCriteriaId":"F6C18AE0-8C12-417C-9CC2-010E1529D0D7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.10.0","versionEndExcluding":"13.10.4","matchCriteriaId":"6CF968F1-8F8D-49D6-995C-DC8366063DA8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.10.0","versionEndExcluding":"13.10.4","matchCriteriaId":"41CC3DA4-3515-4564-87F7-47478EB3DF27"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.11.0","versionEndExcluding":"13.11.2","matchCriteriaId":"CB870D06-315A-452D-B09C-9FDB8D426C89"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.11.0","versionEndExcluding":"13.11.2","matchCriteriaId":"811F3205-355F-463B-A050-7BA2010304E5"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22210.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/322500","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22210.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/322500","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2021-22214","sourceIdentifier":"cve@gitlab.com","published":"2021-06-08T15:15:07.817","lastModified":"2026-06-17T03:36:49.157","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE/EE affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is limited"},{"lang":"es","value":"Cuando se habilitan las peticiones a la red interna para los webhooks, una vulnerabilidad de tipo server-side request forgery en GitLab CE/EE que afecta a todas las versiones a partir desde 10.5, era posible de explotar por un atacante no autenticado incluso en una instancia de GitLab donde el registro está limitado"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=10.5, <13.10.5","status":"affected"},{"version":">=13.11, <13.11.5","status":"affected"},{"version":">=13.12, <13.12.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N","baseScore":6.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":4.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N","baseScore":8.6,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":4.0}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"10.5","versionEndExcluding":"13.10.5","matchCriteriaId":"E68DF969-6C35-4A0B-89B2-0CCDBBEC5FEF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.11","versionEndExcluding":"13.11.5","matchCriteriaId":"B468CD6B-3DBF-4259-A9E7-CD845E4D1B98"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.12","versionEndExcluding":"13.12.2","matchCriteriaId":"CE3BFA69-E4CF-440F-8DDC-03245F803C03"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22214.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/322926","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1110131","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22214.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/322926","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1110131","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-22215","sourceIdentifier":"cve@gitlab.com","published":"2021-06-08T16:15:13.473","lastModified":"2026-06-17T03:36:49.313","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An information disclosure vulnerability in GitLab EE versions 13.11 and later allowed a project owner to leak information about the members' on-call rotations in other projects"},{"lang":"es","value":"Una vulnerabilidad de divulgación de información en las versiones 13.11 y posteriores de GitLab EE, permitía a un propietario de proyecto filtrar información sobre las rotaciones de guardia de los miembros en otros proyectos"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.11, <13.11.5","status":"affected"},{"version":">=13.12, <13.12.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N","baseScore":2.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.11.0","versionEndExcluding":"13.11.5","matchCriteriaId":"36C14C68-B2DB-4EDB-9604-764D5CEC8C2C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.12.0","versionEndExcluding":"13.12.2","matchCriteriaId":"B3020FB1-3219-41FB-9E06-282E9F8075DD"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22215.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/328668","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22215.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/328668","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2021-22218","sourceIdentifier":"cve@gitlab.com","published":"2021-06-08T16:15:13.530","lastModified":"2026-06-17T03:36:49.703","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"All versions of GitLab CE/EE starting from 12.8 before 13.10.5, all versions starting from 13.11 before 13.11.5, and all versions starting from 13.12 before 13.12.2 were affected by an issue in the handling of x509 certificates that could be used to spoof author of signed commits."},{"lang":"es","value":"Todas las versiones de GitLab CE/EE a partir de la 12.8 antes de la 13.10.5, todas las versiones a partir de la 13.11 antes de la 13.11.5, y todas las versiones a partir de la 13.12 antes de la 13.12.2 se veían afectadas por un problema en el manejo de los certificados x509 que podía utilizarse para falsificar el autor de los commits firmados"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.8, <13.10.5","status":"affected"},{"version":">=13.11, <13.11.5","status":"affected"},{"version":">=13.12, <13.12.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N","baseScore":2.6,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N","baseScore":2.6,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-295"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.8.0","versionEndExcluding":"13.10.5","matchCriteriaId":"8DD9951D-A017-419D-A82F-229C8A839869"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.8.0","versionEndExcluding":"13.10.5","matchCriteriaId":"06CE7863-1C98-498D-881D-81224C762161"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.11.0","versionEndExcluding":"13.11.5","matchCriteriaId":"299084AF-AA62-4503-B9E8-3D44898553DF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.11.0","versionEndExcluding":"13.11.5","matchCriteriaId":"36C14C68-B2DB-4EDB-9604-764D5CEC8C2C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.12.0","versionEndExcluding":"13.12.2","matchCriteriaId":"F16BCB65-EA10-492B-B921-5F90632BA5E5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.12.0","versionEndExcluding":"13.12.2","matchCriteriaId":"B3020FB1-3219-41FB-9E06-282E9F8075DD"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22218.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/297665","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1077019","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22218.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/297665","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1077019","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-22213","sourceIdentifier":"cve@gitlab.com","published":"2021-06-08T19:15:07.973","lastModified":"2026-06-17T03:36:49.037","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A cross-site leak vulnerability in the OAuth flow of all versions of GitLab CE/EE since 7.10 allowed an attacker to leak an OAuth access token by getting the victim to visit a malicious page with Safari"},{"lang":"es","value":"Una vulnerabilidad de filtrado tipo cross-site en el flujo OAuth de todas las versiones de GitLab CE/EE desde versión 7.10, permitía a un atacante filtrar un token de acceso OAuth al hacer que la víctima visitara una página maliciosa con Safari"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=7.10, <13.10.5","status":"affected"},{"version":">=13.11, <13.11.5","status":"affected"},{"version":">=13.12, <13.12.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"7.10.0","versionEndExcluding":"13.10.5","matchCriteriaId":"DB45CA99-73C3-465D-BEC7-86FC77934BC5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"7.10.0","versionEndExcluding":"13.10.5","matchCriteriaId":"036070D6-620F-4B4A-AF3A-1DA9C6E95374"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.11.0","versionEndExcluding":"13.11.5","matchCriteriaId":"299084AF-AA62-4503-B9E8-3D44898553DF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.11.0","versionEndExcluding":"13.11.5","matchCriteriaId":"36C14C68-B2DB-4EDB-9604-764D5CEC8C2C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.12.0","versionEndExcluding":"13.12.2","matchCriteriaId":"F16BCB65-EA10-492B-B921-5F90632BA5E5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.12.0","versionEndExcluding":"13.12.2","matchCriteriaId":"B3020FB1-3219-41FB-9E06-282E9F8075DD"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22213.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/300308","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1089277","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22213.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/300308","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1089277","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-22217","sourceIdentifier":"cve@gitlab.com","published":"2021-06-08T19:15:08.040","lastModified":"2026-06-17T03:36:49.597","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A denial of service vulnerability in all versions of GitLab CE/EE before 13.12.2, 13.11.5 or 13.10.5 allows an attacker to cause uncontrolled resource consumption with a specially crafted issue or merge request"},{"lang":"es","value":"Una vulnerabilidad de denegación de servicio en GitLab CE/EE todas las versiones anteriores a 13.12.2, 13.11.5 o 13.10.5, permite a un atacante causar un consumo incontrolado de recursos con una petición de emisión o fusión especialmente diseñada"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":"<13.10.5","status":"affected"},{"version":">=13.11, <13.11.5","status":"affected"},{"version":">=13.12, <13.12.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:N/A:P","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"13.10.5","matchCriteriaId":"9F3DB664-C29D-46AB-9FE0-6675FDA3C575"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"13.10.5","matchCriteriaId":"8FC5C842-8FB2-4F52-83D1-16365659C7ED"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.11","versionEndExcluding":"13.11.5","matchCriteriaId":"FD4F2A93-8299-4AAF-B4DD-2BE34913DF17"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.11","versionEndExcluding":"13.11.5","matchCriteriaId":"4CE95C1D-18CB-4620-984C-E840749104DB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.12","versionEndExcluding":"13.12.2","matchCriteriaId":"099CA247-BCC0-4C7F-99C7-62CD6313D8F5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.12","versionEndExcluding":"13.12.2","matchCriteriaId":"5D4DCC40-F9C1-42F2-A068-6A97A449B2C2"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22217.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/300709","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1090049","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22217.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/300709","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1090049","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2021-22219","sourceIdentifier":"cve@gitlab.com","published":"2021-06-08T19:15:08.100","lastModified":"2026-06-17T03:36:49.813","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"All versions of GitLab CE/EE starting from 9.5 before 13.10.5, all versions starting from 13.11 before 13.11.5, and all versions starting from 13.12 before 13.12.2 allow a high privilege user to obtain sensitive information from log files because the sensitive information was not correctly registered for log masking."},{"lang":"es","value":"Todas las versiones de GitLab CE/EE a partir de la 9.5 antes de la 13.10.5, todas las versiones a partir de la 13.11 antes de la 13.11.5 y todas las versiones a partir de la 13.12 antes de la 13.12.2 permiten que un usuario con altos privilegios obtenga información sensible de los archivos de registro porque la información sensible no se registró correctamente para el enmascaramiento del registro"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=9.5, <13.10.5","status":"affected"},{"version":">=13.11, <13.11.5","status":"affected"},{"version":">=13.12, <13.12.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N","baseScore":4.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":0.7,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-532"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"9.5.0","versionEndExcluding":"13.10.5","matchCriteriaId":"D4E8053F-4A2A-4BD2-AB46-2B7F757B1153"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"9.5.0","versionEndExcluding":"13.10.5","matchCriteriaId":"F4DD7DA7-CB28-48C4-8CD0-AA8BCE4E4CEB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.11.0","versionEndExcluding":"13.11.5","matchCriteriaId":"299084AF-AA62-4503-B9E8-3D44898553DF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.11.0","versionEndExcluding":"13.11.5","matchCriteriaId":"36C14C68-B2DB-4EDB-9604-764D5CEC8C2C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.12.0","versionEndExcluding":"13.12.2","matchCriteriaId":"F16BCB65-EA10-492B-B921-5F90632BA5E5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.12.0","versionEndExcluding":"13.12.2","matchCriteriaId":"B3020FB1-3219-41FB-9E06-282E9F8075DD"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22219.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/296995","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22219.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/296995","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2021-22221","sourceIdentifier":"cve@gitlab.com","published":"2021-06-08T19:15:08.163","lastModified":"2026-06-17T03:36:50.037","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 12.9.0 before 13.10.5, all versions starting from 13.11.0 before 13.11.5, all versions starting from 13.12.0 before 13.12.2. Insufficient expired password validation in various operations allow user to maintain limited access after their password expired"},{"lang":"es","value":"Se ha detectado un problema en GitLab que afecta a todas las versiones a partir de la versión 12.9.0 versiones anteriores a 13.10.5, a todas las versiones a partir de la versión 13.11.0 versiones anteriores a 13.11.5, a todas las versiones a partir de la versión 13.12.0 versiones anteriores a 13.12.2. Una comprobación insuficiente de la contraseña expirada en varias operaciones permite al usuario mantener un acceso limitado después de que su contraseña haya expirado"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.12.0, <13.12.2","status":"affected"},{"version":">=13.11.0, <13.11.5","status":"affected"},{"version":">=12.9.0, <13.10.5","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":2.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":2.5}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:N","baseScore":6.4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-613"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.9.0","versionEndExcluding":"13.10.5","matchCriteriaId":"A62BFC69-BE91-4202-B134-DAB4DD3E052C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.9.0","versionEndExcluding":"13.10.5","matchCriteriaId":"943B7F69-3181-4D24-B114-18B2FCBAA7ED"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.11.0","versionEndExcluding":"13.11.5","matchCriteriaId":"299084AF-AA62-4503-B9E8-3D44898553DF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.11.0","versionEndExcluding":"13.11.5","matchCriteriaId":"36C14C68-B2DB-4EDB-9604-764D5CEC8C2C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.12.0","versionEndExcluding":"13.12.2","matchCriteriaId":"F16BCB65-EA10-492B-B921-5F90632BA5E5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.12.0","versionEndExcluding":"13.12.2","matchCriteriaId":"B3020FB1-3219-41FB-9E06-282E9F8075DD"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22221.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/292006","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22221.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/292006","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2021-22216","sourceIdentifier":"cve@gitlab.com","published":"2021-06-08T20:15:08.333","lastModified":"2026-06-17T03:36:49.493","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A denial of service vulnerability in all versions of GitLab CE/EE before 13.12.2, 13.11.5 or 13.10.5 allows an attacker to cause uncontrolled resource consumption with a very long issue or merge request description"},{"lang":"es","value":"Una vulnerabilidad de denegación de servicio en GitLab CE/EE todas las versiones anteriores a 13.12.2, 13.11.5 o 13.10.5, permite a un atacante causar un consumo no controlado de recursos con una descripción de petición de emisión o fusión muy larga"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":"<13.10.5","status":"affected"},{"version":">=13.11, <13.11.5","status":"affected"},{"version":">=13.12, <13.12.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:N/A:P","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-400"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"13.10.5","matchCriteriaId":"9F3DB664-C29D-46AB-9FE0-6675FDA3C575"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"13.10.5","matchCriteriaId":"8FC5C842-8FB2-4F52-83D1-16365659C7ED"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.11.0","versionEndExcluding":"13.11.5","matchCriteriaId":"299084AF-AA62-4503-B9E8-3D44898553DF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.11.0","versionEndExcluding":"13.11.5","matchCriteriaId":"36C14C68-B2DB-4EDB-9604-764D5CEC8C2C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.12.0","versionEndExcluding":"13.12.2","matchCriteriaId":"F16BCB65-EA10-492B-B921-5F90632BA5E5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.12.0","versionEndExcluding":"13.12.2","matchCriteriaId":"B3020FB1-3219-41FB-9E06-282E9F8075DD"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22216.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/329890","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22216.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/329890","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2021-22220","sourceIdentifier":"cve@gitlab.com","published":"2021-06-08T20:15:08.400","lastModified":"2026-06-17T03:36:49.927","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting with 13.10. GitLab was vulnerable to a stored XSS in blob viewer of notebooks."},{"lang":"es","value":"Se ha detectado un problema en GitLab que afecta a todas las versiones a partir de la versión 13.10. GitLab era vulnerable a un ataque de tipo XSS almacenado en el visualizador de blob de cuadernos"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.12, <13.12.2","status":"affected"},{"version":">=13.11, <13.11.5","status":"affected"},{"version":">=13.10, <13.10.5","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.10","versionEndIncluding":"13.10.5","matchCriteriaId":"6405385D-848B-4D65-B956-94B2F8B5D976"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.11","versionEndIncluding":"13.11.5","matchCriteriaId":"C7CA3FEA-F4BA-48F9-9CE9-D28E22A3BB3A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.12","versionEndIncluding":"13.12.2","matchCriteriaId":"AA29A82E-2FB1-49EC-8F0D-884090A66A8E"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22220.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/294128","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1060114","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22220.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/294128","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1060114","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2021-22175","sourceIdentifier":"cve@gitlab.com","published":"2021-06-11T16:15:09.023","lastModified":"2026-06-17T03:36:44.653","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is disabled"},{"lang":"es","value":"Cuando se habilitan las peticiones a la red interna para los webhooks, una vulnerabilidad de tipo server-side request forgery en GitLab que afecta a todas las versiones desde 10.5, era posible explotar por un atacante no autenticado incluso en una instancia de GitLab en la que el registro está deshabilitado"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=10.5, <13.6.7","status":"affected"},{"version":">=13.7, <13.7.7","status":"affected"},{"version":">=13.8, <13.8.4","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N","baseScore":6.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":4.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-02-18T00:00:00+00:00","id":"CVE-2021-22175","options":[{"exploitation":"active"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"cisaExploitAdd":"2026-02-18","cisaActionDue":"2026-03-11","cisaRequiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","cisaVulnerabilityName":"GitLab Server-Side Request Forgery (SSRF) Vulnerability","weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.5.0","versionEndExcluding":"13.6.7","matchCriteriaId":"DE63DB65-205A-4ED6-8B6C-2B2B33F1E757"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.5.0","versionEndExcluding":"13.6.7","matchCriteriaId":"C3B65808-C140-43B2-8264-56A1BCE86A86"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"13.7.7","matchCriteriaId":"4BBAF21A-84DD-4987-B4BE-2A8CAA44210A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"13.7.7","matchCriteriaId":"9AE735A5-FC67-4B16-B27B-86C51C8771C1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.8.0","versionEndExcluding":"13.8.4","matchCriteriaId":"D3009669-C930-4517-914D-5DB9A0E40B59"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.8.0","versionEndExcluding":"13.8.4","matchCriteriaId":"9F7976E8-BDA5-4104-AC3E-38C02CC613A7"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22175.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/294178","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1059596","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22175.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/294178","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1059596","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-22175","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"]}]}},{"cve":{"id":"CVE-2021-22181","sourceIdentifier":"cve@gitlab.com","published":"2021-06-11T16:15:09.093","lastModified":"2026-06-17T03:36:45.347","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A denial of service vulnerability in GitLab CE/EE affecting all versions since 11.8 allows an attacker to create a recursive pipeline relationship and exhaust resources."},{"lang":"es","value":"Una vulnerabilidad de denegación de servicio en GitLab CE/EE que afecta a todas las versiones desde 11.8, permite a un atacante crear una relación de pipeline recursiva y agotar los recursos"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=11.8, <13.10.5","status":"affected"},{"version":">=13.11, <13.11.5","status":"affected"},{"version":">=13.12, <13.12.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H","baseScore":7.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.1,"impactScore":4.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:N/A:P","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-400"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"13.10.5","matchCriteriaId":"5D74618C-27BD-40A5-AD69-11E13F7288A9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"13.10.5","matchCriteriaId":"C252F358-F6B0-4330-8E41-85AB4BCF9739"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.11.0","versionEndExcluding":"13.11.5","matchCriteriaId":"299084AF-AA62-4503-B9E8-3D44898553DF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.11.0","versionEndExcluding":"13.11.5","matchCriteriaId":"36C14C68-B2DB-4EDB-9604-764D5CEC8C2C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.12.0","versionEndExcluding":"13.12.2","matchCriteriaId":"F16BCB65-EA10-492B-B921-5F90632BA5E5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.12.0","versionEndExcluding":"13.12.2","matchCriteriaId":"B3020FB1-3219-41FB-9E06-282E9F8075DD"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22181.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/249100","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22181.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/249100","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2021-32823","sourceIdentifier":"security-advisories@github.com","published":"2021-06-24T00:15:08.103","lastModified":"2026-06-17T03:53:42.240","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In the bindata RubyGem before version 2.4.10 there is a potential denial-of-service vulnerability. In affected versions it is very slow for certain classes in BinData to be created. For example BinData::Bit100000, BinData::Bit100001, BinData::Bit100002, BinData::Bit<N>. In combination with <user_input>.constantize there is a potential for a CPU-based DoS. In version 2.4.10 bindata improved the creation time of Bits and Integers."},{"lang":"es","value":"En bindata RubyGem versiones anteriores a 2.4.10, presenta una vulnerabilidad potencial de denegación de servicio.&#xa0;En las versiones afectadas, es muy lento crear determinadas clases en BinData.&#xa0;Por ejemplo,BinData::Bit100000, BinData::Bit100001, BinData::Bit100002, BinData::Bit(N).&#xa0;En combinación con (user_input) .constantize, se presenta la posibilidad de un DoS basado en CPU.&#xa0;En la versión 2.4.10 bindata mejoró el tiempo de creación de Bits e Integers"}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"dmendel","product":"bindata","versions":[{"version":"< 2.4.10","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":3.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.2,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":3.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.2,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:N/A:P","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-400"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:bindata_project:bindata:*:*:*:*:*:ruby:*:*","versionEndExcluding":"2.4.10","matchCriteriaId":"F3FDB12D-A7D5-4E28-9515-94054E69934D"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.0","versionEndExcluding":"13.10.5","matchCriteriaId":"4DCC45E4-7F83-4352-A2E0-3F07A7B718A2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.0","versionEndExcluding":"13.10.5","matchCriteriaId":"70D08D88-CFDF-48ED-B767-BA4A048DA9CD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.11.0","versionEndExcluding":"13.11.5","matchCriteriaId":"299084AF-AA62-4503-B9E8-3D44898553DF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.11.0","versionEndExcluding":"13.11.5","matchCriteriaId":"36C14C68-B2DB-4EDB-9604-764D5CEC8C2C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.12.0","versionEndExcluding":"13.12.2","matchCriteriaId":"F16BCB65-EA10-492B-B921-5F90632BA5E5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.12.0","versionEndExcluding":"13.12.2","matchCriteriaId":"B3020FB1-3219-41FB-9E06-282E9F8075DD"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2021/06/01/security-release-gitlab-13-12-2-released/#update-bindata-dependency","source":"security-advisories@github.com","tags":["Third Party Advisory"]},{"url":"https://github.com/dmendel/bindata/blob/v2.4.10/ChangeLog.rdoc#version-2410-2021-05-18-","source":"security-advisories@github.com","tags":["Third Party Advisory"]},{"url":"https://github.com/dmendel/bindata/commit/d99f050b88337559be2cb35906c1f8da49531323","source":"security-advisories@github.com","tags":["Patch","Third Party Advisory"]},{"url":"https://github.com/rubysec/ruby-advisory-db/issues/476","source":"security-advisories@github.com","tags":["Exploit","Patch","Third Party Advisory"]},{"url":"https://rubygems.org/gems/bindata","source":"security-advisories@github.com","tags":["Third Party Advisory"]},{"url":"https://about.gitlab.com/releases/2021/06/01/security-release-gitlab-13-12-2-released/#update-bindata-dependency","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://github.com/dmendel/bindata/blob/v2.4.10/ChangeLog.rdoc#version-2410-2021-05-18-","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://github.com/dmendel/bindata/commit/d99f050b88337559be2cb35906c1f8da49531323","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"]},{"url":"https://github.com/rubysec/ruby-advisory-db/issues/476","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Patch","Third Party Advisory"]},{"url":"https://rubygems.org/gems/bindata","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-22226","sourceIdentifier":"cve@gitlab.com","published":"2021-07-06T21:15:07.973","lastModified":"2026-06-17T03:36:50.590","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Under certain conditions, some users were able to push to protected branches that were restricted to deploy keys in GitLab CE/EE since version 13.9"},{"lang":"es","value":"Bajo determinadas condiciones, algunos usuarios eran capaces de empujar a ramas protegidas que estaban restringidas a claves de despliegue en GitLab CE/EE desde la versión 13.9"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.9, <13.11.6","status":"affected"},{"version":">=13.12, <13.12.6","status":"affected"},{"version":">=14.0, <14.0.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":5.2}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:P/I:P/A:N","baseScore":4.9,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":6.8,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.9.0","versionEndExcluding":"13.11.6","matchCriteriaId":"49B09708-1151-431E-BBA1-74849FE3CD4E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.9.0","versionEndExcluding":"13.11.6","matchCriteriaId":"3F7005C5-F6A9-497B-80B3-A28ABB6CE855"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.12.0","versionEndExcluding":"13.12.6","matchCriteriaId":"49D0A6F1-9FF4-45DA-941D-DBD1F08AFBA4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.12.0","versionEndExcluding":"13.12.6","matchCriteriaId":"DFAF5417-14DB-46E8-9EA7-5E3A9CB2384B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.0.2","matchCriteriaId":"4A2607F6-9727-48E7-A7CE-FE3B8B5B079B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.0.2","matchCriteriaId":"67B269DA-4E25-49D2-A679-D53E5969BF42"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22226.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/326684","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22226.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/326684","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2021-22229","sourceIdentifier":"cve@gitlab.com","published":"2021-07-06T21:15:08.033","lastModified":"2026-06-17T03:36:50.900","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.8. Under a special condition it was possible to access data of an internal repository through project fork done by a project member."},{"lang":"es","value":"Se ha detectado un problema en GitLab CE/EE afectando a todas las versiones a partir de la versión 12.8. Bajo una condición especial era posible acceder a los datos de un repositorio interno por medio del fork del proyecto realizado por un miembro del proyecto"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.8, <13.11.6","status":"affected"},{"version":">=13.12, <13.12.6","status":"affected"},{"version":">=14.0, <14.0.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"12.8","versionEndExcluding":"13.11.6","matchCriteriaId":"16A022F6-E7BC-4CF6-A843-3475FB1F2104"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.12.0","versionEndExcluding":"13.12.6","matchCriteriaId":"690B9807-B9CE-4C31-B944-219F49470468"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.0.2","matchCriteriaId":"B1ABD362-D7CF-4D16-9A7E-5A9231617BED"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22229.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/332609","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22229.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/332609","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2021-22232","sourceIdentifier":"cve@gitlab.com","published":"2021-07-06T21:15:08.093","lastModified":"2026-06-17T03:36:51.220","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"HTML injection was possible via the full name field before versions 13.11.6, 13.12.6, and 14.0.2 in GitLab CE"},{"lang":"es","value":"Una inyección de HTML era posible por medio del campo full name en versiones anteriores a 13.11.6, 13.12.6 y 14.0.2 en GitLab CE"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=9.5, <13.11.6","status":"affected"},{"version":">=13.12, <13.12.6","status":"affected"},{"version":">=14.0, <14.0.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N","baseScore":3.5,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-74"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"9.5.0","versionEndExcluding":"13.11.6","matchCriteriaId":"E5414231-1AFA-477E-B2D4-F120F0A95BC1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.12.0","versionEndExcluding":"13.12.6","matchCriteriaId":"49D0A6F1-9FF4-45DA-941D-DBD1F08AFBA4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.0.2","matchCriteriaId":"4A2607F6-9727-48E7-A7CE-FE3B8B5B079B"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22232.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/300713","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1090634","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22232.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/300713","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1090634","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2021-22223","sourceIdentifier":"cve@gitlab.com","published":"2021-07-06T22:15:08.407","lastModified":"2026-06-17T03:36:50.260","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Client-Side code injection through Feature Flag name in GitLab CE/EE starting with 11.9 allows a specially crafted feature flag name to PUT requests on behalf of other users via clicking on a link"},{"lang":"es","value":"Una inyección de código del lado del cliente mediante la funcionalidad Flag name en GitLab CE/EE a partir de la versión 11.9 permite que una funcionalidad Flag name especialmente diseñada realice peticiones PUT en nombre de otros usuarios por medio de un click a un enlace"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=11.9, <13.11.6","status":"affected"},{"version":">=13.12, <13.12.6","status":"affected"},{"version":">=14.0, <14.0.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.9.0","versionEndExcluding":"13.11.6","matchCriteriaId":"49B09708-1151-431E-BBA1-74849FE3CD4E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.9.0","versionEndExcluding":"13.11.6","matchCriteriaId":"3F7005C5-F6A9-497B-80B3-A28ABB6CE855"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.12.0","versionEndExcluding":"13.12.6","matchCriteriaId":"49D0A6F1-9FF4-45DA-941D-DBD1F08AFBA4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.12.0","versionEndExcluding":"13.12.6","matchCriteriaId":"DFAF5417-14DB-46E8-9EA7-5E3A9CB2384B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.0.2","matchCriteriaId":"4A2607F6-9727-48E7-A7CE-FE3B8B5B079B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.0.2","matchCriteriaId":"67B269DA-4E25-49D2-A679-D53E5969BF42"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22223.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/293946","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1059557","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22223.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/293946","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1059557","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2021-22228","sourceIdentifier":"cve@gitlab.com","published":"2021-07-06T22:15:08.470","lastModified":"2026-06-17T03:36:50.797","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions before 13.11.6, all versions starting from 13.12 before 13.12.6, and all versions starting from 14.0 before 14.0.2. Improper access control allows unauthorised users to access project details using Graphql."},{"lang":"es","value":"Se ha descubierto un problema en GitLab que afecta a todas las versiones anteriores a la 13.11.6, a todas las versiones a partir de la 13.12 antes de la 13.12.6 y a todas las versiones a partir de la 14.0 antes de la 14.0.2. Un control de acceso inadecuado permite a usuarios no autorizados acceder a los detalles del proyecto utilizando Graphql"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":"<13.11.6","status":"affected"},{"version":">=13.12, <13.12.6","status":"affected"},{"version":">=14.0, <14.0.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionEndExcluding":"13.11.6","matchCriteriaId":"A4F2AE54-50F3-474E-82A7-E731151241FE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.12.0","versionEndExcluding":"13.12.6","matchCriteriaId":"690B9807-B9CE-4C31-B944-219F49470468"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.0.2","matchCriteriaId":"B1ABD362-D7CF-4D16-9A7E-5A9231617BED"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22228.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/332605","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking","Patch","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1192460","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22228.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/332605","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Patch","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1192460","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-22227","sourceIdentifier":"cve@gitlab.com","published":"2021-07-07T11:15:08.347","lastModified":"2026-06-17T03:36:50.690","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A reflected cross-site script vulnerability in GitLab before versions 13.11.6, 13.12.6 and 14.0.2 allowed an attacker to send a malicious link to a victim and trigger actions on their behalf if they clicked it"},{"lang":"es","value":"Una vulnerabilidad de tipo cross-site script reflejada en GitLab versiones anteriores a 13.11.6, 13.12.6 y 14.0.2, permitía a un atacante enviar un enlace malicioso a una víctima y desencadenar acciones en su nombre si hacían clic en él"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.9, <13.11.6","status":"affected"},{"version":">=13.12, <13.12.6","status":"affected"},{"version":">=14.0, <14.0.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:-:*:*:*","versionEndExcluding":"13.11.6","matchCriteriaId":"5105F5F8-6E83-4469-B27D-72BE2642B312"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:-:*:*:*","versionStartIncluding":"13.12.0","versionEndExcluding":"13.12.6","matchCriteriaId":"2BF23988-6B40-4E1B-9CEE-E9EEC2238013"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:-:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.0.2","matchCriteriaId":"7FB14BFE-6AC2-4817-9CA4-DDFC34D0AE7D"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22227.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/212887","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/834555","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22227.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/212887","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/834555","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2021-22230","sourceIdentifier":"cve@gitlab.com","published":"2021-07-07T11:15:08.477","lastModified":"2026-06-17T03:36:51.003","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Improper code rendering while rendering merge requests could be exploited to submit malicious code. This vulnerability affects GitLab CE/EE 9.3 and later through 13.11.6, 13.12.6, and 14.0.2."},{"lang":"es","value":"Una renderización inapropiada del código al renderizar las peticiones de fusión podría ser explotada para enviar código malicioso. Esta vulnerabilidad afecta a GitLab CE/EE versiones 9.3 y posteriores hasta 13.11.6, 13.12.6 y 14.0.2"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=9.3, <13.11.6","status":"affected"},{"version":">=13.12, <13.12.6","status":"affected"},{"version":">=14.0, <14.0.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"9.3.0","versionEndExcluding":"13.11.6","matchCriteriaId":"8CB3E7DA-E0E3-4A88-8267-75ABEBD344BA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.12.0","versionEndExcluding":"13.12.6","matchCriteriaId":"49D0A6F1-9FF4-45DA-941D-DBD1F08AFBA4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.0.2","matchCriteriaId":"4A2607F6-9727-48E7-A7CE-FE3B8B5B079B"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"9.3.0","versionEndExcluding":"13.11.6","matchCriteriaId":"4E2F1867-21A0-4C56-8458-3F25652918BA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.12.0","versionEndExcluding":"13.12.6","matchCriteriaId":"DFAF5417-14DB-46E8-9EA7-5E3A9CB2384B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.0.2","matchCriteriaId":"67B269DA-4E25-49D2-A679-D53E5969BF42"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22230.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/211976","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22230.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/211976","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2021-22231","sourceIdentifier":"cve@gitlab.com","published":"2021-07-07T11:15:08.540","lastModified":"2026-06-17T03:36:51.113","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A denial of service in user's profile page is found starting with GitLab CE/EE 8.0 that allows attacker to reject access to their profile page via using a specially crafted username."},{"lang":"es","value":"Se ha detectado una denegación de servicio en la página de perfil del usuario a partir de GitLab CE/EE versión 8.0, que permite a un atacante rechazar el acceso a su página de perfil por medio de un nombre de usuario especialmente diseñado"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=8.0, <13.11.6","status":"affected"},{"version":">=13.12, <13.12.6","status":"affected"},{"version":">=14.0, <14.0.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L","baseScore":3.5,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.1,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:N/A:P","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.0.0","versionEndExcluding":"13.11.6","matchCriteriaId":"B548C443-FE9B-4531-B4A6-0AAA2EAEE06E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.12.0","versionEndExcluding":"13.12.6","matchCriteriaId":"49D0A6F1-9FF4-45DA-941D-DBD1F08AFBA4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.0.2","matchCriteriaId":"4A2607F6-9727-48E7-A7CE-FE3B8B5B079B"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.0.0","versionEndExcluding":"13.11.6","matchCriteriaId":"7A218D8D-3C07-43A8-B656-BC2BD39FD64F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.12.0","versionEndExcluding":"13.12.6","matchCriteriaId":"DFAF5417-14DB-46E8-9EA7-5E3A9CB2384B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.0.2","matchCriteriaId":"67B269DA-4E25-49D2-A679-D53E5969BF42"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22231.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/26295","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/475098","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22231.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/26295","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/475098","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2021-22224","sourceIdentifier":"cve@gitlab.com","published":"2021-07-07T12:15:08.310","lastModified":"2026-06-17T03:36:50.367","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A cross-site request forgery vulnerability in the GraphQL API in GitLab since version 13.12 and before versions 13.12.6 and 14.0.2 allowed an attacker to call mutations as the victim"},{"lang":"es","value":"Una vulnerabilidad de tipo cross-site request forgery en la API GraphQL en GitLab desde la versión 13.12 y versiones anteriores a 13.12.6 y 14.0.2, permitía a un atacante llamar a mutaciones como la víctima"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.12, <13.12.6","status":"affected"},{"version":">=14.0, <14.0.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":4.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-352"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.12.0","versionEndExcluding":"13.12.6","matchCriteriaId":"690B9807-B9CE-4C31-B944-219F49470468"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.0.2","matchCriteriaId":"B1ABD362-D7CF-4D16-9A7E-5A9231617BED"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22224.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/324397","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1122408","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22224.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/324397","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1122408","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2021-22225","sourceIdentifier":"cve@gitlab.com","published":"2021-07-07T12:15:08.380","lastModified":"2026-06-17T03:36:50.483","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Insufficient input sanitization in markdown in GitLab version 13.11 and up allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted markdown"},{"lang":"es","value":"Un saneamiento insuficiente de entrada en markdown en GitLab versión 13.11 y superiores permite a un atacante explotar una vulnerabilidad de tipo cross-site scripting almacenada por medio de un markdown especialmente diseñado"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.11.3, <13.11.6","status":"affected"},{"version":">=13.12, <13.12.6","status":"affected"},{"version":">=14.0, <14.0.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":4.7,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.11.3","versionEndExcluding":"13.11.6","matchCriteriaId":"DE7F35FA-F0AD-4D45-924B-EA3679D2775F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.12.0","versionEndExcluding":"13.12.6","matchCriteriaId":"690B9807-B9CE-4C31-B944-219F49470468"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.0.2","matchCriteriaId":"B1ABD362-D7CF-4D16-9A7E-5A9231617BED"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22225.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/331051","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22225.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/331051","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2021-22233","sourceIdentifier":"cve@gitlab.com","published":"2021-07-07T14:15:09.977","lastModified":"2026-06-17T03:36:51.323","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An information disclosure vulnerability in GitLab EE versions 13.10 and later allowed a user to read project details"},{"lang":"es","value":"Una vulnerabilidad de divulgación de información en GitLab EE versiones 13.10 y posteriores, permitía a un usuario leer detalles del proyecto"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.10, <13.11.6","status":"affected"},{"version":">=13.12, <13.12.6","status":"affected"},{"version":">=14.0, <14.0.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.10.0","versionEndExcluding":"13.11.6","matchCriteriaId":"0287D902-50DB-47A1-B167-E955002D9036"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.12.0","versionEndExcluding":"13.12.6","matchCriteriaId":"DFAF5417-14DB-46E8-9EA7-5E3A9CB2384B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.0.2","matchCriteriaId":"67B269DA-4E25-49D2-A679-D53E5969BF42"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22233.json","source":"cve@gitlab.com","tags":["Exploit","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/329446","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22233.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/329446","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2021-22240","sourceIdentifier":"cve@gitlab.com","published":"2021-08-05T20:15:07.783","lastModified":"2026-06-17T03:36:52.070","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Improper access control in GitLab EE versions 13.11.6, 13.12.6, and 14.0.2 allows users to be created via single sign on despite user cap being enabled"},{"lang":"es","value":"Un control de acceso inapropiado en GitLab EE versiones 13.11.6, 13.12.6 y 14.0.2, permite la creación de usuarios por medio de single sign on a pesar de estar habilitado el user cap"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab EE","versions":[{"version":">=13.7, <13.11.6","status":"affected"},{"version":">=13.12, <13.12.6","status":"affected"},{"version":">=14.0, <14.0.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","baseScore":4.2,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":2.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"13.11.6","matchCriteriaId":"ABC94B41-7363-4D53-A4F0-695513355565"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.12.0","versionEndExcluding":"13.12.6","matchCriteriaId":"DFAF5417-14DB-46E8-9EA7-5E3A9CB2384B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.0.2","matchCriteriaId":"67B269DA-4E25-49D2-A679-D53E5969BF42"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22240.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/327641","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1166566","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22240.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/327641","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1166566","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-22241","sourceIdentifier":"cve@gitlab.com","published":"2021-08-05T20:15:07.870","lastModified":"2026-06-17T03:36:52.177","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0. It was possible to exploit a stored cross-site-scripting via a specifically crafted default branch name."},{"lang":"es","value":"Se ha detectado un problema en GitLab CE/EE afectando a todas las versiones a partir de 14.0. Era posible explotar una vulnerabilidad de tipo cross-site-scripting almacenado por medio de un nombre de rama predeterminado específicamente diseñado"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=14.1, <14.1.2","status":"affected"},{"version":">=14.0, <14.0.7","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.0.7","matchCriteriaId":"7BAF03F5-F078-4080-9F72-B51DE3F0EFD8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.0.7","matchCriteriaId":"80FE53A3-015A-41EF-B238-DEE9AB2FEF8C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"14.1.2","matchCriteriaId":"F02DE4BD-E3C7-491A-9FA7-EB3ED914480F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"14.1.2","matchCriteriaId":"02027E6A-E1D7-4109-BC9A-2B6BC335BA20"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22241.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/336460","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1256777","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22241.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/336460","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1256777","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-22234","sourceIdentifier":"cve@gitlab.com","published":"2021-08-05T21:15:10.870","lastModified":"2026-06-17T03:36:51.430","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.11 before 13.11.7, all versions starting from 13.12 before 13.12.8, and all versions starting from 14.0 before 14.0.4. A specially crafted design image allowed attackers to read arbitrary files on the server."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones a partir de la 13.11 antes de la 13.11.7, a todas las versiones a partir de la 13.12 antes de la 13.12.8 y a todas las versiones a partir de la 14.0 antes de la 14.0.4. Una imagen de diseño especialmente diseñada permitía a los atacantes leer archivos arbitrarios en el servidor"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=14.0, <14.0.4","status":"affected"},{"version":">=13.12, <13.12.8","status":"affected"},{"version":">=13.11, <13.11.7","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N","baseScore":9.6,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.11.0","versionEndIncluding":"13.11.7","matchCriteriaId":"6054239C-6565-4A2B-B89B-1227ABCFD2DD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.11.0","versionEndIncluding":"13.11.7","matchCriteriaId":"607EAE34-2962-4EA2-A78C-3C91357074DA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.12.0","versionEndIncluding":"13.12.8","matchCriteriaId":"63624DE8-5DCF-4A01-A992-5AAB2940224F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.12.0","versionEndIncluding":"13.12.8","matchCriteriaId":"7DC54E9B-DD1E-4111-9661-12952DAD41CF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.0.0","versionEndIncluding":"14.0.4","matchCriteriaId":"81BD24C6-BE7B-4770-80E8-683427C98795"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.0.0","versionEndIncluding":"14.0.4","matchCriteriaId":"CDB584A1-A659-45CA-ABF8-DF35EB234834"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22234.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/335205","source":"cve@gitlab.com","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1212067","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22234.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/335205","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1212067","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-22238","sourceIdentifier":"cve@gitlab.com","published":"2021-08-20T18:15:07.460","lastModified":"2026-06-17T03:36:51.860","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting with 13.3. GitLab was vulnerable to a stored XSS by using the design feature in issues."},{"lang":"es","value":"Se ha detectado un problema en GitLab, afectando a todas las versiones a partir de la 13.3. GitLab era vulnerable a un ataque de tipo XSS almacenado al usar la funcionalidad design en los issues."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=14.1, <14.1.2","status":"affected"},{"version":">=14.0, <14.0.7","status":"affected"},{"version":">13.3, <13.12.9","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N","baseScore":6.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":4.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.12.9","matchCriteriaId":"98C17AD6-0104-4C5E-AF12-01FDBB4FBDFA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.12.9","matchCriteriaId":"D4045B6B-9856-4599-B39D-6A8F408ED775"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.0.7","matchCriteriaId":"7BAF03F5-F078-4080-9F72-B51DE3F0EFD8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.0.7","matchCriteriaId":"80FE53A3-015A-41EF-B238-DEE9AB2FEF8C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"14.1.2","matchCriteriaId":"F02DE4BD-E3C7-491A-9FA7-EB3ED914480F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"14.1.2","matchCriteriaId":"02027E6A-E1D7-4109-BC9A-2B6BC335BA20"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22238.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/332420","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1212067","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22238.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/332420","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1212067","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-22246","sourceIdentifier":"cve@gitlab.com","published":"2021-08-20T18:15:07.523","lastModified":"2026-06-17T03:36:52.730","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability was discovered in GitLab versions before 14.0.2, 13.12.6, 13.11.6. GitLab Webhook feature could be abused to perform denial of service attacks."},{"lang":"es","value":"Se ha detectado una vulnerabilidad en GitLab versiones anteriores a 14.0.2, 13.12.6 y 13.11.6. La funcionalidad GitLab Webhook podría ser abusada para llevar a cabo ataques de denegación de servicio."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=2.0, <13.11.6","status":"affected"},{"version":">=13.12, <13.12.6","status":"affected"},{"version":">=14.0, <14.0.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H","baseScore":7.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.1,"impactScore":4.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:N/A:P","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"2.0.0","versionEndExcluding":"13.11.6","matchCriteriaId":"9EF0E17B-3035-4F17-AA37-B63BB91972C1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"2.0.0","versionEndExcluding":"13.11.6","matchCriteriaId":"5DD85980-606D-498F-85EE-A464253DF63E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.12.0","versionEndExcluding":"13.12.6","matchCriteriaId":"49D0A6F1-9FF4-45DA-941D-DBD1F08AFBA4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.12.0","versionEndExcluding":"13.12.6","matchCriteriaId":"DFAF5417-14DB-46E8-9EA7-5E3A9CB2384B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.0.2","matchCriteriaId":"4A2607F6-9727-48E7-A7CE-FE3B8B5B079B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.0.2","matchCriteriaId":"67B269DA-4E25-49D2-A679-D53E5969BF42"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22246.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/280633","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1029269","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22246.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/280633","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1029269","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-22254","sourceIdentifier":"cve@gitlab.com","published":"2021-08-20T18:15:07.577","lastModified":"2026-06-17T03:36:53.607","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Under very specific conditions a user could be impersonated using Gitlab shell. This vulnerability affects GitLab CE/EE 13.1 and later through 14.1.2, 14.0.7 and 13.12.9."},{"lang":"es","value":"En condiciones muy específicas se podría suplantar la identidad de un usuario usando el shell de Gitlab. Esta vulnerabilidad afecta a GitLab CE/EE versión 13.1 y posteriores hasta 14.1.2, 14.0.7 y 13.12.9."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.1, <13.12.9","status":"affected"},{"version":">=14.0, <14.0.7","status":"affected"},{"version":">=14.1, <14.1.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":3.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:P/I:N/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-116"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.12.9","matchCriteriaId":"9347992E-92FB-495B-BC7E-D5423DEEE81E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.12.9","matchCriteriaId":"71EDEE6C-48CE-4624-BFC8-E14F90958453"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.0.7","matchCriteriaId":"7BAF03F5-F078-4080-9F72-B51DE3F0EFD8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.0.7","matchCriteriaId":"80FE53A3-015A-41EF-B238-DEE9AB2FEF8C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"14.1.2","matchCriteriaId":"F02DE4BD-E3C7-491A-9FA7-EB3ED914480F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"14.1.2","matchCriteriaId":"02027E6A-E1D7-4109-BC9A-2B6BC335BA20"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22254.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/300265","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1087806","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22254.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/300265","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1087806","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-22248","sourceIdentifier":"cve@gitlab.com","published":"2021-08-23T20:15:11.670","lastModified":"2026-06-17T03:36:52.947","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Improper authorization on the pipelines page in GitLab CE/EE affecting all versions since 13.12 allowed unauthorized users to view some pipeline information for public projects that have access to pipelines restricted to members only"},{"lang":"es","value":"Una autorización inapropiada en la página de pipelines en GitLab CE/EE, afectando a todas las versiones desde la 13.12, permitía a usuarios no autorizados visualizar determinada información de pipelines para proyectos públicos que tienen acceso a pipelines restringidos sólo a miembros."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.12, <13.12.9","status":"affected"},{"version":">=14.0, <14.0.7","status":"affected"},{"version":">=14.1, <14.1.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.12.0","versionEndExcluding":"13.12.9","matchCriteriaId":"6D5ECA66-57FA-4FAF-8166-7462696789F1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.12.0","versionEndExcluding":"13.12.9","matchCriteriaId":"A011DA14-CFC6-4A36-9904-2FA8677497FA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.0.7","matchCriteriaId":"7BAF03F5-F078-4080-9F72-B51DE3F0EFD8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.0.7","matchCriteriaId":"80FE53A3-015A-41EF-B238-DEE9AB2FEF8C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"14.1.2","matchCriteriaId":"F02DE4BD-E3C7-491A-9FA7-EB3ED914480F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"14.1.2","matchCriteriaId":"02027E6A-E1D7-4109-BC9A-2B6BC335BA20"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22248.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/336074","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22248.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/336074","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2021-22249","sourceIdentifier":"cve@gitlab.com","published":"2021-08-23T20:15:12.603","lastModified":"2026-06-17T03:36:53.053","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A verbose error message in GitLab EE affecting all versions since 12.2 could disclose the private email address of a user invited to a group"},{"lang":"es","value":"Un mensaje de error verboso en GitLab EE afectando a todas las versiones desde la 12.2, podía divulgar la dirección de correo electrónico privada de un usuario invitado a un grupo."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.2, <13.12.9","status":"affected"},{"version":">=14.0, <14.0.7","status":"affected"},{"version":">=14.1, <14.1.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-209"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"13.12.9","matchCriteriaId":"499474FA-2170-4BD6-985F-19A0D88681E4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"13.12.9","matchCriteriaId":"2D5D42B1-6E9E-43AF-9D34-08976153DB2C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.0.7","matchCriteriaId":"7BAF03F5-F078-4080-9F72-B51DE3F0EFD8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.0.7","matchCriteriaId":"80FE53A3-015A-41EF-B238-DEE9AB2FEF8C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"14.1.2","matchCriteriaId":"F02DE4BD-E3C7-491A-9FA7-EB3ED914480F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"14.1.2","matchCriteriaId":"02027E6A-E1D7-4109-BC9A-2B6BC335BA20"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22249.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/331857","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1204320","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22249.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/331857","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1204320","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-22251","sourceIdentifier":"cve@gitlab.com","published":"2021-08-23T20:15:12.830","lastModified":"2026-06-17T03:36:53.270","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Improper validation of invited users' email address in GitLab EE affecting all versions since 12.2 allowed projects to add members with email address domain that should be blocked by group settings"},{"lang":"es","value":"Una comprobación inapropiada de la dirección de correo electrónico de los usuarios invitados en GitLab EE, afectando a todas las versiones desde la 12.2, permitía que los proyectos añadieran miembros con un dominio de dirección de correo electrónico que debería estar bloqueado por la configuración del grupo."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.2, <13.12.9","status":"affected"},{"version":">=14.0, <14.0.7","status":"affected"},{"version":">=14.1, <14.1.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"13.12.9","matchCriteriaId":"2D5D42B1-6E9E-43AF-9D34-08976153DB2C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.0.7","matchCriteriaId":"80FE53A3-015A-41EF-B238-DEE9AB2FEF8C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"14.1.2","matchCriteriaId":"02027E6A-E1D7-4109-BC9A-2B6BC335BA20"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22251.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/14004","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/679567","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22251.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/14004","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/679567","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-22252","sourceIdentifier":"cve@gitlab.com","published":"2021-08-23T20:15:13.037","lastModified":"2026-06-17T03:36:53.373","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A confusion between tag and branch names in GitLab CE/EE affecting all versions since 13.7 allowed a Developer to access protected CI variables which should only be accessible to Maintainers"},{"lang":"es","value":"Una confusión entre los nombres de las etiquetas y ramas en GitLab CE/EE, afectando a todas las versiones desde la 13.7, permitía a un desarrollador acceder a variables de CI protegidas que sólo deberían ser accesibles para los mantenedores."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.7, <13.12.9","status":"affected"},{"version":">=14.0, <14.0.7","status":"affected"},{"version":">=14.1, <14.1.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"13.12.9","matchCriteriaId":"B6245A48-2068-4032-BCFA-4A4AAF7C633D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"13.12.9","matchCriteriaId":"08757B18-27B5-4136-9BA6-0122CF0455F2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.0.7","matchCriteriaId":"7BAF03F5-F078-4080-9F72-B51DE3F0EFD8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.0.7","matchCriteriaId":"80FE53A3-015A-41EF-B238-DEE9AB2FEF8C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"14.1.2","matchCriteriaId":"F02DE4BD-E3C7-491A-9FA7-EB3ED914480F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"14.1.2","matchCriteriaId":"02027E6A-E1D7-4109-BC9A-2B6BC335BA20"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22252.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/330364","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1186135","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22252.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/330364","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1186135","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-22253","sourceIdentifier":"cve@gitlab.com","published":"2021-08-23T20:15:13.257","lastModified":"2026-06-17T03:36:53.490","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Improper authorization in GitLab EE affecting all versions since 13.4 allowed a user who previously had the necessary access to trigger deployments to protected environments under specific conditions after the access has been removed"},{"lang":"es","value":"Una autorización inapropiada en GitLab EE que afectaba a todas las versiones desde la 13.4, permitía a un usuario que anteriormente tenía el acceso necesario desencadenar despliegues en entornos protegidos bajo condiciones específicas después de que se hubiera eliminado el acceso"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.4, <13.12.9","status":"affected"},{"version":">=14.0, <14.0.7","status":"affected"},{"version":">=14.1, <14.1.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:L","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":1.8,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":2.5}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:P","baseScore":4.9,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":6.8,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.4.0","versionEndExcluding":"13.12.9","matchCriteriaId":"57CF8C65-E69C-434A-87AC-A9474FCF66A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.4.0","versionEndExcluding":"13.12.9","matchCriteriaId":"6E32AD05-BAE2-43C5-B509-1F90093E3386"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.0.7","matchCriteriaId":"7BAF03F5-F078-4080-9F72-B51DE3F0EFD8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.0.7","matchCriteriaId":"80FE53A3-015A-41EF-B238-DEE9AB2FEF8C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"14.1.2","matchCriteriaId":"F02DE4BD-E3C7-491A-9FA7-EB3ED914480F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"14.1.2","matchCriteriaId":"02027E6A-E1D7-4109-BC9A-2B6BC335BA20"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22253.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/323794","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1113783","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22253.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/323794","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1113783","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-22236","sourceIdentifier":"cve@gitlab.com","published":"2021-08-25T19:15:10.207","lastModified":"2026-06-17T03:36:51.650","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Due to improper handling of OAuth client IDs, new subscriptions generated OAuth tokens on an incorrect OAuth client application. This vulnerability is present in GitLab CE/EE since version 14.1."},{"lang":"es","value":"Debido a un manejo inapropiado de los ID de cliente OAuth, las nuevas suscripciones generaban tokens OAuth en una aplicación de cliente OAuth incorrecta. Esta vulnerabilidad está presente en GitLab CE/EE desde la versión 14.1."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=14.1, <14.1.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":2.1,"impactScore":3.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"14.1.2","matchCriteriaId":"F02DE4BD-E3C7-491A-9FA7-EB3ED914480F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"14.1.2","matchCriteriaId":"02027E6A-E1D7-4109-BC9A-2B6BC335BA20"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22236.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/334925","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22236.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/334925","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2021-22237","sourceIdentifier":"cve@gitlab.com","published":"2021-08-25T19:15:10.600","lastModified":"2026-06-17T03:36:51.753","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Under specialized conditions, GitLab may allow a user with an impersonation token to perform Git actions even if impersonation is disabled. This vulnerability is present in GitLab CE/EE versions before 13.12.9, 14.0.7, 14.1.2"},{"lang":"es","value":"En condiciones especiales, GitLab puede permitir que un usuario con un token de suplantación lleve a cabo acciones de Git aunque la suplantación esté desactivada. Esta vulnerabilidad está presente en GitLab CE/EE versiones anteriores a 13.12.9, 14.0.7, 14.1.2"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.1, <13.12.9","status":"affected"},{"version":">=14.0, <14.0.7","status":"affected"},{"version":">=14.1, <14.1.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":6.6,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":0.7,"impactScore":5.9},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-384"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.12.9","matchCriteriaId":"9347992E-92FB-495B-BC7E-D5423DEEE81E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.12.9","matchCriteriaId":"71EDEE6C-48CE-4624-BFC8-E14F90958453"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.0.7","matchCriteriaId":"7BAF03F5-F078-4080-9F72-B51DE3F0EFD8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.0.7","matchCriteriaId":"80FE53A3-015A-41EF-B238-DEE9AB2FEF8C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"14.1.2","matchCriteriaId":"F02DE4BD-E3C7-491A-9FA7-EB3ED914480F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"14.1.2","matchCriteriaId":"02027E6A-E1D7-4109-BC9A-2B6BC335BA20"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22237.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/297516","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22237.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/297516","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2021-22242","sourceIdentifier":"cve@gitlab.com","published":"2021-08-25T19:15:10.750","lastModified":"2026-06-17T03:36:52.287","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Insufficient input sanitization in Mermaid markdown in GitLab CE/EE version 11.4 and up allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted markdown"},{"lang":"es","value":"Un saneo de entradas insuficiente en el markdown de Mermaid en GitLab CE/EE versión 11.4 y superiores, permite a un atacante explotar una vulnerabilidad de tipo cross-site scripting almacenado por medio de un markdown especialmente diseñado"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=11.4, <13.12.9","status":"affected"},{"version":">=14.0, <14.0.7","status":"affected"},{"version":">=14.1, <14.1.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"13.12.9","matchCriteriaId":"4DDEA7AE-C6EE-42DF-9BBB-159289A2BED5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"13.12.9","matchCriteriaId":"1235B1F6-02ED-40C0-BAD8-81D496CF7562"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.0.7","matchCriteriaId":"7BAF03F5-F078-4080-9F72-B51DE3F0EFD8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.0.7","matchCriteriaId":"80FE53A3-015A-41EF-B238-DEE9AB2FEF8C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"14.1.2","matchCriteriaId":"F02DE4BD-E3C7-491A-9FA7-EB3ED914480F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"14.1.2","matchCriteriaId":"02027E6A-E1D7-4109-BC9A-2B6BC335BA20"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22242.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/332528","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1212822","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22242.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/332528","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1212822","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-22243","sourceIdentifier":"cve@gitlab.com","published":"2021-08-25T19:15:11.010","lastModified":"2026-06-17T03:36:52.400","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Under specialized conditions, GitLab CE/EE versions starting 7.10 may allow existing GitLab users to use an invite URL meant for another email address to gain access into a group."},{"lang":"es","value":"En condiciones especiales, GitLab CE/EE versiones a partir de la 7.10, pueden permitir a usuarios existentes de GitLab usar una URL de invitación destinada a otra dirección de correo electrónico para conseguir acceso a un grupo."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=7.10, <13.12.9","status":"affected"},{"version":">=14.0, <14.0.7","status":"affected"},{"version":">=14.1, <14.1.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L","baseScore":5.0,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":1.6,"impactScore":3.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"7.10.0","versionEndExcluding":"13.12.9","matchCriteriaId":"299E64AB-88AD-42F1-93CA-862A34568E49"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"7.10.0","versionEndExcluding":"13.12.9","matchCriteriaId":"3E7A215E-541C-4537-87E5-5A134F66C2D3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.0.7","matchCriteriaId":"7BAF03F5-F078-4080-9F72-B51DE3F0EFD8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.0.7","matchCriteriaId":"80FE53A3-015A-41EF-B238-DEE9AB2FEF8C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"14.1.2","matchCriteriaId":"F02DE4BD-E3C7-491A-9FA7-EB3ED914480F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"14.1.2","matchCriteriaId":"02027E6A-E1D7-4109-BC9A-2B6BC335BA20"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22243.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/325934","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22243.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/325934","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2021-22244","sourceIdentifier":"cve@gitlab.com","published":"2021-08-25T19:15:11.200","lastModified":"2026-06-17T03:36:52.517","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Improper authorization in the vulnerability report feature in GitLab EE affecting all versions since 13.1 allowed a reporter to access vulnerability data"},{"lang":"es","value":"Una autorización inapropiada en la funcionalidad vulnerability report en GitLab EE, afectando a todas las versiones desde la 13.1, permitía a un informador acceder a los datos de la vulnerabilidad"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.1, <13.12.9","status":"affected"},{"version":">=14.0, <14.0.7","status":"affected"},{"version":">=14.1, <14.1.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":3.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"13.12.9","matchCriteriaId":"71EDEE6C-48CE-4624-BFC8-E14F90958453"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.0.7","matchCriteriaId":"80FE53A3-015A-41EF-B238-DEE9AB2FEF8C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"14.1.2","matchCriteriaId":"02027E6A-E1D7-4109-BC9A-2B6BC335BA20"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22244.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/299039","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1047140","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22244.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/299039","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1047140","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-22245","sourceIdentifier":"cve@gitlab.com","published":"2021-08-25T19:15:11.350","lastModified":"2026-06-17T03:36:52.627","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Improper validation of commit author in GitLab CE/EE affecting all versions allowed an attacker to make several pages in a project impossible to view"},{"lang":"es","value":"Una comprobación inapropiada del autor de los commit en GitLab CE/EE, afectando a todas las versiones, permitía a un atacante imposibilitar la visualización de varias páginas de un proyecto"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":"<13.12.9","status":"affected"},{"version":">=14.0, <14.0.7","status":"affected"},{"version":">=14.1, <14.1.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L","baseScore":2.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":1.2,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L","baseScore":2.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":1.2,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:N/A:P","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-20"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"13.12.9","matchCriteriaId":"E1E1D1F5-7EB7-41B4-A122-8B6DD40EC1FB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"13.12.9","matchCriteriaId":"8C66B593-5C4B-4E80-99B4-0F2CF0EDE166"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.0.7","matchCriteriaId":"7BAF03F5-F078-4080-9F72-B51DE3F0EFD8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.0.7","matchCriteriaId":"80FE53A3-015A-41EF-B238-DEE9AB2FEF8C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"14.1.2","matchCriteriaId":"F02DE4BD-E3C7-491A-9FA7-EB3ED914480F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"14.1.2","matchCriteriaId":"02027E6A-E1D7-4109-BC9A-2B6BC335BA20"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22245.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/255612","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/987689","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22245.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/255612","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/987689","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-22247","sourceIdentifier":"cve@gitlab.com","published":"2021-08-25T19:15:11.560","lastModified":"2026-06-17T03:36:52.840","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Improper authorization in GitLab CE/EE affecting all versions since 13.0 allows guests in private projects to view CI/CD analytics"},{"lang":"es","value":"Una autorización inapropiada en GitLab CE/EE, afectando a todas las versiones desde la 13.0, permite a invitados de proyectos privados visualizar los análisis de CI/CD."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.0, <13.12.9","status":"affected"},{"version":">=14.0, <14.0.7","status":"affected"},{"version":">=14.1, <14.1.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.0.0","versionEndExcluding":"13.12.9","matchCriteriaId":"2AAE6430-9B4C-45EC-A66D-44835B6D772D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.0.0","versionEndExcluding":"13.12.9","matchCriteriaId":"9665C026-AB2A-4AAD-97B7-1E75F7290233"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.0.7","matchCriteriaId":"7BAF03F5-F078-4080-9F72-B51DE3F0EFD8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.0.7","matchCriteriaId":"80FE53A3-015A-41EF-B238-DEE9AB2FEF8C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"14.1.2","matchCriteriaId":"F02DE4BD-E3C7-491A-9FA7-EB3ED914480F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"14.1.2","matchCriteriaId":"02027E6A-E1D7-4109-BC9A-2B6BC335BA20"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22247.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/299333","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1074326","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22247.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/299333","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1074326","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-22250","sourceIdentifier":"cve@gitlab.com","published":"2021-08-25T19:15:11.707","lastModified":"2026-06-17T03:36:53.160","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Improper authorization in GitLab CE/EE affecting all versions since 13.3 allowed users to view and delete impersonation tokens that administrators created for their account"},{"lang":"es","value":"Una autorización inapropiada en GitLab CE/EE, afectando a todas las versiones desde la 13.3, permitía a usuarios visualizar y eliminar los tokens de suplantación creados por los administradores para su cuenta."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.3, <13.12.9","status":"affected"},{"version":">=14.0, <14.0.7","status":"affected"},{"version":">=14.1, <14.1.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.5}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:N","baseScore":5.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.12.9","matchCriteriaId":"98C17AD6-0104-4C5E-AF12-01FDBB4FBDFA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"13.12.9","matchCriteriaId":"D4045B6B-9856-4599-B39D-6A8F408ED775"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.0.7","matchCriteriaId":"7BAF03F5-F078-4080-9F72-B51DE3F0EFD8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.0.7","matchCriteriaId":"80FE53A3-015A-41EF-B238-DEE9AB2FEF8C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"14.1.2","matchCriteriaId":"F02DE4BD-E3C7-491A-9FA7-EB3ED914480F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"14.1.2","matchCriteriaId":"02027E6A-E1D7-4109-BC9A-2B6BC335BA20"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22250.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/332410","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1205916","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22250.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/332410","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1205916","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-22256","sourceIdentifier":"cve@gitlab.com","published":"2021-08-25T19:15:11.793","lastModified":"2026-06-17T03:36:53.823","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Improper authorization in GitLab CE/EE affecting all versions since 12.6 allowed guest users to create issues for Sentry errors and track their status"},{"lang":"es","value":"Una autorización inapropiada en GitLab CE/EE, afectando a todas las versiones desde la 12.6, permitía a usuarios invitados crear problemas para los errores de Sentry y seguir su estado"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.6, <13.12.9","status":"affected"},{"version":">=14.0, <14.0.7","status":"affected"},{"version":">=14.1, <14.1.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.5}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:N","baseScore":5.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.6.0","versionEndExcluding":"13.12.9","matchCriteriaId":"56194586-FC63-4A31-BF87-8E454C986124"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.6.0","versionEndExcluding":"13.12.9","matchCriteriaId":"6E790CD7-5D26-49EA-AB46-78A1314C5036"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.0.7","matchCriteriaId":"7BAF03F5-F078-4080-9F72-B51DE3F0EFD8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.0.7","matchCriteriaId":"80FE53A3-015A-41EF-B238-DEE9AB2FEF8C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"14.1.2","matchCriteriaId":"F02DE4BD-E3C7-491A-9FA7-EB3ED914480F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"14.1.2","matchCriteriaId":"02027E6A-E1D7-4109-BC9A-2B6BC335BA20"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22256.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/326948","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1117768","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22256.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/326948","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1117768","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-22239","sourceIdentifier":"cve@gitlab.com","published":"2021-09-09T15:15:08.683","lastModified":"2026-06-17T03:36:51.970","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An unauthorized user was able to insert metadata when creating new issue on GitLab CE/EE 14.0 and later."},{"lang":"es","value":"Un usuario no autorizado podía insertar metadatos cuando creaba una nueva incidencia en GitLab CE/EE versiones 14.0 y posteriores"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=14.1, <14.1.2","status":"affected"},{"version":">=14.0, <14.0.7","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N","baseScore":5.0,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.0.7","matchCriteriaId":"7BAF03F5-F078-4080-9F72-B51DE3F0EFD8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.0.7","matchCriteriaId":"80FE53A3-015A-41EF-B238-DEE9AB2FEF8C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"14.1.2","matchCriteriaId":"F02DE4BD-E3C7-491A-9FA7-EB3ED914480F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"14.1.2","matchCriteriaId":"02027E6A-E1D7-4109-BC9A-2B6BC335BA20"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22239.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/336301","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22239.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/336301","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2021-22259","sourceIdentifier":"cve@gitlab.com","published":"2021-10-04T17:15:07.687","lastModified":"2026-06-17T03:36:54.157","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A potential DOS vulnerability was discovered in GitLab EE starting with version 12.6 due to lack of pagination in dependencies API."},{"lang":"es","value":"Se ha detectado una potencial vulnerabilidad de DOS en GitLab EE a partir de la versión 12.6, debido a una falta de paginación en la API de dependencias"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.6, <14.1.7","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:N/A:P","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.6.0","versionEndExcluding":"14.1.7","matchCriteriaId":"B811D1F7-9E49-4561-A941-0E6B1DDE02C0"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22259.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/335146","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22259.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/335146","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2021-39868","sourceIdentifier":"cve@gitlab.com","published":"2021-10-04T17:15:07.853","lastModified":"2026-06-17T04:04:19.807","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In all versions of GitLab CE/EE since version 8.12, an authenticated low-privileged malicious user may create a project with unlimited repository size by modifying values in a project export."},{"lang":"es","value":"En todas las versiones de GitLab CE/EE desde la versión 8.12, un usuario malicioso autenticado con pocos privilegios puede crear un proyecto con un tamaño de repositorio ilimitado modificando los valores de una exportación de proyecto"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=8.12, <14.1.7","status":"affected"},{"version":">=14.2, <14.2.5","status":"affected"},{"version":">=14.3, <14.3.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-732"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.12.0","versionEndExcluding":"14.1.7","matchCriteriaId":"66F73181-4C75-4B9D-B5C1-D5D974C09913"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.12.0","versionEndExcluding":"14.1.7","matchCriteriaId":"34400732-6C43-41C4-946E-FCA69E7BA43F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.5","matchCriteriaId":"CAB23F69-59A2-430F-A082-A5F81A7A464C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.5","matchCriteriaId":"CD7E2FAA-308F-450F-8990-52A7DEB8ED00"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:4.3.0:*:*:*:community:*:*:*","matchCriteriaId":"43C7D46F-A414-4818-B74C-547684E7B01D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:4.3.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"35B8762D-58EF-4F52-9C12-6CA842F2E195"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39868.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/24649","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/420258","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39868.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/24649","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/420258","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-39871","sourceIdentifier":"cve@gitlab.com","published":"2021-10-04T17:15:07.907","lastModified":"2026-06-17T04:04:20.140","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In all versions of GitLab CE/EE since version 13.0, an instance that has the setting to disable Bitbucket Server import enabled is bypassed by an attacker making a crafted API call."},{"lang":"es","value":"En todas las versiones de GitLab CE/EE desde la versión 13.0, una instancia que tenga activada la opción de deshabilitar la importación de Bitbucket Server puede ser omitida por un atacante que realice una llamada a la API diseñada"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.0, <14.1.7","status":"affected"},{"version":">=14.2, <14.2.5","status":"affected"},{"version":">=14.3, <14.3.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.0.0","versionEndExcluding":"14.1.7","matchCriteriaId":"609D7DAD-8BB9-4AE1-984C-1739B812D868"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.0.0","versionEndExcluding":"14.1.7","matchCriteriaId":"164E3D6C-24AB-411A-82BA-034B761C4423"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.5","matchCriteriaId":"CAB23F69-59A2-430F-A082-A5F81A7A464C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.5","matchCriteriaId":"CD7E2FAA-308F-450F-8990-52A7DEB8ED00"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:4.3.0:*:*:*:community:*:*:*","matchCriteriaId":"43C7D46F-A414-4818-B74C-547684E7B01D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:4.3.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"35B8762D-58EF-4F52-9C12-6CA842F2E195"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39871.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/340782","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/630263","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39871.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/340782","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/630263","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-39873","sourceIdentifier":"cve@gitlab.com","published":"2021-10-04T17:15:07.967","lastModified":"2026-06-17T04:04:20.360","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In all versions of GitLab CE/EE, there exists a content spoofing vulnerability which may be leveraged by attackers to trick users into visiting a malicious website by spoofing the content in an error response."},{"lang":"es","value":"En todas las versiones de GitLab CE/EE, se presenta una vulnerabilidad de suplantación de contenido que puede ser aprovechada por los atacantes para engañar a usuarios para que visiten un sitio web malicioso suplantando el contenido de una respuesta de error"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=1.0, <14.1.7","status":"affected"},{"version":">=14.2, <14.2.5","status":"affected"},{"version":">=14.3, <14.3.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"1.0.0","versionEndExcluding":"14.1.7","matchCriteriaId":"15511E8F-E088-49D8-BF62-7C0D3A5252BF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"1.0.0","versionEndExcluding":"14.1.7","matchCriteriaId":"C2FC870F-C488-49EF-92B2-A46CE6116A94"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.5","matchCriteriaId":"CAB23F69-59A2-430F-A082-A5F81A7A464C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.5","matchCriteriaId":"CD7E2FAA-308F-450F-8990-52A7DEB8ED00"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:4.3.0:*:*:*:community:*:*:*","matchCriteriaId":"43C7D46F-A414-4818-B74C-547684E7B01D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:4.3.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"35B8762D-58EF-4F52-9C12-6CA842F2E195"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39873.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/27241","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/504961","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39873.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/27241","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/504961","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-39874","sourceIdentifier":"cve@gitlab.com","published":"2021-10-04T17:15:08.027","lastModified":"2026-06-17T04:04:20.473","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In all versions of GitLab CE/EE since version 11.0, the requirement to enforce 2FA is not honored when using git commands."},{"lang":"es","value":"En todas las versiones de GitLab CE/EE a partir de la versión 11.0, no se cumple el requisito de aplicar 2FA cuando son usados comandos git"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=11.0, <14.1.7","status":"affected"},{"version":">=14.2, <14.2.5","status":"affected"},{"version":">=14.3, <14.3.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"14.1.7","matchCriteriaId":"2D710BE7-B04E-4A85-A041-2292926B1E7E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"14.1.7","matchCriteriaId":"FAC87DC2-2465-4C38-8968-0BF090F5B984"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.2","versionEndExcluding":"14.2.5","matchCriteriaId":"A3352A07-9A5A-4CA9-B6F6-71BA3A1D4F9C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.2","versionEndExcluding":"14.2.5","matchCriteriaId":"CAAC78F3-28E1-4A0D-BA8A-78AE9393B988"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.3","versionEndExcluding":"14.3.1","matchCriteriaId":"A573FB75-1C20-4E3A-982C-2B422C95BED8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.3","versionEndExcluding":"14.3.1","matchCriteriaId":"D0EFF286-2716-472C-AB8E-47595940C0B3"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39874.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/222527","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/898477","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39874.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/222527","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/898477","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-39877","sourceIdentifier":"cve@gitlab.com","published":"2021-10-04T17:15:08.080","lastModified":"2026-06-17T04:04:20.800","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability was discovered in GitLab starting with version 12.2 that allows an attacker to cause uncontrolled resource consumption with a specially crafted file."},{"lang":"es","value":"Se ha detectado una vulnerabilidad en GitLab a partir de la versión 12.2, que permite a un atacante causar un consumo no controlado de recursos con un archivo especialmente diseñado"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.2, <14.1.7","status":"affected"},{"version":">=14.2, <14.2.5","status":"affected"},{"version":">=14.3, <14.3.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H","baseScore":7.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.1,"impactScore":4.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:N/A:P","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-400"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"14.1.7","matchCriteriaId":"CA94E173-68B0-4B51-A5BB-DEB3BD6384C0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"14.1.7","matchCriteriaId":"6A1492ED-8F20-4C94-B2F4-BFEFB929360D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.2","versionEndExcluding":"14.2.5","matchCriteriaId":"A3352A07-9A5A-4CA9-B6F6-71BA3A1D4F9C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.2","versionEndExcluding":"14.2.5","matchCriteriaId":"CAAC78F3-28E1-4A0D-BA8A-78AE9393B988"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.3","versionEndExcluding":"14.3.1","matchCriteriaId":"A573FB75-1C20-4E3A-982C-2B422C95BED8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.3","versionEndExcluding":"14.3.1","matchCriteriaId":"D0EFF286-2716-472C-AB8E-47595940C0B3"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39877.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/300095","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1077021","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39877.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/300095","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1077021","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-39879","sourceIdentifier":"cve@gitlab.com","published":"2021-10-04T17:15:08.137","lastModified":"2026-06-17T04:04:21.023","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Missing authentication in all versions of GitLab CE/EE since version 7.11.0 allows an attacker with access to a victim's session to disable two-factor authentication"},{"lang":"es","value":"Una falta de autenticación en todas las versiones de GitLab CE/EE desde la versión 7.11.0, permite a un atacante con acceso a la sesión de la víctima desactivar la autenticación de dos factores"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=7.11.0, <14.1.7","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N","baseScore":2.2,"baseSeverity":"LOW","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":0.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N","baseScore":3.5,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-306"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"7.11.0","versionEndExcluding":"14.1.7","matchCriteriaId":"A20E3C4D-D78D-47B9-BEF1-518E708AC8E4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"7.11.0","versionEndExcluding":"14.1.7","matchCriteriaId":"8F50ACD2-854F-49FC-9ACF-BE5EF32208C6"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39879.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/338825","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39879.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/338825","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2021-39883","sourceIdentifier":"cve@gitlab.com","published":"2021-10-04T17:15:08.193","lastModified":"2026-06-17T04:04:21.470","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Improper authorization checks in all versions of GitLab EE starting from 13.11 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 allows subgroup members to see epics from all parent subgroups."},{"lang":"es","value":"Las comprobaciones de autorización inadecuadas en todas las versiones de GitLab EE a partir de la 13.11 antes de la 14.1.7, en todas las versiones a partir de la 14.2 antes de la 14.2.5 y en todas las versiones a partir de la 14.3 antes de la 14.3.1 permiten a los miembros de los subgrupos ver las epopeyas de todos los subgrupos padres"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.11, <14.1.7","status":"affected"},{"version":">=14.2, <14.2.5","status":"affected"},{"version":">=14.3, <14.3.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.11.0","versionEndExcluding":"14.1.7","matchCriteriaId":"1D26E3D1-3FD1-4543-B8FF-2687E3D690B4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.5","matchCriteriaId":"CD7E2FAA-308F-450F-8990-52A7DEB8ED00"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.3.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"ED0EDF4C-4350-476E-A6C4-C2FEFC2078D8"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39883.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/334279","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39883.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/334279","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2021-39885","sourceIdentifier":"cve@gitlab.com","published":"2021-10-04T17:15:08.247","lastModified":"2026-06-17T04:04:21.687","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A Stored XSS in merge request creation page in all versions of Gitlab EE starting from 13.7 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 allows an attacker to execute arbitrary JavaScript code on the victim's behalf via malicious approval rule names"},{"lang":"es","value":"Un XSS almacenado en la página de creación de solicitudes de fusión en todas las versiones de Gitlab EE a partir de la 13.7 antes de la 14.1.7, todas las versiones a partir de la 14.2 antes de la 14.2.5 y todas las versiones a partir de la 14.3 antes de la 14.3.1 permite a un atacante ejecutar código JavaScript arbitrario en nombre de la víctima a través de nombres de reglas de aprobación maliciosos"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.7, <14.1.7","status":"affected"},{"version":">=14.2, <14.2.5","status":"affected"},{"version":">=14.3, <14.3.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"14.1.7","matchCriteriaId":"017676DB-63DA-4DF4-956E-4E5D792A63F0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.5","matchCriteriaId":"CD7E2FAA-308F-450F-8990-52A7DEB8ED00"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.3.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"ED0EDF4C-4350-476E-A6C4-C2FEFC2078D8"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39885.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/341140","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1342009","source":"cve@gitlab.com","tags":["Exploit","Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39885.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/341140","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1342009","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-39896","sourceIdentifier":"cve@gitlab.com","published":"2021-10-04T17:15:08.303","lastModified":"2026-06-17T04:04:22.897","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In all versions of GitLab CE/EE since version 8.0, when an admin uses the impersonate feature twice and stops impersonating, the admin may be logged in as the second user they impersonated, which may lead to repudiation issues."},{"lang":"es","value":"En todas las versiones de GitLab CE/EE desde la versión 8.0, cuando un administrador usa la funcionalidad de suplantación dos veces y deja de hacerlo, el administrador puede iniciar sesión como el segundo usuario al que suplantó, lo que puede conllevar a problemas de repudio"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=8.0, <14.1.7","status":"affected"},{"version":">=14.2, <14.2.5","status":"affected"},{"version":">=14.3, <14.3.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N","baseScore":3.8,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":2.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N","baseScore":3.8,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":2.5}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:N","baseScore":5.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.0.0","versionEndExcluding":"14.1.7","matchCriteriaId":"108BFCA8-3661-485A-BD06-27FA8999BB50"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.0.0","versionEndExcluding":"14.1.7","matchCriteriaId":"4B4A8EE5-32B8-4DFB-9431-01A76FF04037"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.2","versionEndExcluding":"14.2.5","matchCriteriaId":"A3352A07-9A5A-4CA9-B6F6-71BA3A1D4F9C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.2","versionEndExcluding":"14.2.5","matchCriteriaId":"CAAC78F3-28E1-4A0D-BA8A-78AE9393B988"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.3","versionEndExcluding":"14.3.1","matchCriteriaId":"A573FB75-1C20-4E3A-982C-2B422C95BED8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.3","versionEndExcluding":"14.3.1","matchCriteriaId":"D0EFF286-2716-472C-AB8E-47595940C0B3"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39896.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/339362","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39896.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/339362","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2021-39899","sourceIdentifier":"cve@gitlab.com","published":"2021-10-04T17:15:08.357","lastModified":"2026-06-17T04:04:23.230","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In all versions of GitLab CE/EE, an attacker with physical access to a user’s machine may brute force the user’s password via the change password function. There is a rate limit in place, but the attack may still be conducted by stealing the session id from the physical compromise of the account and splitting the attack over several IP addresses and passing in the compromised session value from these various locations."},{"lang":"es","value":"En todas las versiones de GitLab CE/EE, un atacante con acceso físico a la máquina de un usuario puede forzar la contraseña del usuario por medio de la función change password. Se presenta un límite de velocidad, pero el ataque puede llevarse a cabo al robar el identificador de sesión desde el compromiso físico de la cuenta y dividiendo el ataque en varias direcciones IP y pasando el valor de la sesión comprometida desde estas diversas ubicaciones"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=1.0, <14.1.7","status":"affected"},{"version":">=14.2, <14.2.5","status":"affected"},{"version":">=14.3, <14.3.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N","baseScore":2.9,"baseSeverity":"LOW","attackVector":"PHYSICAL","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":0.4,"impactScore":2.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":4.2,"baseSeverity":"MEDIUM","attackVector":"PHYSICAL","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":0.5,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:M/Au:N/C:P/I:N/A:N","baseScore":1.9,"accessVector":"LOCAL","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":3.4,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-640"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"1.0.0","versionEndExcluding":"14.1.7","matchCriteriaId":"15511E8F-E088-49D8-BF62-7C0D3A5252BF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"1.0.0","versionEndExcluding":"14.1.7","matchCriteriaId":"C2FC870F-C488-49EF-92B2-A46CE6116A94"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.2","versionEndExcluding":"14.2.5","matchCriteriaId":"A3352A07-9A5A-4CA9-B6F6-71BA3A1D4F9C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.2","versionEndExcluding":"14.2.5","matchCriteriaId":"CAAC78F3-28E1-4A0D-BA8A-78AE9393B988"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.3","versionEndExcluding":"14.3.1","matchCriteriaId":"A573FB75-1C20-4E3A-982C-2B422C95BED8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.3","versionEndExcluding":"14.3.1","matchCriteriaId":"D0EFF286-2716-472C-AB8E-47595940C0B3"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39899.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/339154","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39899.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/339154","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2021-39900","sourceIdentifier":"cve@gitlab.com","published":"2021-10-04T17:15:08.413","lastModified":"2026-06-17T04:04:23.337","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Information disclosure from SendEntry in GitLab starting with 10.8 allowed exposure of full URL of artifacts stored in object-storage with a temporary availability via Rails logs."},{"lang":"es","value":"Una divulgación de información de SendEntry en GitLab a partir de la versión 10.8, permitía la exposición de la URL completa de los artefactos almacenados en el almacenamiento de objetos con una disponibilidad temporal por medio de los registros de Rails"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=10.8, <14.1.7","status":"affected"},{"version":">=14.2, <14.2.5","status":"affected"},{"version":">=14.3, <14.3.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N","baseScore":2.0,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":0.5,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N","baseScore":2.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-532"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.8.0","versionEndExcluding":"14.1.7","matchCriteriaId":"018E5854-4757-42B1-8C78-1CD2903E6FFD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.8.0","versionEndExcluding":"14.1.7","matchCriteriaId":"24E7D2D9-8143-455A-81AB-620515030293"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.5","matchCriteriaId":"CAB23F69-59A2-430F-A082-A5F81A7A464C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.5","matchCriteriaId":"CD7E2FAA-308F-450F-8990-52A7DEB8ED00"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.3.0:*:*:*:community:*:*:*","matchCriteriaId":"3E754C1F-3FB2-4387-8523-19896FDE7A14"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.3.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"ED0EDF4C-4350-476E-A6C4-C2FEFC2078D8"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39900.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/325088","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39900.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/325088","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2021-39887","sourceIdentifier":"cve@gitlab.com","published":"2021-10-05T12:15:07.903","lastModified":"2026-06-17T04:04:21.907","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A stored Cross-Site Scripting vulnerability in the GitLab Flavored Markdown in GitLab CE/EE version 8.4 and above allowed an attacker to execute arbitrary JavaScript code on the victim's behalf."},{"lang":"es","value":"Una vulnerabilidad de tipo Cross-Site Scripting almacenado en el GitLab Flavored Markdown en GitLab CE/EE versión 8.4 y superior, permitía a un atacante ejecutar código JavaScript arbitrario en nombre de la víctima"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=8.4, <14.1.7","status":"affected"},{"version":">=14.2, <14.2.5","status":"affected"},{"version":">=14.3, <14.3.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.4.0","versionEndExcluding":"14.1.7","matchCriteriaId":"43AA0053-AAD2-412F-A7A1-BF43BAEA0AAD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.4.0","versionEndExcluding":"14.1.7","matchCriteriaId":"88AA013C-438F-4CEB-9603-37A5F26BF17D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.2","versionEndExcluding":"14.2.5","matchCriteriaId":"A3352A07-9A5A-4CA9-B6F6-71BA3A1D4F9C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.2","versionEndExcluding":"14.2.5","matchCriteriaId":"CAAC78F3-28E1-4A0D-BA8A-78AE9393B988"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.3","versionEndExcluding":"14.3.1","matchCriteriaId":"A573FB75-1C20-4E3A-982C-2B422C95BED8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.3","versionEndExcluding":"14.3.1","matchCriteriaId":"D0EFF286-2716-472C-AB8E-47595940C0B3"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39887.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/332903","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1218174","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39887.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/332903","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1218174","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-39866","sourceIdentifier":"cve@gitlab.com","published":"2021-10-05T13:15:07.920","lastModified":"2026-06-17T04:04:19.590","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A business logic error in the project deletion process in GitLab 13.6 and later allows persistent access via project access tokens."},{"lang":"es","value":"Un error de lógica de negocio en el proceso de eliminación de proyectos en GitLab versiones 13.6 y posteriores, permite el acceso persistente por medio de tokens de acceso al proyecto"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=14.3, <14.3.1","status":"affected"},{"version":">=14.2, <14.2.5","status":"affected"},{"version":">=13.6, <14.1.7","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.5}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:N","baseScore":5.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.6.0","versionEndExcluding":"14.1.7","matchCriteriaId":"0712F301-9E84-4F2D-A437-8F3C31AB36B2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.6.0","versionEndExcluding":"14.1.7","matchCriteriaId":"70611DD5-5353-49DB-A9AF-E2869AE9A7CC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.5","matchCriteriaId":"CAB23F69-59A2-430F-A082-A5F81A7A464C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.5","matchCriteriaId":"CD7E2FAA-308F-450F-8990-52A7DEB8ED00"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:4.3.0:*:*:*:community:*:*:*","matchCriteriaId":"43C7D46F-A414-4818-B74C-547684E7B01D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:4.3.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"35B8762D-58EF-4F52-9C12-6CA842F2E195"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39866.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/333175","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1199561","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39866.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/333175","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1199561","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2021-39867","sourceIdentifier":"cve@gitlab.com","published":"2021-10-05T13:15:07.977","lastModified":"2026-06-17T04:04:19.697","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vulnerability in Gitea Importer may be exploited by an attacker to trigger Server Side Request Forgery (SSRF) attacks."},{"lang":"es","value":"En todas las versiones de GitLab CE/EE desde la versión 8.15, una vulnerabilidad de reenganche de DNS en Gitea Importer puede ser explotada por un atacante para desencadenar ataques de tipo Server Side Request Forgery (SSRF)"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=8.15, <14.1.7","status":"affected"},{"version":">=14.2, <14.2.5","status":"affected"},{"version":">=14.3, <14.3.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":5.2}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:N","baseScore":5.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.15.0","versionEndExcluding":"14.1.7","matchCriteriaId":"EE603FFD-D46C-43B0-81D9-F94954F64B52"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.15.0","versionEndExcluding":"14.1.7","matchCriteriaId":"F219D34C-E4FD-48FE-ADEF-2C86672AFC73"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.5","matchCriteriaId":"CAB23F69-59A2-430F-A082-A5F81A7A464C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.5","matchCriteriaId":"CD7E2FAA-308F-450F-8990-52A7DEB8ED00"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:4.3.0:*:*:*:community:*:*:*","matchCriteriaId":"43C7D46F-A414-4818-B74C-547684E7B01D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:4.3.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"35B8762D-58EF-4F52-9C12-6CA842F2E195"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39867.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/214401","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39867.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/214401","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2021-39869","sourceIdentifier":"cve@gitlab.com","published":"2021-10-05T13:15:08.033","lastModified":"2026-06-17T04:04:19.920","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In all versions of GitLab CE/EE since version 8.9, project exports may expose trigger tokens configured on that project."},{"lang":"es","value":"En todas las versiones de GitLab CE/EE desde la versión 8.9, las exportaciones de proyectos pueden desencadenar la exposición de los tokens configurados en ese proyecto"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=8.9, <14.1.7","status":"affected"},{"version":">=14.2, <14.2.5","status":"affected"},{"version":">=14.3, <14.3.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.9.0","versionEndExcluding":"14.1.7","matchCriteriaId":"88E98918-92EC-49EC-B7B1-C4D4BF568B63"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.9.0","versionEndExcluding":"14.1.7","matchCriteriaId":"B8E226B5-1D6D-4403-80D8-8CB5F5BF4DD6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.5","matchCriteriaId":"CAB23F69-59A2-430F-A082-A5F81A7A464C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.5","matchCriteriaId":"CD7E2FAA-308F-450F-8990-52A7DEB8ED00"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:4.3.0:*:*:*:community:*:*:*","matchCriteriaId":"43C7D46F-A414-4818-B74C-547684E7B01D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:4.3.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"35B8762D-58EF-4F52-9C12-6CA842F2E195"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39869.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/27044","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/497144","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39869.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/27044","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/497144","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-39872","sourceIdentifier":"cve@gitlab.com","published":"2021-10-05T13:15:08.090","lastModified":"2026-06-17T04:04:20.250","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired password to still access GitLab through git and API through access tokens acquired before password expiration."},{"lang":"es","value":"En todas las versiones de GitLab CE/EE desde la versión 14.1, una vulnerabilidad de control de acceso inapropiada permite a usuarios con la contraseña caducada seguir accediendo a GitLab mediante git y de la API mediante tokens de acceso adquiridos antes de la caducidad de la contraseña"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=14.1, <14.1.7","status":"affected"},{"version":">=14.2, <14.2.5","status":"affected"},{"version":">=14.3, <14.3.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-287"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"14.1.7","matchCriteriaId":"85648CA9-25DB-4DAD-B043-A8ECF067940F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"14.1.7","matchCriteriaId":"9893A9C9-8C55-4EB5-8602-5DD46320035F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.5","matchCriteriaId":"CAB23F69-59A2-430F-A082-A5F81A7A464C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.5","matchCriteriaId":"CD7E2FAA-308F-450F-8990-52A7DEB8ED00"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:4.3.0:*:*:*:community:*:*:*","matchCriteriaId":"43C7D46F-A414-4818-B74C-547684E7B01D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:4.3.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"35B8762D-58EF-4F52-9C12-6CA842F2E195"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39872.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/337954","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1285226","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39872.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/337954","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1285226","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-39875","sourceIdentifier":"cve@gitlab.com","published":"2021-10-05T13:15:08.143","lastModified":"2026-06-17T04:04:20.580","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In all versions of GitLab CE/EE since version 13.6, it is possible to see pending invitations of any public group or public project by visiting an API endpoint."},{"lang":"es","value":"En todas las versiones de GitLab CE/EE desde la versión 13.6, es posible visualizar las invitaciones pendientes de cualquier grupo público o proyecto público al visitar un endpoint de la API"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.6, <14.1.7","status":"affected"},{"version":">=14.2, <14.2.5","status":"affected"},{"version":">=14.3, <14.3.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.6.0","versionEndExcluding":"14.1.7","matchCriteriaId":"0712F301-9E84-4F2D-A437-8F3C31AB36B2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.6.0","versionEndExcluding":"14.1.7","matchCriteriaId":"70611DD5-5353-49DB-A9AF-E2869AE9A7CC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.5","matchCriteriaId":"CAB23F69-59A2-430F-A082-A5F81A7A464C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.5","matchCriteriaId":"CD7E2FAA-308F-450F-8990-52A7DEB8ED00"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:4.3.0:*:*:*:community:*:*:*","matchCriteriaId":"43C7D46F-A414-4818-B74C-547684E7B01D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:4.3.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"35B8762D-58EF-4F52-9C12-6CA842F2E195"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39875.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/290985","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1048259","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39875.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/290985","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1048259","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-39878","sourceIdentifier":"cve@gitlab.com","published":"2021-10-05T13:15:08.197","lastModified":"2026-06-17T04:04:20.910","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A stored Reflected Cross-Site Scripting vulnerability in the Jira integration in GitLab version 13.0 up to 14.3.1 allowed an attacker to execute arbitrary javascript code."},{"lang":"es","value":"Una vulnerabilidad de tipo Cross-Site Scripting reflejado almacenado en la integración de Jira en GitLab versión 13.0 hasta 14.3.1, permitía a un atacante ejecutar código javascript arbitrario"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.0, <14.1.7","status":"affected"},{"version":">=14.2, <14.2.5","status":"affected"},{"version":">=14.3, <14.3.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:N/A:N","baseScore":5.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.3,"impactScore":4.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.0.0","versionEndExcluding":"14.1.7","matchCriteriaId":"609D7DAD-8BB9-4AE1-984C-1739B812D868"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.0.0","versionEndExcluding":"14.1.7","matchCriteriaId":"164E3D6C-24AB-411A-82BA-034B761C4423"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.5","matchCriteriaId":"CAB23F69-59A2-430F-A082-A5F81A7A464C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.5","matchCriteriaId":"CD7E2FAA-308F-450F-8990-52A7DEB8ED00"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.3.0","versionEndExcluding":"14.3.1","matchCriteriaId":"F2308ED7-163D-4ECD-AFDC-35E2A694273C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.3.0","versionEndExcluding":"14.3.1","matchCriteriaId":"157A67E5-BAEB-4C73-A3D2-A9D8E189A15B"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39878.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/334043","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1194254","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39878.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/334043","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1194254","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2021-39882","sourceIdentifier":"cve@gitlab.com","published":"2021-10-05T13:15:08.257","lastModified":"2026-06-17T04:04:21.360","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In all versions of GitLab CE/EE, provided a user ID, anonymous users can use a few endpoints to retrieve information about any GitLab user."},{"lang":"es","value":"En todas las versiones de GitLab CE/EE, siempre que se disponga de un ID de usuario, unos usuarios anónimos pueden usar algunos endpoints para recuperar información sobre cualquier usuario de GitLab"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=1.0, <14.1.7","status":"affected"},{"version":">=14.2, <14.2.5","status":"affected"},{"version":">=14.3, <14.3.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-319"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"1.0.0","versionEndExcluding":"14.1.7","matchCriteriaId":"15511E8F-E088-49D8-BF62-7C0D3A5252BF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"1.0.0","versionEndExcluding":"14.1.7","matchCriteriaId":"C2FC870F-C488-49EF-92B2-A46CE6116A94"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.2","versionEndExcluding":"14.2.5","matchCriteriaId":"A3352A07-9A5A-4CA9-B6F6-71BA3A1D4F9C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.2","versionEndExcluding":"14.2.5","matchCriteriaId":"CAAC78F3-28E1-4A0D-BA8A-78AE9393B988"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:4.3.0:*:*:*:community:*:*:*","matchCriteriaId":"43C7D46F-A414-4818-B74C-547684E7B01D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:4.3.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"35B8762D-58EF-4F52-9C12-6CA842F2E195"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39882.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/297473","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39882.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/297473","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2021-39884","sourceIdentifier":"cve@gitlab.com","published":"2021-10-05T13:15:08.313","lastModified":"2026-06-17T04:04:21.577","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In all versions of GitLab EE since version 8.13, an endpoint discloses names of private groups that have access to a project to low privileged users that are part of that project."},{"lang":"es","value":"En todas las versiones de GitLab EE desde la versión 8.13, un endpoint divulga nombres de grupos privados que tienen acceso a un proyecto a usuarios con pocos privilegios que forman parte de ese proyecto"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=8.13, <14.1.7","status":"affected"},{"version":">=14.2, <14.2.5","status":"affected"},{"version":">=14.3, <14.3.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.13.0","versionEndExcluding":"14.1.7","matchCriteriaId":"A23B5751-7AF8-4AF1-949E-4D7FC0519E2C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.13.0","versionEndExcluding":"14.1.7","matchCriteriaId":"844B1B1E-7C4A-4324-B6DB-924A70DCB5DE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.5","matchCriteriaId":"CAB23F69-59A2-430F-A082-A5F81A7A464C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.5","matchCriteriaId":"CD7E2FAA-308F-450F-8990-52A7DEB8ED00"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.3.0","versionEndExcluding":"14.3.1","matchCriteriaId":"F2308ED7-163D-4ECD-AFDC-35E2A694273C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.3.0","versionEndExcluding":"14.3.1","matchCriteriaId":"157A67E5-BAEB-4C73-A3D2-A9D8E189A15B"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39884.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/25414","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/447817","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39884.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/25414","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/447817","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2021-39888","sourceIdentifier":"cve@gitlab.com","published":"2021-10-05T13:15:08.367","lastModified":"2026-06-17T04:04:22.020","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In all versions of GitLab EE starting from 13.10 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 a specific API endpoint may reveal details about a private group and other sensitive info inside issue and merge request templates."},{"lang":"es","value":"En todas las versiones de GitLab EE a partir de la 13.10 antes de la 14.1.7, en todas las versiones a partir de la 14.2 antes de la 14.2.5, y en todas las versiones a partir de la 14.3 antes de la 14.3.1, un punto final específico de la API puede revelar detalles sobre un grupo privado y otra información sensible dentro de las plantillas de incidencias y solicitudes de fusión"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.10, <14.1.7","status":"affected"},{"version":">=14.2, <14.2.5","status":"affected"},{"version":">=14.3, <14.3.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.10.0","versionEndExcluding":"14.1.7","matchCriteriaId":"802F4AE1-5D4B-4CF8-A462-F3DD4FF18015"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.5","matchCriteriaId":"CD7E2FAA-308F-450F-8990-52A7DEB8ED00"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.3.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"ED0EDF4C-4350-476E-A6C4-C2FEFC2078D8"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39888.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/336446","source":"cve@gitlab.com","tags":["Broken Link","Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1255128","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39888.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/336446","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1255128","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2021-39893","sourceIdentifier":"cve@gitlab.com","published":"2021-10-05T13:15:08.417","lastModified":"2026-06-17T04:04:22.563","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A potential DOS vulnerability was discovered in GitLab starting with version 9.1 that allowed parsing files without authorisation."},{"lang":"es","value":"En GitLab, a partir de la versión 9.1, se ha detectado una potencial vulnerabilidad de DOS que permitía analizar archivos sin autorización"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=9.1, <14.1.7","status":"affected"},{"version":">=14.2, <14.2.5","status":"affected"},{"version":">=14.3, <14.3.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"9.1.0","versionEndExcluding":"14.1.7","matchCriteriaId":"4D551586-EB1A-4508-BFE1-5767DC423649"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"9.1.0","versionEndExcluding":"14.1.7","matchCriteriaId":"A49ACE8F-A68C-4D39-80CB-470571DD857C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.5","matchCriteriaId":"CAB23F69-59A2-430F-A082-A5F81A7A464C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.5","matchCriteriaId":"CD7E2FAA-308F-450F-8990-52A7DEB8ED00"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.3.0","versionEndExcluding":"14.3.1","matchCriteriaId":"F2308ED7-163D-4ECD-AFDC-35E2A694273C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.3.0","versionEndExcluding":"14.3.1","matchCriteriaId":"157A67E5-BAEB-4C73-A3D2-A9D8E189A15B"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39893.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/340076","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39893.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/340076","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2021-39894","sourceIdentifier":"cve@gitlab.com","published":"2021-10-05T13:15:08.467","lastModified":"2026-06-17T04:04:22.673","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In all versions of GitLab CE/EE since version 8.0, a DNS rebinding vulnerability exists in Fogbugz importer which may be used by attackers to exploit Server Side Request Forgery attacks."},{"lang":"es","value":"En todas las versiones de GitLab CE/EE desde la versión 8.0, se presenta una vulnerabilidad de reenganche de DNS en el importador Fogbugz que puede ser usada por atacantes para explotar ataques de tipo Server Side Request Forgery"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=8.0, <14.1.7","status":"affected"},{"version":">=14.2, <14.2.5","status":"affected"},{"version":">=14.3, <14.3.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.5}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:N","baseScore":5.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.0.0","versionEndExcluding":"14.1.7","matchCriteriaId":"108BFCA8-3661-485A-BD06-27FA8999BB50"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.0.0","versionEndExcluding":"14.1.7","matchCriteriaId":"4B4A8EE5-32B8-4DFB-9431-01A76FF04037"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.5","matchCriteriaId":"CAB23F69-59A2-430F-A082-A5F81A7A464C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.5","matchCriteriaId":"CD7E2FAA-308F-450F-8990-52A7DEB8ED00"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.3.0:*:*:*:community:*:*:*","matchCriteriaId":"3E754C1F-3FB2-4387-8523-19896FDE7A14"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.3.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"ED0EDF4C-4350-476E-A6C4-C2FEFC2078D8"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39894.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/214399","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39894.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/214399","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2021-22257","sourceIdentifier":"cve@gitlab.com","published":"2021-10-05T14:15:07.570","lastModified":"2026-06-17T03:36:53.940","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 14.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. The route for /user.keys is not restricted on instances with public visibility disabled. This allows user enumeration on such instances."},{"lang":"es","value":"Se ha detectado un problema en GitLab que afecta a todas las versiones a partir de la 14.0 anteriores a 14.0.9, todas las versiones a partir de la 14.1 anteriores a 14.1.4, todas las versiones a partir de la 14.2 anteriores a 14.2.2. La ruta para /user.keys no está restringida en las instancias con visibilidad pública deshabilitada. Esto permite una enumeración de usuarios en dichas instancias"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=14.0, <14.0.9","status":"affected"},{"version":">=14.1, <14.1.4","status":"affected"},{"version":">=14.2, <14.2.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.0.9","matchCriteriaId":"7B16376E-DEE9-4CBA-BECA-072B6782A0BF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.0.9","matchCriteriaId":"A66113E2-D71B-4F05-9FB5-A06E01B832DE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"14.1.4","matchCriteriaId":"9A88A687-E3B3-43B3-87C6-489DF361D7D1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"14.1.4","matchCriteriaId":"B0917E00-8A8B-456B-8AF9-FEDE1B16079F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.2","matchCriteriaId":"3CE159DB-7F83-42A6-9527-EB372B1F0C12"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.2","matchCriteriaId":"9748F8EA-2A15-4F22-8C54-5CA56B75EA58"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22257.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/23832","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22257.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/23832","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2021-22258","sourceIdentifier":"cve@gitlab.com","published":"2021-10-05T14:15:07.627","lastModified":"2026-06-17T03:36:54.050","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"The project import/export feature in GitLab 8.9 and greater could be used to obtain otherwise private email addresses"},{"lang":"es","value":"La función de importación/exportación de proyectos en GitLab versiones 8.9 y superiores, podría usarse para obtener direcciones de correo electrónico que de otro modo serían privadas"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=14.2, <14.2.2","status":"affected"},{"version":">=14.1, <14.1.4","status":"affected"},{"version":">=8.9, <14.0.9","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.9.0","versionEndExcluding":"14.0.9","matchCriteriaId":"213DCC0A-42E3-445B-AE12-2DFD9BACE729"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.9.0","versionEndExcluding":"14.0.9","matchCriteriaId":"462F56BD-0CDF-425B-B986-0E44ADBB0A18"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"14.1.4","matchCriteriaId":"9A88A687-E3B3-43B3-87C6-489DF361D7D1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"14.1.4","matchCriteriaId":"B0917E00-8A8B-456B-8AF9-FEDE1B16079F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.2","matchCriteriaId":"3CE159DB-7F83-42A6-9527-EB372B1F0C12"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.2","matchCriteriaId":"9748F8EA-2A15-4F22-8C54-5CA56B75EA58"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22258.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/24231","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/410436","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22258.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/24231","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/410436","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-22261","sourceIdentifier":"cve@gitlab.com","published":"2021-10-05T14:15:07.677","lastModified":"2026-06-17T03:36:54.380","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A stored Cross-Site Scripting vulnerability in the Jira integration in all GitLab versions starting from 13.9 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to execute arbitrary JavaScript code on the victim's behalf via malicious Jira API responses"},{"lang":"es","value":"Una vulnerabilidad de Cross-Site Scripting almacenada en la integración de Jira en todas las versiones de GitLab a partir de la 13.9 antes de la 14.0.9, todas las versiones a partir de la 14.1 antes de la 14.1.4 y todas las versiones a partir de la 14.2 antes de la 14.2.2 permite a un atacante ejecutar código JavaScript arbitrario en nombre de la víctima a través de respuestas maliciosas de la API de Jira"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.9, <14.0.9","status":"affected"},{"version":">=14.1, <14.1.4","status":"affected"},{"version":">=14.2, <14.2.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:N","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.0,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N","baseScore":4.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.7,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.9.0","versionEndExcluding":"14.0.9","matchCriteriaId":"29B9C584-5188-4BCE-95A0-24E0157E255C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.9.0","versionEndExcluding":"14.0.9","matchCriteriaId":"CAD3B3E9-A722-47ED-94F2-5D3395008234"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"14.1.4","matchCriteriaId":"9A88A687-E3B3-43B3-87C6-489DF361D7D1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"14.1.4","matchCriteriaId":"B0917E00-8A8B-456B-8AF9-FEDE1B16079F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.2","matchCriteriaId":"3CE159DB-7F83-42A6-9527-EB372B1F0C12"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.2","matchCriteriaId":"9748F8EA-2A15-4F22-8C54-5CA56B75EA58"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22261.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/328389","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1132083","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22261.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/328389","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1132083","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-22262","sourceIdentifier":"cve@gitlab.com","published":"2021-10-05T14:15:07.723","lastModified":"2026-06-17T03:36:54.500","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Missing access control in all GitLab versions starting from 13.12 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 with Jira Cloud integration enabled allows Jira users without administrative privileges to add and remove Jira Connect Namespaces via the GitLab.com for Jira Cloud application configuration page"},{"lang":"es","value":"La falta de control de acceso en todas las versiones de GitLab a partir de la 13.12 antes de la 14.0.9, en todas las versiones a partir de la 14.1 antes de la 14.1.4 y en todas las versiones a partir de la 14.2 antes de la 14.2.2 con la integración de Jira Cloud habilitada permite a los usuarios de Jira sin privilegios administrativos añadir y eliminar espacios de nombres de Jira Connect a través de la página de configuración de la aplicación GitLab.com for Jira Cloud"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.12, <14.0.9","status":"affected"},{"version":">=14.1, <14.1.4","status":"affected"},{"version":">=14.2, <14.2.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":2.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.12.0","versionEndExcluding":"14.0.9","matchCriteriaId":"EF7D37D0-0A38-4526-8453-52552D96E2C4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.12.0","versionEndExcluding":"14.0.9","matchCriteriaId":"7A9D293C-4926-444D-90AD-D69C150ADBA4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"14.1.4","matchCriteriaId":"9A88A687-E3B3-43B3-87C6-489DF361D7D1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"14.1.4","matchCriteriaId":"B0917E00-8A8B-456B-8AF9-FEDE1B16079F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.2","matchCriteriaId":"3CE159DB-7F83-42A6-9527-EB372B1F0C12"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.2","matchCriteriaId":"9748F8EA-2A15-4F22-8C54-5CA56B75EA58"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22262.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/327062","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1147812","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22262.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/327062","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1147812","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-22264","sourceIdentifier":"cve@gitlab.com","published":"2021-10-05T14:15:07.773","lastModified":"2026-06-17T03:36:54.727","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 13.8 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. Under specialized conditions, an invited group member may continue to have access to a project even after the invited group, which the member was part of, is deleted."},{"lang":"es","value":"Se ha detectado un problema en GitLab que afecta a todas las versiones a partir de la 13.8 anteriores a 14.0.9, todas las versiones a partir de la 14.1 anteriores a 14.1.4, todas las versiones a partir de la 14.2 anteriores a 14.2.2. En condiciones especiales, un miembro de un grupo invitado puede seguir teniendo acceso a un proyecto incluso después de que se elimine el grupo invitado del que formaba parte"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.8, <14.0.9","status":"affected"},{"version":">=14.1, <14.1.4","status":"affected"},{"version":">=14.2, <14.2.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","baseScore":6.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.8.0","versionEndExcluding":"14.0.9","matchCriteriaId":"CBBEA39E-3C01-43B1-8804-A7EDD4789D4F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.8.0","versionEndExcluding":"14.0.9","matchCriteriaId":"3F33970A-044D-4C8B-A070-C809D39F8E24"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"14.1.4","matchCriteriaId":"9A88A687-E3B3-43B3-87C6-489DF361D7D1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"14.1.4","matchCriteriaId":"B0917E00-8A8B-456B-8AF9-FEDE1B16079F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.2","matchCriteriaId":"3CE159DB-7F83-42A6-9527-EB372B1F0C12"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.2","matchCriteriaId":"9748F8EA-2A15-4F22-8C54-5CA56B75EA58"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22264.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/336073","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22264.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/336073","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2021-39870","sourceIdentifier":"cve@gitlab.com","published":"2021-10-05T14:15:07.833","lastModified":"2026-06-17T04:04:20.030","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In all versions of GitLab CE/EE since version 11.11, an instance that has the setting to disable Repo by URL import enabled is bypassed by an attacker making a crafted API call."},{"lang":"es","value":"En todas las versiones de GitLab CE/EE a partir de la versión 11.11, un atacante que realice una llamada a la API diseñada puede omitir una instancia que tenga habilitada la opción de desactivar la importación de repositorios por URL"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=11.11, <14.1.7","status":"affected"},{"version":">=14.2, <14.2.5","status":"affected"},{"version":">=14.3, <14.3.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.11.0","versionEndExcluding":"14.1.7","matchCriteriaId":"0FD14F81-7A6C-4DDF-B1FE-04E297E981F5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.11.0","versionEndExcluding":"14.1.7","matchCriteriaId":"10238EEB-8252-411D-A94D-100AEA35238B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.5","matchCriteriaId":"CAB23F69-59A2-430F-A082-A5F81A7A464C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.5","matchCriteriaId":"CD7E2FAA-308F-450F-8990-52A7DEB8ED00"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.3.0","versionEndExcluding":"14.3.1","matchCriteriaId":"F2308ED7-163D-4ECD-AFDC-35E2A694273C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.3.0","versionEndExcluding":"14.3.1","matchCriteriaId":"157A67E5-BAEB-4C73-A3D2-A9D8E189A15B"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39870.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/29748","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/630263","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39870.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/29748","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/630263","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-39881","sourceIdentifier":"cve@gitlab.com","published":"2021-10-05T14:15:07.883","lastModified":"2026-06-17T04:04:21.247","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In all versions of GitLab CE/EE since version 7.7, the application may let a malicious user create an OAuth client application with arbitrary scope names which may allow the malicious user to trick unsuspecting users to authorize the malicious client application using the spoofed scope name and description."},{"lang":"es","value":"En todas las versiones de GitLab CE/EE desde la versión 7.7, la aplicación puede permitir a un usuario malicioso crear una aplicación cliente OAuth con nombres de ámbito arbitrarios que pueden permitir al usuario malicioso engañar a usuarios desprevenidos para que autoricen la aplicación cliente maliciosa usando el nombre de ámbito y descripción falsos"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=7.7, <14.1.7","status":"affected"},{"version":">=14.2, <14.2.5","status":"affected"},{"version":">=14.3, <14.3.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N","baseScore":3.5,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N","baseScore":3.5,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"7.7.0","versionEndExcluding":"14.1.7","matchCriteriaId":"5D0F9C11-4E74-4B19-9B90-23C31BDF7E0A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"7.7.0","versionEndExcluding":"14.1.7","matchCriteriaId":"E0D20B7F-E6B7-4B9C-AF76-FC5A81F7B41A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.5","matchCriteriaId":"CAB23F69-59A2-430F-A082-A5F81A7A464C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.5","matchCriteriaId":"CD7E2FAA-308F-450F-8990-52A7DEB8ED00"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.3.0","versionEndExcluding":"14.3.1","matchCriteriaId":"F2308ED7-163D-4ECD-AFDC-35E2A694273C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.3.0","versionEndExcluding":"14.3.1","matchCriteriaId":"157A67E5-BAEB-4C73-A3D2-A9D8E189A15B"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39881.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/26695","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/494530","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39881.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/26695","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/494530","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-39886","sourceIdentifier":"cve@gitlab.com","published":"2021-10-05T14:15:07.933","lastModified":"2026-06-17T04:04:21.797","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Permissions rules were not applied while issues were moved between projects of the same group in GitLab versions starting with 10.6 and up to 14.1.7 allowing users to read confidential Epic references."},{"lang":"es","value":"Las reglas de permisos no se aplicaban mientras las incidencias se movían entre proyectos del mismo grupo en las versiones de GitLab a partir de la 10.6 y hasta la 14.1.7, permitiendo a usuarios leer referencias Ëpicas confidenciales"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=10.6, <14.1.7","status":"affected"},{"version":">=14.2, <14.2.5","status":"affected"},{"version":">=14.3, <14.3.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N","baseScore":2.6,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-276"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.6.0","versionEndExcluding":"14.1.7","matchCriteriaId":"5E975667-70FE-4BF7-88BC-71E9DCA541C4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.6.0","versionEndExcluding":"14.1.7","matchCriteriaId":"F86378DA-3ACE-4B89-807D-C2C0CD6C495A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.5","matchCriteriaId":"CAB23F69-59A2-430F-A082-A5F81A7A464C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.5","matchCriteriaId":"CD7E2FAA-308F-450F-8990-52A7DEB8ED00"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.3.0","versionEndExcluding":"14.3.1","matchCriteriaId":"F2308ED7-163D-4ECD-AFDC-35E2A694273C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.3.0","versionEndExcluding":"14.3.1","matchCriteriaId":"157A67E5-BAEB-4C73-A3D2-A9D8E189A15B"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39886.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/330520","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39886.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/330520","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2021-39889","sourceIdentifier":"cve@gitlab.com","published":"2021-10-05T14:15:07.987","lastModified":"2026-06-17T04:04:22.133","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In all versions of GitLab EE since version 14.1, due to an insecure direct object reference vulnerability, an endpoint may reveal the protected branch name to a malicious user who makes a crafted API call with the ID of the protected branch."},{"lang":"es","value":"En todas las versiones de GitLab EE desde la versión 14.1, debido a una vulnerabilidad de referencia directa a objetos insegura, un endpoint puede revelar el nombre de la rama protegida a un usuario malintencionado que realice una llamada a la API diseñada con el ID de la rama protegida"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=14.1, <14.1.7","status":"affected"},{"version":">=14.2, <14.2.5","status":"affected"},{"version":">=14.3, <14.3.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-639"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"14.1.7","matchCriteriaId":"9893A9C9-8C55-4EB5-8602-5DD46320035F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.5","matchCriteriaId":"CD7E2FAA-308F-450F-8990-52A7DEB8ED00"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.3.0","versionEndExcluding":"14.3.1","matchCriteriaId":"157A67E5-BAEB-4C73-A3D2-A9D8E189A15B"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39889.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/338062","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1294017","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39889.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/338062","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1294017","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-39891","sourceIdentifier":"cve@gitlab.com","published":"2021-10-05T14:15:08.037","lastModified":"2026-06-17T04:04:22.350","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In all versions of GitLab CE/EE since version 8.0, access tokens created as part of admin's impersonation of a user are not cleared at the end of impersonation which may lead to unnecessary sensitive info disclosure."},{"lang":"es","value":"En todas las versiones de GitLab CE/EE desde la versión 8.0, los tokens de acceso creados como parte de la suplantación de un usuario por parte del administrador no se borran al final de la suplantación, lo que puede conllevar a una divulgación innecesaria de información confidencial"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=8.0, <14.1.7","status":"affected"},{"version":">=14.2, <14.2.5","status":"affected"},{"version":">=14.3, <14.3.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":0.7,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-212"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.0.0","versionEndExcluding":"14.1.7","matchCriteriaId":"108BFCA8-3661-485A-BD06-27FA8999BB50"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.0.0","versionEndExcluding":"14.1.7","matchCriteriaId":"4B4A8EE5-32B8-4DFB-9431-01A76FF04037"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.5","matchCriteriaId":"CAB23F69-59A2-430F-A082-A5F81A7A464C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.5","matchCriteriaId":"CD7E2FAA-308F-450F-8990-52A7DEB8ED00"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.3.0","versionEndExcluding":"14.3.1","matchCriteriaId":"F2308ED7-163D-4ECD-AFDC-35E2A694273C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.3.0","versionEndExcluding":"14.3.1","matchCriteriaId":"157A67E5-BAEB-4C73-A3D2-A9D8E189A15B"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39891.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/335137","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39891.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/335137","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2021-39880","sourceIdentifier":"cve@gitlab.com","published":"2021-10-05T15:15:07.727","lastModified":"2026-06-17T04:04:21.130","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A Denial Of Service vulnerability in the apollo_upload_server Ruby gem in GitLab CE/EE all versions starting from 11.9 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to deny access to all users via specially crafted requests to the apollo_upload_server middleware."},{"lang":"es","value":"Una vulnerabilidad de denegación de servicio en la gema apollo_upload_server Ruby en GitLab CE/EE todas las versiones a partir de la 11.9 antes de la 14.0.9, todas las versiones a partir de la 14.1 antes de la 14.1.4, y todas las versiones a partir de la 14.2 antes de la 14.2.2 permite a un atacante denegar el acceso a todos los usuarios a través de peticiones especialmente diseñadas al middleware apollo_upload_server"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=14.2, <14.2.2","status":"affected"},{"version":">=14.1, <14.1.4","status":"affected"},{"version":">=11.9, <14.0.9","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:N/A:P","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartExcluding":"11.9.0","versionEndExcluding":"14.0.9","matchCriteriaId":"B3FAD5E0-444A-4E02-90EB-2B566FF5C357"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.9.0","versionEndExcluding":"14.0.9","matchCriteriaId":"A06CCFC9-FAC1-4920-8C43-83BB9C3C697B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartExcluding":"14.1.0","versionEndExcluding":"14.1.4","matchCriteriaId":"19C48DA3-9DC3-42D9-904C-A0BCA9444E21"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"14.1.4","matchCriteriaId":"B0917E00-8A8B-456B-8AF9-FEDE1B16079F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.2","matchCriteriaId":"3CE159DB-7F83-42A6-9527-EB372B1F0C12"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.2","matchCriteriaId":"9748F8EA-2A15-4F22-8C54-5CA56B75EA58"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39880.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/330561","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1181284","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39880.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/330561","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1181284","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-22263","sourceIdentifier":"cve@gitlab.com","published":"2021-10-11T17:15:07.537","lastModified":"2026-06-17T03:36:54.613","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 13.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. A user account with 'external' status which is granted 'Maintainer' role on any project on the GitLab instance where 'project tokens' are allowed may elevate its privilege to 'Internal' and access Internal projects."},{"lang":"es","value":"Se ha detectado un problema en GitLab afectando todas las versiones a partir de la 13.0 anteriores a 14.0.9, todas las versiones a partir de la 14.1 anteriores a 14.1.4, todas las versiones a partir de la 14.2 anteriores a 14.2.2. Una cuenta de usuario con estado \"external\" a la que se le haya concedido el rol \"Maintainer\" en cualquier proyecto de la instancia de GitLab en la que se permitan los \"tokens de proyecto\" puede elevar su privilegio a \"Internal\" y acceder a los proyectos Internos"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.0, <14.0.9","status":"affected"},{"version":">=14.1, <14.1.4","status":"affected"},{"version":">=14.2, <14.2.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":4.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":5.2}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:N","baseScore":5.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-269"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.0.0","versionEndExcluding":"14.0.9","matchCriteriaId":"63F23DAB-6DA8-4038-854B-991B239AA7A0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.0.0","versionEndExcluding":"14.0.9","matchCriteriaId":"6A06534D-7B62-4F9C-88CD-DA404FC59768"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"14.1.4","matchCriteriaId":"9A88A687-E3B3-43B3-87C6-489DF361D7D1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"14.1.4","matchCriteriaId":"B0917E00-8A8B-456B-8AF9-FEDE1B16079F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.2","matchCriteriaId":"3CE159DB-7F83-42A6-9527-EB372B1F0C12"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.2","matchCriteriaId":"9748F8EA-2A15-4F22-8C54-5CA56B75EA58"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22263.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/331473","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1193062","source":"cve@gitlab.com","tags":["Exploit","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22263.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/331473","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1193062","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-39902","sourceIdentifier":"cve@gitlab.com","published":"2021-11-04T23:15:07.667","lastModified":"2026-06-17T04:04:23.560","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Incorrect Authorization in GitLab CE/EE 13.4 or above allows a user with guest membership in a project to modify the severity of an incident."},{"lang":"es","value":"Una autorización incorrecta en GitLab CE/EE versión 13.4 o superior permite a un usuario con membresía de invitado en un proyecto modificar la gravedad de un incidente"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.4, <14.2.6","status":"affected"},{"version":">=14.3, <14.3.4","status":"affected"},{"version":">=14.4, <14.4.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.4.0","versionEndExcluding":"14.2.6","matchCriteriaId":"513B3075-3C9F-4D2A-9AA2-4F6536DD420C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.4.0","versionEndExcluding":"14.2.6","matchCriteriaId":"5EE402EB-2EDC-46AE-8924-B81E427D7EE7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.3.0","versionEndExcluding":"14.3.4","matchCriteriaId":"89D408A9-D433-4674-9EFF-94C13094C8D1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.3.0","versionEndExcluding":"14.3.4","matchCriteriaId":"79C91F49-B540-4D22-8CC9-E5CAD399E520"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.4.0:*:*:*:community:*:*:*","matchCriteriaId":"33F825B9-51B3-44A9-ADC5-395B99F866E4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.4.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"0FC6A40A-F861-445A-BD61-1ACF7D7849B1"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39902.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/341479","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1341674","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39902.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/341479","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1341674","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-39903","sourceIdentifier":"cve@gitlab.com","published":"2021-11-04T23:15:10.000","lastModified":"2026-06-17T04:04:23.710","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In all versions of GitLab CE/EE since version 13.0, a privileged user, through an API call, can change the visibility level of a group or a project to a restricted option even after the instance administrator sets that visibility option as restricted in settings."},{"lang":"es","value":"En todas las versiones de GitLab CE/EE desde versión 13.0, un usuario con privilegios, mediante una llamada a la API, puede cambiar el nivel de visibilidad de un grupo o un proyecto a una opción restringida incluso después de que el administrador de la instancia establezca esa opción de visibilidad como restringida en la configuración"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.0, <14.2.6","status":"affected"},{"version":">=14.3, <14.3.4","status":"affected"},{"version":">=14.4, <14.4.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.0.0","versionEndExcluding":"14.2.6","matchCriteriaId":"B2F52683-494D-4206-9028-CBCB7F331E55"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.0.0","versionEndExcluding":"14.2.6","matchCriteriaId":"61ECACB6-A194-4715-93EE-0339DC6C3D2E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.3.0","versionEndExcluding":"14.3.4","matchCriteriaId":"89D408A9-D433-4674-9EFF-94C13094C8D1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.3.0","versionEndExcluding":"14.3.4","matchCriteriaId":"79C91F49-B540-4D22-8CC9-E5CAD399E520"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.4.0:*:*:*:community:*:*:*","matchCriteriaId":"33F825B9-51B3-44A9-ADC5-395B99F866E4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.4.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"0FC6A40A-F861-445A-BD61-1ACF7D7849B1"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39903.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/300017","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1086781","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39903.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/300017","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1086781","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-39914","sourceIdentifier":"cve@gitlab.com","published":"2021-11-04T23:15:10.183","lastModified":"2026-06-17T04:04:25.000","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A regular expression denial of service issue in GitLab versions 8.13 to 14.2.5, 14.3.0 to 14.3.3 and 14.4.0 could cause excessive usage of resources when a specially crafted username was used when provisioning a new user"},{"lang":"es","value":"Un problema de denegación de servicio con expresiones regulares en GitLab versiones 8.13 a 14.2.5, 14.3.0 a 14.3.3 y 14.4.0, podía causar un uso excesivo de recursos cuando se usaba un nombre de usuario especialmente diseñado al aprovisionar un nuevo usuario"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=8.13, <14.2.6","status":"affected"},{"version":">=14.3.0, <14.3.4","status":"affected"},{"version":">=14.4.0, <14.4.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":3.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":1.6,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-400"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.13.0","versionEndExcluding":"14.2.6","matchCriteriaId":"BDC22F02-6C58-4F97-8864-13533B8D856D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.13.0","versionEndExcluding":"14.2.6","matchCriteriaId":"8260E67F-3155-42CE-9318-A42048E79815"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.3.0","versionEndExcluding":"14.3.4","matchCriteriaId":"89D408A9-D433-4674-9EFF-94C13094C8D1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.3.0","versionEndExcluding":"14.3.4","matchCriteriaId":"79C91F49-B540-4D22-8CC9-E5CAD399E520"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.4.0:*:*:*:community:*:*:*","matchCriteriaId":"33F825B9-51B3-44A9-ADC5-395B99F866E4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.4.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"0FC6A40A-F861-445A-BD61-1ACF7D7849B1"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39914.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/289948","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39914.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/289948","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2021-22260","sourceIdentifier":"cve@gitlab.com","published":"2021-11-05T00:15:08.843","lastModified":"2026-06-17T03:36:54.270","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A stored Cross-Site Scripting vulnerability in the DataDog integration in all versions of GitLab CE/EE starting from 13.7 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to execute arbitrary JavaScript code on the victim's behalf"},{"lang":"es","value":"Una vulnerabilidad de Cross-Site Scripting almacenada en la integración de DataDog en todas las versiones de GitLab CE/EE a partir de la 13.7 antes de la 14.0.9, todas las versiones a partir de la 14.1 antes de la 14.1.4, y todas las versiones a partir de la 14.2 antes de la 14.2.2 permite a un atacante ejecutar código JavaScript arbitrario en nombre de la víctima"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.7, <14.0.9","status":"affected"},{"version":">=14.1, <14.1.4","status":"affected"},{"version":">=14.2, <14.2.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":7.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.3,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"14.0.9","matchCriteriaId":"AD423025-5EAD-4BE9-A9D0-83A2758DE5CC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"14.0.9","matchCriteriaId":"CF1AEA4C-7835-4864-9956-5B64C5C58A9B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"14.1.4","matchCriteriaId":"9A88A687-E3B3-43B3-87C6-489DF361D7D1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"14.1.4","matchCriteriaId":"B0917E00-8A8B-456B-8AF9-FEDE1B16079F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.2","matchCriteriaId":"3CE159DB-7F83-42A6-9527-EB372B1F0C12"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.2","matchCriteriaId":"9748F8EA-2A15-4F22-8C54-5CA56B75EA58"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22260.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/336614","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1257383","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22260.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/336614","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1257383","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-39895","sourceIdentifier":"cve@gitlab.com","published":"2021-11-05T00:15:10.280","lastModified":"2026-06-17T04:04:22.783","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In all versions of GitLab CE/EE since version 8.0, an attacker can set the pipeline schedules to be active in a project export so when an unsuspecting owner imports that project, pipelines are active by default on that project. Under specialized conditions, this may lead to information disclosure if the project is imported from an untrusted source."},{"lang":"es","value":"En todas las versiones de GitLab CE/EE desde versión 8.0, un atacante puede configurar las programaciones de tuberías para que estén activas en una exportación de proyectos, de modo que cuando un propietario desprevenido importa ese proyecto, las tuberías están activas por defecto en ese proyecto. Bajo condiciones especializadas, esto puede conllevar a una divulgación de información si el proyecto es importado desde una fuente no confiable"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=8.0, <14.1.7","status":"affected"},{"version":">=14.2, <14.2.5","status":"affected"},{"version":">=14.3, <14.3.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:L","baseScore":6.0,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":0.5,"impactScore":5.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N","baseScore":4.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":0.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:H/Au:S/C:P/I:N/A:N","baseScore":2.1,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.0.0","versionEndExcluding":"14.1.7","matchCriteriaId":"108BFCA8-3661-485A-BD06-27FA8999BB50"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.0.0","versionEndExcluding":"14.1.7","matchCriteriaId":"4B4A8EE5-32B8-4DFB-9431-01A76FF04037"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.5","matchCriteriaId":"CAB23F69-59A2-430F-A082-A5F81A7A464C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.5","matchCriteriaId":"CD7E2FAA-308F-450F-8990-52A7DEB8ED00"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.3.0:*:*:*:community:*:*:*","matchCriteriaId":"3E754C1F-3FB2-4387-8523-19896FDE7A14"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.3.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"ED0EDF4C-4350-476E-A6C4-C2FEFC2078D8"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39895.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/337824","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1272535","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39895.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/337824","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1272535","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-39897","sourceIdentifier":"cve@gitlab.com","published":"2021-11-05T00:15:10.467","lastModified":"2026-06-17T04:04:23.007","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Improper access control in GitLab CE/EE version 10.5 and above allowed subgroup members with inherited access to a project from a parent group to still have access even after the subgroup is transferred"},{"lang":"es","value":"Un control de acceso inapropiado en GitLab CE/EE versión 10.5 y superiores, permitía que miembros de un subgrupo con acceso heredado a un proyecto de un grupo padre siguieran teniendo acceso incluso después de que se transfiriera el subgrupo"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.9, <12.9.8","status":"affected"},{"version":">=12.10, <12.10.7","status":"affected"},{"version":">=13.0, <13.0.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N","baseScore":2.6,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-281"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.9.0","versionEndExcluding":"12.9.8","matchCriteriaId":"63B9688C-C8BC-4E06-9A90-688E1A72EED6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.9.0","versionEndExcluding":"12.9.8","matchCriteriaId":"F76601E6-F6EF-49C4-8FBF-75A24F2ACDED"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.10.0","versionEndExcluding":"12.10.7","matchCriteriaId":"C9ED9593-9837-4849-A890-C2FDDC56C5A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.10.0","versionEndExcluding":"12.10.7","matchCriteriaId":"846CD4C7-BFCB-4DFC-901E-46CCA8ADA56A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:13.0.0:*:*:*:community:*:*:*","matchCriteriaId":"439E1C57-8846-4EB8-A78A-DE6BDAF6CAF5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:13.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"F6CA871C-BEFF-4951-AC88-ACA603C25CE1"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39897.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/341017","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1330806","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39897.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/341017","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1330806","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-39898","sourceIdentifier":"cve@gitlab.com","published":"2021-11-05T00:15:10.590","lastModified":"2026-06-17T04:04:23.120","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In all versions of GitLab CE/EE since version 10.6, a project export leaks the external webhook token value which may allow access to the project which it was exported from."},{"lang":"es","value":"En todas las versiones de GitLab CE/EE desde versión 10.6, una exportación de proyecto filtra el valor del token externo de webhook que puede permitir el acceso al proyecto desde el que se exportó"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=10.6, <14.1.7","status":"affected"},{"version":">=14.2, <14.2.5","status":"affected"},{"version":">=14.3, <14.3.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":3.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-200"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.6.0","versionEndExcluding":"14.1.7","matchCriteriaId":"5E975667-70FE-4BF7-88BC-71E9DCA541C4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.6.0","versionEndExcluding":"14.1.7","matchCriteriaId":"F86378DA-3ACE-4B89-807D-C2C0CD6C495A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.5","matchCriteriaId":"CAB23F69-59A2-430F-A082-A5F81A7A464C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.5","matchCriteriaId":"CD7E2FAA-308F-450F-8990-52A7DEB8ED00"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.3.0:*:*:*:community:*:*:*","matchCriteriaId":"3E754C1F-3FB2-4387-8523-19896FDE7A14"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.3.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"ED0EDF4C-4350-476E-A6C4-C2FEFC2078D8"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39898.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/33734","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/698068","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39898.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/33734","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/698068","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-39901","sourceIdentifier":"cve@gitlab.com","published":"2021-11-05T00:15:10.760","lastModified":"2026-06-17T04:04:23.450","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In all versions of GitLab CE/EE since version 11.10, an admin of a group can see the SCIM token of that group by visiting a specific endpoint."},{"lang":"es","value":"En todas las versiones de GitLab CE/EE desde versión 11.10, un administrador de un grupo puede visualizar el token SCIM de ese grupo visitando un endpoint específico"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=11.10, <14.2.6","status":"affected"},{"version":">=14.3, <14.3.4","status":"affected"},{"version":">=14.4, <14.4.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N","baseScore":2.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N","baseScore":2.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.10.0","versionEndExcluding":"14.2.6","matchCriteriaId":"F2CD9B47-731D-41FC-BA21-405B7E1C6F9B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.10.0","versionEndExcluding":"14.2.6","matchCriteriaId":"5E5E1FE8-0EBB-457C-9EF9-E91E45EAFBB3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.3.0","versionEndExcluding":"14.3.4","matchCriteriaId":"89D408A9-D433-4674-9EFF-94C13094C8D1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.3.0","versionEndExcluding":"14.3.4","matchCriteriaId":"79C91F49-B540-4D22-8CC9-E5CAD399E520"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.4.0:*:*:*:community:*:*:*","matchCriteriaId":"33F825B9-51B3-44A9-ADC5-395B99F866E4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.4.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"0FC6A40A-F861-445A-BD61-1ACF7D7849B1"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39901.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/11640","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/565884","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39901.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/11640","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/565884","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-39904","sourceIdentifier":"cve@gitlab.com","published":"2021-11-05T00:15:10.847","lastModified":"2026-06-17T04:04:23.890","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An Improper Access Control vulnerability in the GraphQL API in all versions of GitLab CE/EE starting from 13.1 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows a Merge Request creator to resolve discussions and apply suggestions after a project owner has locked the Merge Request"},{"lang":"es","value":"Una vulnerabilidad de control de acceso inadecuado en la API GraphQL en todas las versiones de GitLab CE/EE a partir de la 13.1 antes de la 14.2.6, en todas las versiones a partir de la 14.3 antes de la 14.3.4 y en todas las versiones a partir de la 14.4 antes de la 14.4.1 permite a un creador de solicitudes de fusión resolver debates y aplicar sugerencias después de que el propietario de un proyecto haya bloqueado la solicitud de fusión"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.1, <14.2.6","status":"affected"},{"version":">=14.3, <14.3.4","status":"affected"},{"version":">=14.4, <14.4.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"14.2.6","matchCriteriaId":"5B701A38-1E59-4324-8BCE-3DE4CEBD47AD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"14.2.6","matchCriteriaId":"AD728B83-4A21-4FCE-B4F2-CF3664333CD8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.3.0","versionEndExcluding":"14.3.4","matchCriteriaId":"89D408A9-D433-4674-9EFF-94C13094C8D1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.3.0","versionEndExcluding":"14.3.4","matchCriteriaId":"79C91F49-B540-4D22-8CC9-E5CAD399E520"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39904.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/295298","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1063420","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39904.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/295298","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1063420","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-39905","sourceIdentifier":"cve@gitlab.com","published":"2021-11-05T00:15:10.917","lastModified":"2026-06-17T04:04:24.003","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An information disclosure vulnerability in the GitLab CE/EE API since version 8.9.6 allows a user to see basic information on private groups that a public project has been shared with"},{"lang":"es","value":"Una vulnerabilidad de divulgación de información en la API de GitLab CE/EE desde la versión 8.9.6 permite a un usuario visualizar información básica sobre grupos privados con los que se ha compartido un proyecto público"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=8.9.6, <14.2.6","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.9.6","versionEndExcluding":"14.2.6","matchCriteriaId":"CFCF0CBD-4B05-4A94-9673-6A819D400373"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.9.6","versionEndExcluding":"14.2.6","matchCriteriaId":"4437CC02-B662-41A6-960A-93AF320164D9"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39905.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/28226","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/538029","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39905.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/28226","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/538029","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-39906","sourceIdentifier":"cve@gitlab.com","published":"2021-11-05T00:15:10.977","lastModified":"2026-06-17T04:04:24.110","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Improper validation of ipynb files in GitLab CE/EE version 13.5 and above allows an attacker to execute arbitrary JavaScript code on the victim's behalf."},{"lang":"es","value":"Una comprobación inapropiada de los archivos ipynb en GitLab CE/EE versión 13.5 y superiores, permite a un atacante ejecutar código JavaScript arbitrario en nombre de la víctima"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.5, <14.2.6","status":"affected"},{"version":">=14.3, <14.3.4","status":"affected"},{"version":">=14.4, <14.4.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.5.0","versionEndExcluding":"14.2.6","matchCriteriaId":"7F789731-B47A-4019-96E3-9F990251E403"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.5.0","versionEndExcluding":"14.2.6","matchCriteriaId":"42BD9BA7-BD4E-4079-B544-1E2974D7D644"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.3.0","versionEndExcluding":"14.3.4","matchCriteriaId":"89D408A9-D433-4674-9EFF-94C13094C8D1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.3.0","versionEndExcluding":"14.3.4","matchCriteriaId":"79C91F49-B540-4D22-8CC9-E5CAD399E520"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.4.0","versionEndExcluding":"14.4.1","matchCriteriaId":"2D305C0C-D7D9-449F-8FFE-24E2CFF940B9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.4.0","versionEndExcluding":"14.4.1","matchCriteriaId":"1E8C3501-2DAB-46F9-BC87-DA62E137BECC"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39906.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/341566","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1347600","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39906.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/341566","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1347600","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-39907","sourceIdentifier":"cve@gitlab.com","published":"2021-11-05T00:15:11.047","lastModified":"2026-06-17T04:04:24.220","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A potential DOS vulnerability was discovered in GitLab CE/EE starting with version 13.7. The stripping of EXIF data from certain images resulted in high CPU usage."},{"lang":"es","value":"Se ha detectado una posible vulnerabilidad de DOS en GitLab CE/EE a partir de la versión 13.7. La eliminación de los datos EXIF de determinadas imágenes resultaba en un elevado uso de la CPU"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=14.4, <14.4.1","status":"affected"},{"version":">=14.3, <14.3.4","status":"affected"},{"version":">=13.7, <14.2.6","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"14.2.6","matchCriteriaId":"E26D49ED-4972-4DD8-B6A1-08A2383A6580"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"14.2.6","matchCriteriaId":"578141AF-34A9-4132-847B-E9FAB4B501D1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.3.0","versionEndExcluding":"14.3.4","matchCriteriaId":"89D408A9-D433-4674-9EFF-94C13094C8D1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.3.0","versionEndExcluding":"14.3.4","matchCriteriaId":"79C91F49-B540-4D22-8CC9-E5CAD399E520"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.4.0","versionEndExcluding":"14.4.1","matchCriteriaId":"2D305C0C-D7D9-449F-8FFE-24E2CFF940B9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.4.0","versionEndExcluding":"14.4.1","matchCriteriaId":"1E8C3501-2DAB-46F9-BC87-DA62E137BECC"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39907.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/299869","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1083182","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39907.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/299869","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1083182","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-39909","sourceIdentifier":"cve@gitlab.com","published":"2021-11-05T00:15:11.147","lastModified":"2026-06-17T04:04:24.443","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Lack of email address ownership verification in the CODEOWNERS feature in all versions of GitLab EE starting from 11.3 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows an attacker to bypass CODEOWNERS Merge Request approval requirement under rare circumstances"},{"lang":"es","value":"La falta de verificación de la propiedad de la dirección de correo electrónico en la función CODEOWNERS en todas las versiones de GitLab EE a partir de la 11.3 antes de la 14.2.6, en todas las versiones a partir de la 14.3 antes de la 14.3.4 y en todas las versiones a partir de la 14.4 antes de la 14.4.1 permite a un atacante eludir el requisito de aprobación de la solicitud de fusión CODEOWNERS en raras circunstancias"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=11.3, <14.2.6","status":"affected"},{"version":">=14.3, <14.3.4","status":"affected"},{"version":">=14.4, <14.4.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-347"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"14.2.6","matchCriteriaId":"F7AFBE73-2546-47FF-8950-9732653E1A6F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.3.0","versionEndExcluding":"14.3.4","matchCriteriaId":"79C91F49-B540-4D22-8CC9-E5CAD399E520"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.4.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"0FC6A40A-F861-445A-BD61-1ACF7D7849B1"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.2.0","versionEndExcluding":"14.3.4","matchCriteriaId":"991530FE-7F93-46F4-9515-480966361B90"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"14.4.1","matchCriteriaId":"E77C4BBF-6EF9-47A6-8AD3-7349589AC1BC"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39909.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/335191","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1237750","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39909.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/335191","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1237750","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-39911","sourceIdentifier":"cve@gitlab.com","published":"2021-11-05T00:15:11.210","lastModified":"2026-06-17T04:04:24.670","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An improper access control flaw in all versions of GitLab CE/EE starting from 13.9 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 exposes private email address of Issue and Merge Requests assignee to Webhook data consumers"},{"lang":"es","value":"Un defecto de control de acceso inadecuado en todas las versiones de GitLab CE/EE a partir de la 13.9 antes de la 14.2.6, en todas las versiones a partir de la 14.3 antes de la 14.3.4, y en todas las versiones a partir de la 14.4 antes de la 14.4.1 expone la dirección de correo electrónico privada de la persona que asigna las incidencias y las solicitudes de fusión a los consumidores de datos Webhook"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.9, <14.2.6","status":"affected"},{"version":">=14.3, <14.3.4","status":"affected"},{"version":">=14.4, <14.4.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:P/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N","baseScore":1.7,"baseSeverity":"LOW","attackVector":"PHYSICAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":0.3,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.9.0","versionEndExcluding":"14.2.6","matchCriteriaId":"2A1127EE-4C28-4D65-B3C9-C6A3A9A0D8B8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.9.0","versionEndExcluding":"14.2.6","matchCriteriaId":"0DF10F51-D41C-4F2E-88DF-CD940B3693A7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.3.0","versionEndExcluding":"14.3.4","matchCriteriaId":"89D408A9-D433-4674-9EFF-94C13094C8D1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.3.0","versionEndExcluding":"14.3.4","matchCriteriaId":"79C91F49-B540-4D22-8CC9-E5CAD399E520"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39911.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/297470","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39911.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/297470","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2021-39912","sourceIdentifier":"cve@gitlab.com","published":"2021-11-05T00:15:11.287","lastModified":"2026-06-17T04:04:24.787","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A potential DoS vulnerability was discovered in GitLab CE/EE starting with version 13.7. Using a malformed TIFF images was possible to trigger memory exhaustion."},{"lang":"es","value":"Se ha detectado una potencial vulnerabilidad DoS en GitLab CE/EE a partir de la versión 13.7. Usando imágenes TIFF mal formadas era posible desencadenar el agotamiento de la memoria"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=14.4, <14.4.1","status":"affected"},{"version":">=14.3, <14.3.4","status":"affected"},{"version":">=13.7, <14.2.6","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"14.2.6","matchCriteriaId":"E26D49ED-4972-4DD8-B6A1-08A2383A6580"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"14.2.6","matchCriteriaId":"578141AF-34A9-4132-847B-E9FAB4B501D1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.3.0","versionEndExcluding":"14.3.4","matchCriteriaId":"89D408A9-D433-4674-9EFF-94C13094C8D1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.3.0","versionEndExcluding":"14.3.4","matchCriteriaId":"79C91F49-B540-4D22-8CC9-E5CAD399E520"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.4.0","versionEndExcluding":"14.4.1","matchCriteriaId":"2D305C0C-D7D9-449F-8FFE-24E2CFF940B9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.4.0","versionEndExcluding":"14.4.1","matchCriteriaId":"1E8C3501-2DAB-46F9-BC87-DA62E137BECC"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39912.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/341363","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1330882","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39912.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/341363","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1330882","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-39913","sourceIdentifier":"cve@gitlab.com","published":"2021-11-05T00:15:11.373","lastModified":"2026-06-17T04:04:24.890","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Accidental logging of system root password in the migration log in all versions of GitLab CE/EE before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows an attacker with local file system access to obtain system root-level privileges"},{"lang":"es","value":"El registro accidental de la contraseña de root del sistema en el registro de migración en todas las versiones de GitLab CE/EE anteriores a la 14.2.6, en todas las versiones a partir de la 14.3 antes de la 14.3.4 y en todas las versiones a partir de la 14.4 antes de la 14.4.1 permite a un atacante con acceso al sistema de archivos local obtener privilegios a nivel de root del sistema"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":"<14.2.6","status":"affected"},{"version":">=14.3, <14.3.4","status":"affected"},{"version":">=14.4, <14.4.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","baseScore":4.4,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":0.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":6.7,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":0.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":3.9,"impactScore":10.0,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-532"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"14.2.6","matchCriteriaId":"AAF9A988-5327-48FF-98B7-8927EDAC9381"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"14.2.6","matchCriteriaId":"D84364AB-6BE8-440A-A51B-A057E260E5C9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.3.0","versionEndExcluding":"14.3.4","matchCriteriaId":"89D408A9-D433-4674-9EFF-94C13094C8D1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.3.0","versionEndExcluding":"14.3.4","matchCriteriaId":"79C91F49-B540-4D22-8CC9-E5CAD399E520"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39913.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/28074","source":"cve@gitlab.com","tags":["Broken Link","Issue Tracking","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39913.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/28074","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Issue Tracking","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2021-22170","sourceIdentifier":"cve@gitlab.com","published":"2021-12-06T18:15:08.067","lastModified":"2026-06-17T03:36:44.070","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Assuming a database breach, nonce reuse issues in GitLab 11.6+ allows an attacker to decrypt some of the database's encrypted content"},{"lang":"es","value":"Suponiendo una violación de la base de datos, los problemas de reúso de nonce en GitLab versión 11.6+ permiten a un atacante descifrar parte del contenido cifrado de la base de datos"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=11.6.0, <13.5.6","status":"affected"},{"version":">=13.6.0, <13.6.4","status":"affected"},{"version":">=13.7.0, <13.7.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":6.2,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.5,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-327"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"13.5.6","matchCriteriaId":"D1CC209C-89A2-4D94-93C2-F87C2F4DC765"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.6.0","versionEndExcluding":"13.6.4","matchCriteriaId":"62B4F25F-FE51-44A1-BC14-502FD1CFD024"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"13.7.2","matchCriteriaId":"63CD3419-E8D4-4ABD-8366-C79491C37695"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22170.json","source":"cve@gitlab.com","tags":["Exploit","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/36855","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22170.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/36855","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-39890","sourceIdentifier":"cve@gitlab.com","published":"2021-12-06T18:15:08.127","lastModified":"2026-06-17T04:04:22.243","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"It was possible to bypass 2FA for LDAP users and access some specific pages with Basic Authentication in GitLab 14.1.1 and above."},{"lang":"es","value":"Era posible omitir el 2FA para usuarios de LDAP y acceder a algunas páginas específicas con autenticación básica en GitLab versiones 14.1.1 y posteriores"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=14.3, <14.3.1","status":"affected"},{"version":">=14.2, <14.2.5","status":"affected"},{"version":">=14.1.1, <14.1.7","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":3.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-287"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"14.1.1","versionEndExcluding":"14.1.7","matchCriteriaId":"7FE74A88-01A4-4A1E-A9AB-8CCE6144ED44"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.5","matchCriteriaId":"3EDBFD35-59F1-4F5A-83D6-5F705C1E6CF9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.3.0:*:*:*:community:*:*:*","matchCriteriaId":"3E754C1F-3FB2-4387-8523-19896FDE7A14"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.3.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"ED0EDF4C-4350-476E-A6C4-C2FEFC2078D8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.3.1:*:*:*:community:*:*:*","matchCriteriaId":"09C2D2FA-0C57-43B6-91E4-538748910E18"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.3.1:*:*:*:enterprise:*:*:*","matchCriteriaId":"12127E60-FAFA-4D5F-B23D-F9D2B3C33EED"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39890.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/341522","source":"cve@gitlab.com","tags":["Broken Link","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39890.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/341522","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-39910","sourceIdentifier":"cve@gitlab.com","published":"2021-12-13T16:15:08.740","lastModified":"2026-06-17T04:04:24.557","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. GitLab was vulnerable to HTML Injection through the Swagger UI feature."},{"lang":"es","value":"Se ha detectado un problema en GitLab CE/EE afectando a todas las versiones a partir de 12.6 anteriores a 14.3.6, todas las versiones a partir de 14.4 anteriores a 14.4.4, todas las versiones a partir de 14.5 anteriores a 14.5.2. GitLab era vulnerable a una inyección de HTML mediante la función Swagger UI"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.6, <14.3.6","status":"affected"},{"version":">=14.4, <14.4.4","status":"affected"},{"version":">=14.5, <14.5.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N","baseScore":2.6,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.6.0","versionEndExcluding":"14.3.6","matchCriteriaId":"37A38133-9F36-43B8-909B-3D6763E2EB6D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.6.0","versionEndExcluding":"14.3.6","matchCriteriaId":"3169438E-8AA7-443F-AEA7-81FF781BE373"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.4.0","versionEndExcluding":"14.4.4","matchCriteriaId":"1E801B5F-9C94-4CB2-89ED-D071E567132C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.4.0","versionEndExcluding":"14.4.4","matchCriteriaId":"7C38F838-02EA-4E2F-8493-57DD401EF911"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.2","matchCriteriaId":"95F59DF7-707C-4C43-8352-8115DAF1C533"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.2","matchCriteriaId":"64F26CC0-C99A-4748-963B-944F39E4B647"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39910.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/325901","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1133656","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39910.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/325901","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1133656","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-39915","sourceIdentifier":"cve@gitlab.com","published":"2021-12-13T16:15:08.800","lastModified":"2026-06-17T04:04:25.113","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Improper access control in the GraphQL API in GitLab CE/EE affecting all versions starting from 13.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker to see the names of project access tokens on arbitrary projects"},{"lang":"es","value":"Un control de acceso inapropiado en la API GraphQL en GitLab CE/EE afectando a todas las versiones a partir de 13.0 anteriores a 14.3.6, todas las versiones a partir de 14.4 anteriores a 14.4.4, todas las versiones a partir de 14.5 anteriores a 14.5.2, permite a un atacante ver los nombres de los tokens de acceso al proyecto en proyectos arbitrarios"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.0, <14.3.6","status":"affected"},{"version":">=14.4, <14.4.4","status":"affected"},{"version":">=14.5, <14.5.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-668"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.0.0","versionEndExcluding":"14.3.6","matchCriteriaId":"644C633B-0168-41DA-A71A-528066331F92"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.0.0","versionEndExcluding":"14.3.6","matchCriteriaId":"51EEAE95-0800-4F51-AA55-E2D6B2934886"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.4.0","versionEndExcluding":"14.4.4","matchCriteriaId":"1E801B5F-9C94-4CB2-89ED-D071E567132C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.4.0","versionEndExcluding":"14.4.4","matchCriteriaId":"7C38F838-02EA-4E2F-8493-57DD401EF911"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.2","matchCriteriaId":"95F59DF7-707C-4C43-8352-8115DAF1C533"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.2","matchCriteriaId":"64F26CC0-C99A-4748-963B-944F39E4B647"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39915.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/340803","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1336059","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39915.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/340803","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1336059","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-39916","sourceIdentifier":"cve@gitlab.com","published":"2021-12-13T16:15:08.860","lastModified":"2026-06-17T04:04:25.223","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Lack of an access control check in the External Status Check feature allowed any authenticated user to retrieve the configuration of any External Status Check in GitLab EE starting from 14.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2."},{"lang":"es","value":"Una falta de una comprobación de control de acceso en la función de comprobación de estado externa permitía a cualquier usuario autenticado recuperar la configuración de cualquier comprobación de estado externa en GitLab EE a partir de la versión 14.1 anteriores a 14.3.6, todas las versiones a partir de 14.4 anteriores a 14.4.4, todas las versiones a partir de 14.5 anteriores a 14.5.2"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=14.1, <14.3.6","status":"affected"},{"version":">=14.4, <14.4.4","status":"affected"},{"version":">=14.5, <14.5.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-639"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"14.3.6","matchCriteriaId":"8229FF7A-2977-4AF4-91E1-6C7BDFF7DF32"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"14.3.6","matchCriteriaId":"AB9412B6-04E5-4361-91FE-64F07CEB9500"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.4.0","versionEndExcluding":"14.4.4","matchCriteriaId":"1E801B5F-9C94-4CB2-89ED-D071E567132C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.4.0","versionEndExcluding":"14.4.4","matchCriteriaId":"7C38F838-02EA-4E2F-8493-57DD401EF911"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.2","matchCriteriaId":"95F59DF7-707C-4C43-8352-8115DAF1C533"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.2","matchCriteriaId":"64F26CC0-C99A-4748-963B-944F39E4B647"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39916.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/343379","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1372216","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39916.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/343379","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1372216","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-39917","sourceIdentifier":"cve@gitlab.com","published":"2021-12-13T16:15:08.913","lastModified":"2026-06-17T04:04:25.340","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A regular expression related to quick actions features was susceptible to catastrophic backtracking that could cause a DOS attack."},{"lang":"es","value":"Se ha detectado un problema en GitLab CE/EE afectando a todas las versiones a partir de 12.9 anteriores a 14.3.6, todas las versiones a partir de 14.4 anteriores a 14.4.4, todas las versiones a partir de 14.5 anteriores a 14.5.2. Una expresión regular relacionada con las características de las acciones rápidas era susceptible de un retroceso catastrófico que podía causar un ataque DOS"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.9, <14.3.6","status":"affected"},{"version":">=14.4, <14.4.4","status":"affected"},{"version":">=14.5, <14.5.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:N/A:P","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-697"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.9.0","versionEndExcluding":"14.3.6","matchCriteriaId":"DEC0CC7F-765F-4D63-BC9D-8A0DCBDBCC9E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.9.0","versionEndExcluding":"14.3.6","matchCriteriaId":"A1B5B973-0998-48D9-B359-3ED252F537F7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.4.0","versionEndExcluding":"14.4.4","matchCriteriaId":"1E801B5F-9C94-4CB2-89ED-D071E567132C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.4.0","versionEndExcluding":"14.4.4","matchCriteriaId":"7C38F838-02EA-4E2F-8493-57DD401EF911"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.2","matchCriteriaId":"95F59DF7-707C-4C43-8352-8115DAF1C533"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.2","matchCriteriaId":"64F26CC0-C99A-4748-963B-944F39E4B647"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39917.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/338486","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1277918","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39917.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/338486","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1277918","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-39918","sourceIdentifier":"cve@gitlab.com","published":"2021-12-13T16:15:08.970","lastModified":"2026-06-17T04:04:25.453","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Incorrect Authorization in GitLab EE affecting all versions starting from 11.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows a user to add comments to a vulnerability which cannot be accessed."},{"lang":"es","value":"Una Autorización Incorrecta en GitLab EE afectando a todas las versiones a partir de 11.1 anteriores a 14.3.6, todas las versiones a partir de 14.4 anteriores a 14.4.4, todas las versiones a partir de 14.5 anteriores a 14.5.2, permite a un usuario añadir comentarios a una vulnerabilidad a la que no es posible acceder"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=11.1, <14.3.6","status":"affected"},{"version":">=14.4, <14.4.4","status":"affected"},{"version":">=14.5, <14.5.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":3.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.1.0","versionEndExcluding":"14.3.6","matchCriteriaId":"4B375CBB-4F63-4E62-9D2D-E9224A8BE5B4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.1.0","versionEndExcluding":"14.3.6","matchCriteriaId":"7E914CBD-5470-4754-8C7F-BAB6BE7ACED6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.4.0","versionEndExcluding":"14.4.4","matchCriteriaId":"1E801B5F-9C94-4CB2-89ED-D071E567132C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.4.0","versionEndExcluding":"14.4.4","matchCriteriaId":"7C38F838-02EA-4E2F-8493-57DD401EF911"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.2","matchCriteriaId":"95F59DF7-707C-4C43-8352-8115DAF1C533"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.2","matchCriteriaId":"64F26CC0-C99A-4748-963B-944F39E4B647"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39918.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/329916","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1180043","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39918.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/329916","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1180043","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-39919","sourceIdentifier":"cve@gitlab.com","published":"2021-12-13T16:15:09.027","lastModified":"2026-06-17T04:04:25.563","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In all versions of GitLab CE/EE starting version 14.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, the reset password token and new user email token are accidentally logged which may lead to information disclosure."},{"lang":"es","value":"En todas las versiones de GitLab CE/EE a partir de versión 14.0 anteriores a 14.3.6, todas las versiones a partir de 14.4 anteriores a 14.4.4, todas las versiones a partir de 14.5 anteriores a 14.5.2, el token de restablecimiento de contraseña y el token de correo electrónico del nuevo usuario son registradas accidentalmente, lo que puede conllevar a una divulgación de información"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=14.0, <14.3.6","status":"affected"},{"version":">=14.4, <14.4.4","status":"affected"},{"version":">=14.5, <14.5.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","baseScore":4.4,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":0.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","baseScore":4.4,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":0.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:N/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-640"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.3.6","matchCriteriaId":"9FA5A64E-6E36-4F36-B106-87EBA9CC8CA6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.3.6","matchCriteriaId":"65C592BC-4B95-4190-9649-0CA04024B62F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.4.0","versionEndExcluding":"14.4.4","matchCriteriaId":"1E801B5F-9C94-4CB2-89ED-D071E567132C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.4.0","versionEndExcluding":"14.4.4","matchCriteriaId":"7C38F838-02EA-4E2F-8493-57DD401EF911"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.2","matchCriteriaId":"95F59DF7-707C-4C43-8352-8115DAF1C533"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.2","matchCriteriaId":"64F26CC0-C99A-4748-963B-944F39E4B647"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39919.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/342445","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39919.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/342445","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2021-39930","sourceIdentifier":"cve@gitlab.com","published":"2021-12-13T16:15:09.077","lastModified":"2026-06-17T04:04:26.830","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Missing authorization in GitLab EE versions between 12.4 and 14.3.6, between 14.4.0 and 14.4.4, and between 14.5.0 and 14.5.2 allowed an attacker to access a user's custom project and group templates"},{"lang":"es","value":"Una falta de autorización en GitLab EE versiones entre la 12.4 y la 14.3.6, entre la 14.4.0 y la 14.4.4, y entre la 14.5.0 y la 14.5.2, permitía a un atacante acceder a las plantillas personalizadas de proyectos y grupos de un usuario"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.4, <14.3.6","status":"affected"},{"version":">=14.4, <14.4.4","status":"affected"},{"version":">=14.5, <14.5.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.4.0","versionEndExcluding":"14.3.6","matchCriteriaId":"9AADA4A8-F37C-4C30-8745-2AB05AD1ED75"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.4.0","versionEndExcluding":"14.3.6","matchCriteriaId":"D10130CE-4BD4-4D46-A314-7208DFAC7DDA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.4.0","versionEndExcluding":"14.4.4","matchCriteriaId":"1E801B5F-9C94-4CB2-89ED-D071E567132C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.4.0","versionEndExcluding":"14.4.4","matchCriteriaId":"7C38F838-02EA-4E2F-8493-57DD401EF911"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.2","matchCriteriaId":"95F59DF7-707C-4C43-8352-8115DAF1C533"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.2","matchCriteriaId":"64F26CC0-C99A-4748-963B-944F39E4B647"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39930.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/26103","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/475240","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39930.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/26103","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/475240","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-39931","sourceIdentifier":"cve@gitlab.com","published":"2021-12-13T16:15:09.130","lastModified":"2026-06-17T04:04:26.943","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.11 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Under specific condition an unauthorised project member was allowed to delete a protected branches due to a business logic error."},{"lang":"es","value":"Se ha detectado un problema en GitLab CE/EE afectando a todas las versiones a partir de 8.11 anteriores a 14.3.6, todas las versiones a partir de 14.4 anteriores a 14.4.4, todas las versiones a partir de 14.5 anteriores a 14.5.2. Bajo una condición específica, un miembro del proyecto no autorizado podía eliminar una rama protegida debido a un error de lógica de negocio"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=8.11, <14.3.6","status":"affected"},{"version":">=14.4, <14.4.4","status":"affected"},{"version":">=14.5, <14.5.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":3.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.11.0","versionEndExcluding":"14.3.6","matchCriteriaId":"A78FD971-1C9E-452D-9DB5-7FA751CCB066"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.11.0","versionEndExcluding":"14.3.6","matchCriteriaId":"BE8381E4-15EE-4CC7-AACC-5A4D3B7F6A9B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.4.0","versionEndExcluding":"14.4.4","matchCriteriaId":"1E801B5F-9C94-4CB2-89ED-D071E567132C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.4.0","versionEndExcluding":"14.4.4","matchCriteriaId":"7C38F838-02EA-4E2F-8493-57DD401EF911"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.2","matchCriteriaId":"95F59DF7-707C-4C43-8352-8115DAF1C533"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.2","matchCriteriaId":"64F26CC0-C99A-4748-963B-944F39E4B647"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39931.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/340445","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1318379","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39931.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/340445","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1318379","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-39932","sourceIdentifier":"cve@gitlab.com","published":"2021-12-13T16:15:09.193","lastModified":"2026-06-17T04:04:27.057","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Using large payloads, the diff feature could be used to trigger high load time for users reviewing code changes."},{"lang":"es","value":"Se ha detectado un problema en GitLab CE/EE afectando a todas las versiones a partir de 11.0 anteriores a 14.3.6, todas las versiones a partir de 14.4 anteriores a 14.4.4, todas las versiones a partir de 14.5 anteriores a 14.5.2. Usando cargas útiles grandes, la función diff podría ser usada para desencadenar un alto tiempo de carga para usuarios que revisan los cambios de código"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.10, <14.3.6","status":"affected"},{"version":">=14.4, <14.4.4","status":"affected"},{"version":">=14.5, <14.5.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:N/A:P","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-20"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"14.3.6","matchCriteriaId":"6A7C3358-250D-40CB-94C6-D4BAD57EDF12"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"14.3.6","matchCriteriaId":"60E6BEBB-6965-46E2-9F9F-AE166BC93365"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.4.0","versionEndExcluding":"14.4.4","matchCriteriaId":"1E801B5F-9C94-4CB2-89ED-D071E567132C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.4.0","versionEndExcluding":"14.4.4","matchCriteriaId":"7C38F838-02EA-4E2F-8493-57DD401EF911"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.2","matchCriteriaId":"95F59DF7-707C-4C43-8352-8115DAF1C533"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.2","matchCriteriaId":"64F26CC0-C99A-4748-963B-944F39E4B647"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39932.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/217360","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39932.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/217360","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2021-39933","sourceIdentifier":"cve@gitlab.com","published":"2021-12-13T16:15:09.250","lastModified":"2026-06-17T04:04:27.160","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A regular expression used for handling user input (notes, comments, etc) was susceptible to catastrophic backtracking that could cause a DOS attack."},{"lang":"es","value":"Se ha detectado un problema en GitLab CE/EE afectando a todas las versiones a partir de 12.10 anteriores a 14.3.6, a todas las versiones a partir de 14.4 anteriores a 14.4.4, a todas las versiones a partir de 14.5 anteriores a 14.5.2. Una expresión regular usada para el manejo de la entrada del usuario (notas, comentarios, etc) era susceptible de un retroceso catastrófico que podía causar un ataque DOS"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.10, <14.3.6","status":"affected"},{"version":">=14.4, <14.4.4","status":"affected"},{"version":">=14.5, <14.5.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:N/A:P","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-1333"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.10.0","versionEndExcluding":"14.3.6","matchCriteriaId":"F093F933-8552-46D5-8B05-34587C104DFF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.10.0","versionEndExcluding":"14.3.6","matchCriteriaId":"47495883-D8D0-485E-9920-993CF00199FF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.4.0","versionEndExcluding":"14.4.4","matchCriteriaId":"1E801B5F-9C94-4CB2-89ED-D071E567132C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.4.0","versionEndExcluding":"14.4.4","matchCriteriaId":"7C38F838-02EA-4E2F-8493-57DD401EF911"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.2","matchCriteriaId":"95F59DF7-707C-4C43-8352-8115DAF1C533"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.2","matchCriteriaId":"64F26CC0-C99A-4748-963B-944F39E4B647"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39933.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/340449","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1320077","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39933.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/340449","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1320077","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-39934","sourceIdentifier":"cve@gitlab.com","published":"2021-12-13T16:15:09.310","lastModified":"2026-06-17T04:04:27.273","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Improper access control allows any project member to retrieve the service desk email address in GitLab CE/EE versions starting 12.10 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2."},{"lang":"es","value":"Un control de acceso inapropiado permite a cualquier miembro del proyecto recuperar la dirección de correo electrónico de la mesa de servicio en GitLab CE/EE versiones a partir de 12.10 anteriores a 14.3.6, todas las versiones a partir de 14.4 anteriores a 14.4.4, todas las versiones a partir de 14.5 anteriores a 14.5.2"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.10, <14.3.6","status":"affected"},{"version":">=14.4, <14.4.4","status":"affected"},{"version":">=14.5, <14.5.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-639"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.10.0","versionEndExcluding":"14.3.6","matchCriteriaId":"F093F933-8552-46D5-8B05-34587C104DFF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.10.0","versionEndExcluding":"14.3.6","matchCriteriaId":"47495883-D8D0-485E-9920-993CF00199FF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.4.0","versionEndExcluding":"14.4.4","matchCriteriaId":"1E801B5F-9C94-4CB2-89ED-D071E567132C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.4.0","versionEndExcluding":"14.4.4","matchCriteriaId":"7C38F838-02EA-4E2F-8493-57DD401EF911"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.2","matchCriteriaId":"95F59DF7-707C-4C43-8352-8115DAF1C533"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.2","matchCriteriaId":"64F26CC0-C99A-4748-963B-944F39E4B647"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39934.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/342823","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1360744","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39934.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/342823","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1360744","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-39935","sourceIdentifier":"cve@gitlab.com","published":"2021-12-13T16:15:09.367","lastModified":"2026-06-17T04:04:27.387","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Unauthorized external users could perform Server Side Requests via the CI Lint API"},{"lang":"es","value":"Se ha detectado un problema en GitLab CE/EE afectando a todas las versiones a partir de 10.5 anteriores a 14.3.6, todas las versiones a partir de 14.4 anteriores a 14.4.4, todas las versiones a partir de 14.5 anteriores a 14.5.2. Los usuarios externos no autorizados podían llevar a cabo ataques de tipo Server Side Requests por medio de la API de CI Lint"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=10.5, <14.3.6","status":"affected"},{"version":">=14.4, <14.4.4","status":"affected"},{"version":">=14.5, <14.5.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N","baseScore":6.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":4.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-02-03T15:23:46.312568Z","id":"CVE-2021-39935","options":[{"exploitation":"active"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"cisaExploitAdd":"2026-02-03","cisaActionDue":"2026-02-24","cisaRequiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","cisaVulnerabilityName":"GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability","weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.5.0","versionEndExcluding":"14.3.6","matchCriteriaId":"5B03195F-1FF5-433A-9AE5-1ACB532D4315"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.5.0","versionEndExcluding":"14.3.6","matchCriteriaId":"74E57AED-C563-4935-86BD-DB5B6495B5B0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.4.0","versionEndExcluding":"14.4.4","matchCriteriaId":"1E801B5F-9C94-4CB2-89ED-D071E567132C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.4.0","versionEndExcluding":"14.4.4","matchCriteriaId":"7C38F838-02EA-4E2F-8493-57DD401EF911"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.2","matchCriteriaId":"95F59DF7-707C-4C43-8352-8115DAF1C533"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.2","matchCriteriaId":"64F26CC0-C99A-4748-963B-944F39E4B647"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39935.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/346187","source":"cve@gitlab.com","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1236965","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39935.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/346187","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1236965","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-39935","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"]}]}},{"cve":{"id":"CVE-2021-39936","sourceIdentifier":"cve@gitlab.com","published":"2021-12-13T16:15:09.450","lastModified":"2026-06-17T04:04:27.527","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Improper access control in GitLab CE/EE affecting all versions starting from 10.7 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker in possession of a deploy token to access a project's disabled wiki."},{"lang":"es","value":"Un control de acceso inapropiado en GitLab CE/EE afectando a todas las versiones a partir de 10.7 anteriores a 14.3.6, a todas las versiones a partir de 14.4 anteriores a 14.4.4, a todas las versiones a partir de 14.5 anteriores a 14.5.2, permite a un atacante en posesión de un token de despliegue acceder a la wiki deshabilitada de un proyecto"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=10.7, <14.3.6","status":"affected"},{"version":">=14.4, <14.4.4","status":"affected"},{"version":">=14.5, <14.5.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N","baseScore":3.5,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.7.0","versionEndExcluding":"14.3.6","matchCriteriaId":"13C65B78-EB90-4AE8-A40F-4D6E2A01A1AC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.7.0","versionEndExcluding":"14.3.6","matchCriteriaId":"3AF19671-9087-438C-A0A9-89C976B71288"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.4.0","versionEndExcluding":"14.4.4","matchCriteriaId":"1E801B5F-9C94-4CB2-89ED-D071E567132C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.4.0","versionEndExcluding":"14.4.4","matchCriteriaId":"7C38F838-02EA-4E2F-8493-57DD401EF911"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.2","matchCriteriaId":"95F59DF7-707C-4C43-8352-8115DAF1C533"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.2","matchCriteriaId":"64F26CC0-C99A-4748-963B-944F39E4B647"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39936.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/241767","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/964057","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39936.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/241767","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/964057","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-39937","sourceIdentifier":"cve@gitlab.com","published":"2021-12-13T16:15:09.507","lastModified":"2026-06-17T04:04:27.637","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A collision in access memoization logic in all versions of GitLab CE/EE before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, leads to potential elevated privileges in groups and projects under rare circumstances"},{"lang":"es","value":"Una colisión en la lógica de memorización de acceso en todas las versiones de GitLab CE/EE anteriores a 14.3.6, todas las versiones a partir de 14.4 anteriores a 14.4.4, todas las versiones a partir de 14.5 anteriores a 14.5.2, conlleva a potenciales privilegios elevados en grupos y proyectos en raras circunstancias"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=0.0, <14.3.6","status":"affected"},{"version":">=14.4, <14.4.4","status":"affected"},{"version":">=14.5, <14.5.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":4.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-269"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"14.3.6","matchCriteriaId":"33693A17-B66C-4EC6-A2E4-F601FFAD792F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"14.3.6","matchCriteriaId":"DBBFD87A-01CB-4936-9611-DCB99A078996"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.4.0","versionEndExcluding":"14.4.4","matchCriteriaId":"1E801B5F-9C94-4CB2-89ED-D071E567132C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.4.0","versionEndExcluding":"14.4.4","matchCriteriaId":"7C38F838-02EA-4E2F-8493-57DD401EF911"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.2","matchCriteriaId":"95F59DF7-707C-4C43-8352-8115DAF1C533"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.2","matchCriteriaId":"64F26CC0-C99A-4748-963B-944F39E4B647"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39937.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/336802","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39937.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/336802","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2021-39938","sourceIdentifier":"cve@gitlab.com","published":"2021-12-13T16:15:09.567","lastModified":"2026-06-17T04:04:27.747","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerable regular expression pattern in GitLab CE/EE since version 8.15 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker to cause uncontrolled resource consumption leading to Denial of Service via specially crafted deploy Slash commands"},{"lang":"es","value":"Un patrón de expresión regular vulnerable en GitLab CE/EE desde la versión 8.15 anteriores a 14.3.6, todas las versiones a partir de 14.4 anteriores a 14.4.4, todas las versiones a partir de 14.5 anteriores a 14.5.2, permite a un atacante causar un consumo no controlado de recursos que conduzca a una denegación de servicio por medio de comandos deploy Slash especialmente diseñados"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=14.5, <14.5.2","status":"affected"},{"version":">=14.4, <14.4.4","status":"affected"},{"version":">=8.15, <14.3.6","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":3.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":1.6,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:N/A:P","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-400"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.15.0","versionEndExcluding":"14.3.6","matchCriteriaId":"332B8CE2-A920-47D2-957E-224551893BCF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.15.0","versionEndExcluding":"14.3.6","matchCriteriaId":"AE379EBC-5C73-42E2-AE2E-EDF3C4A45AE1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.4.0","versionEndExcluding":"14.4.4","matchCriteriaId":"1E801B5F-9C94-4CB2-89ED-D071E567132C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.4.0","versionEndExcluding":"14.4.4","matchCriteriaId":"7C38F838-02EA-4E2F-8493-57DD401EF911"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.2","matchCriteriaId":"95F59DF7-707C-4C43-8352-8115DAF1C533"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.2","matchCriteriaId":"64F26CC0-C99A-4748-963B-944F39E4B647"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39938.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/344873","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39938.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/344873","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2021-39939","sourceIdentifier":"cve@gitlab.com","published":"2021-12-13T16:15:09.617","lastModified":"2026-06-17T04:04:27.853","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An uncontrolled resource consumption vulnerability in GitLab Runner affecting all versions starting from 13.7 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker triggering a job with a specially crafted docker image to exhaust resources on runner manager"},{"lang":"es","value":"Una vulnerabilidad de consumo no controlado de recursos en GitLab Runner afectando a todas las versiones a partir de 13.7 anteriores a 14.3.6, a todas las versiones a partir de 14.4 anteriores a 14.4.4, a todas las versiones a partir de 14.5 anteriores a 14.5.2, permite a un atacante que desencadena un trabajo con una imagen docker especialmente manipulada agotar los recursos del administrador de runner"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab Runner","versions":[{"version":">=13.7, <14.3.6","status":"affected"},{"version":">=14.4, <14.4.4","status":"affected"},{"version":">=14.5, <14.5.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:N/A:P","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-400"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"14.3.6","matchCriteriaId":"F7187B3F-BBDE-4C7F-8F03-C14C02D4146C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"14.3.6","matchCriteriaId":"B25FBB5B-85C2-4771-B571-7945F06378A9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.4.0","versionEndExcluding":"14.4.4","matchCriteriaId":"1E801B5F-9C94-4CB2-89ED-D071E567132C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.4.0","versionEndExcluding":"14.4.4","matchCriteriaId":"7C38F838-02EA-4E2F-8493-57DD401EF911"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.2","matchCriteriaId":"95F59DF7-707C-4C43-8352-8115DAF1C533"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.2","matchCriteriaId":"64F26CC0-C99A-4748-963B-944F39E4B647"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39939.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-runner/-/issues/28630","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39939.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-runner/-/issues/28630","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2021-39940","sourceIdentifier":"cve@gitlab.com","published":"2021-12-13T16:15:09.667","lastModified":"2026-06-17T04:04:27.967","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. GitLab Maven Package registry is vulnerable to a regular expression denial of service when a specifically crafted string is sent."},{"lang":"es","value":"Se ha detectado un problema en GitLab CE/EE afectando a todas las versiones a partir de 13.2 anteriores a 14.3.6, a todas las versiones a partir de 14.4 anteriores a 14.4.4, a todas las versiones a partir de 14.5 anteriores a 14.5.2. El registro de paquetes de GitLab Maven es vulnerable a una denegación de servicio de expresión regular cuando es enviada una cadena específicamente manipulada"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=14.5, <14.5.2","status":"affected"},{"version":">=14.4, <14.4.4","status":"affected"},{"version":">=13.2, <14.3.6","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:N/A:P","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-1333"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"14.3.6","matchCriteriaId":"39529D7F-D52A-4D04-8E28-A90A7A9A19B5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"14.3.6","matchCriteriaId":"9DC42918-EB5D-4CF0-8CFB-CEB21CFFA56A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.4.0","versionEndExcluding":"14.4.4","matchCriteriaId":"1E801B5F-9C94-4CB2-89ED-D071E567132C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.4.0","versionEndExcluding":"14.4.4","matchCriteriaId":"7C38F838-02EA-4E2F-8493-57DD401EF911"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.2","matchCriteriaId":"95F59DF7-707C-4C43-8352-8115DAF1C533"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.2","matchCriteriaId":"64F26CC0-C99A-4748-963B-944F39E4B647"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39940.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/263116","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/997961","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39940.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/263116","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/997961","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-39941","sourceIdentifier":"cve@gitlab.com","published":"2021-12-13T16:15:09.720","lastModified":"2026-06-17T04:04:28.080","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An information disclosure vulnerability in GitLab CE/EE versions 12.0 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed non-project members to see the default branch name for projects that restrict access to the repository to project members"},{"lang":"es","value":"Una vulnerabilidad de divulgación de información en GitLab CE/EE versiones 12.0 a 14.3.6, 14.4 a 14.4.4 y 14.5 a 14.5.2, permitía a los no miembros del proyecto visualizar el nombre de la rama por defecto de los proyectos que restringen el acceso al repositorio a los miembros del proyecto"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.0, <14.3.6","status":"affected"},{"version":">=14.4, <14.4.4","status":"affected"},{"version":">=14.5, <14.5.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":3.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-200"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.0.0","versionEndExcluding":"14.3.6","matchCriteriaId":"E255C88F-CE01-42CC-9BE2-D4BFB40AD857"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.0.0","versionEndExcluding":"14.3.6","matchCriteriaId":"00830D20-52B0-45D4-A417-8F8D78F411AF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.4.0","versionEndExcluding":"14.4.4","matchCriteriaId":"1E801B5F-9C94-4CB2-89ED-D071E567132C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.4.0","versionEndExcluding":"14.4.4","matchCriteriaId":"7C38F838-02EA-4E2F-8493-57DD401EF911"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.2","matchCriteriaId":"95F59DF7-707C-4C43-8352-8115DAF1C533"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.2","matchCriteriaId":"64F26CC0-C99A-4748-963B-944F39E4B647"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39941.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/33864","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/706361","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39941.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/33864","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/706361","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-39944","sourceIdentifier":"cve@gitlab.com","published":"2021-12-13T16:15:09.773","lastModified":"2026-06-17T04:04:28.417","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A permissions validation flaw allowed group members with a developer role to elevate their privilege to a maintainer on projects they import"},{"lang":"es","value":"Se ha detectado un problema en GitLab CE/EE afectando a todas las versiones a partir de 11.0 anteriores a 14.3.6, todas las versiones a partir de 14.4 anteriores a 14.4.4, todas las versiones a partir de 14.5 anteriores a 14.5.2. Un fallo de comprobación de permisos permitía a los miembros del grupo con un rol de desarrollador elevar sus privilegios a los de mantenedor en los proyectos que importaban"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=11.0, <14.3.6","status":"affected"},{"version":">=14.4, <14.4.4","status":"affected"},{"version":">=14.5, <14.5.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":4.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":4.2}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:N","baseScore":5.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-269"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"14.3.6","matchCriteriaId":"6A7C3358-250D-40CB-94C6-D4BAD57EDF12"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"14.3.6","matchCriteriaId":"60E6BEBB-6965-46E2-9F9F-AE166BC93365"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.4.0","versionEndExcluding":"14.4.4","matchCriteriaId":"1E801B5F-9C94-4CB2-89ED-D071E567132C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.4.0","versionEndExcluding":"14.4.4","matchCriteriaId":"7C38F838-02EA-4E2F-8493-57DD401EF911"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.2","matchCriteriaId":"95F59DF7-707C-4C43-8352-8115DAF1C533"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.2","matchCriteriaId":"64F26CC0-C99A-4748-963B-944F39E4B647"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39944.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/336531","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1256017","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39944.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/336531","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1256017","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-39945","sourceIdentifier":"cve@gitlab.com","published":"2021-12-13T16:15:09.827","lastModified":"2026-06-17T04:04:28.527","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Improper access control in the GitLab CE/EE API affecting all versions starting from 9.4 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an author of a Merge Request to approve the Merge Request even after having their project access revoked"},{"lang":"es","value":"Un control de acceso inapropiado en la API de GitLab CE/EE afectando a todas las versiones a partir de 9.4 anteriores a 14.3.6, a todas las versiones a partir de 14.4 anteriores a 14.4.4, a todas las versiones a partir de 14.5 anteriores a 14.5.2, permite a un autor de una solicitud de fusión aprobar la solicitud de fusión incluso después de que le es revocado el acceso al proyecto"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=14.5, <14.5.2","status":"affected"},{"version":">=14.4, <14.4.4","status":"affected"},{"version":">=9.4, <14.3.6","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N","baseScore":2.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N","baseScore":2.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"9.4.0","versionEndExcluding":"14.3.6","matchCriteriaId":"64438CDF-3C87-455F-A1D6-1DE70D4B68D7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"9.4.0","versionEndExcluding":"14.3.6","matchCriteriaId":"8B8E7F0C-0331-4308-AB4E-8F61DA7CF766"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.4.0","versionEndExcluding":"14.4.4","matchCriteriaId":"1E801B5F-9C94-4CB2-89ED-D071E567132C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.4.0","versionEndExcluding":"14.4.4","matchCriteriaId":"7C38F838-02EA-4E2F-8493-57DD401EF911"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.2","matchCriteriaId":"95F59DF7-707C-4C43-8352-8115DAF1C533"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.2","matchCriteriaId":"64F26CC0-C99A-4748-963B-944F39E4B647"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39945.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/331675","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1198317","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39945.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/331675","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1198317","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-39892","sourceIdentifier":"cve@gitlab.com","published":"2022-01-18T17:15:08.613","lastModified":"2026-06-17T04:04:22.457","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In all versions of GitLab CE/EE since version 12.0, a lower privileged user can import users from projects that they don't have a maintainer role on and disclose email addresses of those users."},{"lang":"es","value":"En todas las versiones de GitLab CE/EE desde la versión 12.0, un usuario con bajos privilegios puede importar usuarios de proyectos en los que no presenta rol de mantenedor y revelar las direcciones de correo electrónico de esos usuarios"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.0, <14.1.7","status":"affected"},{"version":">=14.2, <14.2.5","status":"affected"},{"version":">=14.3, <14.3.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.0","versionEndExcluding":"14.1.7","matchCriteriaId":"49B8ADCC-002C-4C60-86D8-06F5AE1CC123"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.0","versionEndExcluding":"14.1.7","matchCriteriaId":"E79A41C1-5B87-49E5-A916-256A2926F155"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.2","versionEndExcluding":"14.2.5","matchCriteriaId":"A3352A07-9A5A-4CA9-B6F6-71BA3A1D4F9C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.2","versionEndExcluding":"14.2.5","matchCriteriaId":"CAAC78F3-28E1-4A0D-BA8A-78AE9393B988"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.3.0:*:*:*:community:*:*:*","matchCriteriaId":"3E754C1F-3FB2-4387-8523-19896FDE7A14"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.3.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"ED0EDF4C-4350-476E-A6C4-C2FEFC2078D8"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39892.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/28440","source":"cve@gitlab.com","tags":["Exploit","Vendor Advisory"]},{"url":"https://hackerone.com/reports/542539","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39892.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/28440","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]},{"url":"https://hackerone.com/reports/542539","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-39927","sourceIdentifier":"cve@gitlab.com","published":"2022-01-18T17:15:08.670","lastModified":"2026-06-17T04:04:26.490","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Server side request forgery protections in GitLab CE/EE versions between 8.4 and 14.4.4, between 14.5.0 and 14.5.2, and between 14.6.0 and 14.6.1 would fail to protect against attacks sending requests to localhost on port 80 or 443 if GitLab was configured to run on a port other than 80 or 443"},{"lang":"es","value":"Las protecciones contra la falsificación de solicitudes del lado del servidor en las versiones de GitLab CE/EE entre 8.4 y 14.4.4, entre 14.5.0 y 14.5.2, y entre 14.6.0 y 14.6.1 fallaban en la protección contra los ataques que enviaban solicitudes a localhost en el puerto 80 o 443 si GitLab estaba configurado para ejecutarse en un puerto distinto de 80 o 443"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=8.4, <14.4.5","status":"affected"},{"version":">=14.5, <14.5.3","status":"affected"},{"version":">=14.6, <14.6.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N","baseScore":3.5,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.4","versionEndIncluding":"14.4.5","matchCriteriaId":"18815F54-39C9-4E87-8B50-8BA058A3D140"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.4","versionEndIncluding":"14.4.5","matchCriteriaId":"EA53DF0F-A2AD-4245-AD38-673C515D4F1D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.5.0","versionEndIncluding":"14.5.3","matchCriteriaId":"04EC98EF-477A-4138-8572-EFFFC09F5553"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.5.0","versionEndIncluding":"14.5.3","matchCriteriaId":"66BCBDDE-A8A9-4CF3-8D3C-8FF6245C5EDA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.6.0","versionEndIncluding":"14.6.3","matchCriteriaId":"02B3A58F-4627-476B-A0EC-FAC73BD0C858"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.6.0","versionEndIncluding":"14.6.3","matchCriteriaId":"0601C524-6D95-476B-ACAD-BED3711BB92D"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39927.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/340476","source":"cve@gitlab.com","tags":["Broken Link","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39927.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/340476","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2021-39942","sourceIdentifier":"cve@gitlab.com","published":"2022-01-18T17:15:08.723","lastModified":"2026-06-17T04:04:28.197","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A denial of service vulnerability in GitLab CE/EE affecting all versions starting from 12.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows low-privileged users to bypass file size limits in the NPM package repository to potentially cause denial of service."},{"lang":"es","value":"Una vulnerabilidad de denegación de servicio en GitLab CE/EE que afecta a todas las versiones a partir de la 12.0 anteriores a 14.3.6, a todas las versiones a partir de la 14.4 anteriores a 14.4.4, a todas las versiones a partir de la 14.5 anteriores a 14.5.2, permite a usuarios poco privilegiados omitir los límites de tamaño de los archivos en el repositorio de paquetes NPM para causar potencialmente una denegación de servicio"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.0, <14.3.6","status":"affected"},{"version":">=14.4, <14.4.4","status":"affected"},{"version":">=14.5, <14.5.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:N/A:P","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-400"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.0","versionEndExcluding":"14.3.6","matchCriteriaId":"1C7AB60E-211F-4D45-9B36-46D8015236FB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.0","versionEndExcluding":"14.3.6","matchCriteriaId":"4596CD51-B35F-4F09-AB30-D9F3855CEB58"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.4","versionEndExcluding":"14.4.4","matchCriteriaId":"D91C9E0F-249E-4A0C-AB0F-FAEAEBBBBEC7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.4","versionEndExcluding":"14.4.4","matchCriteriaId":"61868AF5-26AA-4080-ABEE-DFAE02D94825"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.5","versionEndExcluding":"14.5.2","matchCriteriaId":"E3FD2719-9886-4B6C-A92C-4E6B662DF9E4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.5","versionEndExcluding":"14.5.2","matchCriteriaId":"3C34F25B-47BF-4ACA-9B75-2B0D46F69033"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39942.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/297492","source":"cve@gitlab.com","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1071861","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39942.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/297492","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1071861","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-39946","sourceIdentifier":"cve@gitlab.com","published":"2022-01-18T17:15:08.777","lastModified":"2026-06-17T04:04:28.640","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Improper neutralization of user input in GitLab CE/EE versions 14.3 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed an attacker to exploit XSS by abusing the generation of the HTML code related to emojis"},{"lang":"es","value":"Una neutralización inapropiada de la entrada del usuario en GitLab CE/EE versiones 14.3 a 14.3.6, 14.4 a 14.4.4 y 14.5 a 14.5.2, permitía a un atacante explotar una vulnerabilidad de tipo XSS al abusar de la generación del código HTML relacionado con los emojis"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=14.3, <14.3.6","status":"affected"},{"version":">=14.4, <14.4.4","status":"affected"},{"version":">=14.5, <14.5.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.3","versionEndExcluding":"14.3.6","matchCriteriaId":"9C09470F-03BE-4790-B7BC-4DDC238F67E4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.3","versionEndExcluding":"14.3.6","matchCriteriaId":"E37AE065-3899-47CB-851F-679056540FC4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.4","versionEndExcluding":"14.4.4","matchCriteriaId":"D91C9E0F-249E-4A0C-AB0F-FAEAEBBBBEC7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.4","versionEndExcluding":"14.4.4","matchCriteriaId":"61868AF5-26AA-4080-ABEE-DFAE02D94825"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.5","versionEndExcluding":"14.5.2","matchCriteriaId":"E3FD2719-9886-4B6C-A92C-4E6B662DF9E4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.5","versionEndExcluding":"14.5.2","matchCriteriaId":"3C34F25B-47BF-4ACA-9B75-2B0D46F69033"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39946.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/345657","source":"cve@gitlab.com","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1398305","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39946.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/345657","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1398305","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-0090","sourceIdentifier":"cve@gitlab.com","published":"2022-01-18T17:15:09.510","lastModified":"2026-06-17T04:19:57.417","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab is configured in a way that it doesn't ignore replacement references with git sub-commands, allowing a malicious user to spoof the contents of their commits in the UI."},{"lang":"es","value":"Se ha detectado un problema que afecta a versiones de GitLab anteriores a la 14.4.5, entre la 14.5.0 y la 14.5.3, y entre la 14.6.0 y la 14.6.1. GitLab está configurado de forma que no ignora las referencias de reemplazo con subcomandos git, lo que permite a un usuario malicioso falsificar el contenido de sus confirmaciones en la Interfaz de Usuario"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":"<14.4.5","status":"affected"},{"version":">=14.5.0, <14.5.3","status":"affected"},{"version":">=14.6.0, <14.6.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-269"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"14.4.5","matchCriteriaId":"DAFE3371-08B7-4003-AB1B-196DC1734C26"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"14.4.5","matchCriteriaId":"6318720F-9838-43DF-A781-BAC58DF09E88"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.3","matchCriteriaId":"F4792D58-0D9A-43E6-879B-8DC10289BBED"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.3","matchCriteriaId":"2E89DBD2-9B16-4842-B103-B2B4096C046F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.6.0","versionEndExcluding":"14.6.1","matchCriteriaId":"E8762E3A-22EC-4E2A-BFDB-29E6C97170C2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.6.0","versionEndExcluding":"14.6.1","matchCriteriaId":"1245CFA6-7887-4551-AE12-C8104F5B0B65"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0090.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitaly/-/issues/3948","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1415964","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0090.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitaly/-/issues/3948","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1415964","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2022-0093","sourceIdentifier":"cve@gitlab.com","published":"2022-01-18T17:15:09.613","lastModified":"2026-06-17T04:19:57.533","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab allows a user with an expired password to access sensitive information through RSS feeds."},{"lang":"es","value":"Se ha detectado un problema que afecta a versiones de GitLab anteriores a 14.4.5, entre 14.5.0 y 14.5.3, y entre 14.6.0 y 14.6.1. GitLab permite que un usuario con una contraseña caducada acceda a información confidencial mediante canales RSS"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":"<14.4.5","status":"affected"},{"version":">=14.5.0, <14.5.3","status":"affected"},{"version":">=14.6.0, <14.6.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N","baseScore":3.5,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"14.4.5","matchCriteriaId":"DAFE3371-08B7-4003-AB1B-196DC1734C26"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"14.4.5","matchCriteriaId":"6318720F-9838-43DF-A781-BAC58DF09E88"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.3","matchCriteriaId":"F4792D58-0D9A-43E6-879B-8DC10289BBED"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.3","matchCriteriaId":"2E89DBD2-9B16-4842-B103-B2B4096C046F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.6.0","versionEndExcluding":"14.6.1","matchCriteriaId":"E8762E3A-22EC-4E2A-BFDB-29E6C97170C2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.6.0","versionEndExcluding":"14.6.1","matchCriteriaId":"1245CFA6-7887-4551-AE12-C8104F5B0B65"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0093.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/343247","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1348738","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0093.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/343247","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1348738","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2022-0124","sourceIdentifier":"cve@gitlab.com","published":"2022-01-18T17:15:09.713","lastModified":"2026-06-17T04:20:00.840","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. Gitlab's Slack integration is incorrectly validating user input and allows to craft malicious URLs that are sent to slack."},{"lang":"es","value":"Se ha detectado un problema que afecta a las versiones de GitLab anteriores a 14.4.5, entre 14.5.0 y 14.5.3, y entre 14.6.0 y 14.6.1. La integración de Gitlab con Slack comprueba incorrectamente las entradas de los usuarios y permite que se diseñen URLs maliciosas que se envían a Slack"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":"<14.4.5","status":"affected"},{"version":">=14.5.0, <14.5.3","status":"affected"},{"version":">=14.6.0, <14.6.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-116"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"14.4.5","matchCriteriaId":"DAFE3371-08B7-4003-AB1B-196DC1734C26"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"14.4.5","matchCriteriaId":"6318720F-9838-43DF-A781-BAC58DF09E88"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.3","matchCriteriaId":"F4792D58-0D9A-43E6-879B-8DC10289BBED"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.3","matchCriteriaId":"2E89DBD2-9B16-4842-B103-B2B4096C046F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.6.0","versionEndExcluding":"14.6.1","matchCriteriaId":"E8762E3A-22EC-4E2A-BFDB-29E6C97170C2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.6.0","versionEndExcluding":"14.6.1","matchCriteriaId":"1245CFA6-7887-4551-AE12-C8104F5B0B65"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0124.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/340176","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1310778","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0124.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/340176","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1310778","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2022-0125","sourceIdentifier":"cve@gitlab.com","published":"2022-01-18T17:15:09.813","lastModified":"2026-06-17T04:20:00.953","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 12.0 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was not verifying that a maintainer of a project had the right access to import members from a target project."},{"lang":"es","value":"Se ha detectado un problema en GitLab que afecta a todas las versiones a partir de la 12.0 anteriores a 14.4.5, todas las versiones a partir de la 14.5.0 anteriores a 14.5.3, todas las versiones a partir de la 14.6.0 anteriores a 14.6.2. GitLab no verificaba que un mantenedor de un proyecto tuviera el acceso correcto para importar miembros de un proyecto de destino"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.0, <14.4.5","status":"affected"},{"version":">=14.5.0, <14.5.3","status":"affected"},{"version":">=14.6.0, <14.6.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.0","versionEndExcluding":"14.4.5","matchCriteriaId":"3D31106C-47AB-42D8-B8F2-66B24DB7ABA8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.0","versionEndExcluding":"14.4.5","matchCriteriaId":"541536FE-7310-4BCD-B56F-95D83A81FC03"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.3","matchCriteriaId":"F4792D58-0D9A-43E6-879B-8DC10289BBED"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.3","matchCriteriaId":"2E89DBD2-9B16-4842-B103-B2B4096C046F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.6.0","versionEndExcluding":"14.6.2","matchCriteriaId":"3881FF6F-04B1-4780-A445-8FD3C5E70211"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.6.0","versionEndExcluding":"14.6.2","matchCriteriaId":"404671C6-4722-446A-B0B3-BA551FEAA4FC"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0125.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/345564","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1356100","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0125.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/345564","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1356100","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2022-0151","sourceIdentifier":"cve@gitlab.com","published":"2022-01-18T17:15:09.913","lastModified":"2026-06-17T04:20:03.440","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 12.10 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was not correctly handling requests to delete existing packages which could result in a Denial of Service under specific conditions."},{"lang":"es","value":"Se ha detectado un problema en GitLab que afecta a todas las versiones a partir de la 12.10 anteriores a 14.4.5, todas las versiones a partir de la 14.5.0 anteriores a 14.5.3, todas las versiones a partir de la 14.6.0 anteriores a 14.6.2. GitLab no manejaba correctamente las peticiones de eliminación de paquetes existentes, lo que podía resultar en una denegación de servicio en determinadas condiciones"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.10, <14.4.5","status":"affected"},{"version":">=14.5.0, <14.5.3","status":"affected"},{"version":">=14.6.0, <14.6.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":1.2,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.10","versionEndExcluding":"14.4.5","matchCriteriaId":"C1049651-CE0D-4A0C-8E1D-81F674680E93"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.10","versionEndExcluding":"14.4.5","matchCriteriaId":"A62613E7-9021-480A-9629-41C042734BA5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.3","matchCriteriaId":"F4792D58-0D9A-43E6-879B-8DC10289BBED"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.3","matchCriteriaId":"2E89DBD2-9B16-4842-B103-B2B4096C046F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.6.0","versionEndExcluding":"14.6.2","matchCriteriaId":"3881FF6F-04B1-4780-A445-8FD3C5E70211"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.6.0","versionEndExcluding":"14.6.2","matchCriteriaId":"404671C6-4722-446A-B0B3-BA551FEAA4FC"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0151.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/348176","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0151.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/348176","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2022-0152","sourceIdentifier":"cve@gitlab.com","published":"2022-01-18T17:15:10.030","lastModified":"2026-06-17T04:20:03.550","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 13.10 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was vulnerable to unauthorized access to some particular fields through the GraphQL API."},{"lang":"es","value":"Se ha detectado un problema en GitLab que afecta a todas las versiones a partir de la 13.10 anteriores a 14.4.5, todas las versiones a partir de la 14.5.0 anteriores a 14.5.3, todas las versiones a partir de la 14.6.0 anteriores a 14.6.2. GitLab era vulnerable al acceso no autorizado a algunos campos concretos mediante la API GraphQL"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=14.6, <14.6.2","status":"affected"},{"version":">=14.5, <14.5.3","status":"affected"},{"version":">=13.10, <14.4.5","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.10","versionEndExcluding":"14.4.5","matchCriteriaId":"D99F1A3C-A96F-434C-AE61-5F9561DE6CDC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.10","versionEndExcluding":"14.4.5","matchCriteriaId":"BA21ACC6-C8ED-4A08-B6B1-3401BE7DDB75"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.3","matchCriteriaId":"F4792D58-0D9A-43E6-879B-8DC10289BBED"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.3","matchCriteriaId":"2E89DBD2-9B16-4842-B103-B2B4096C046F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.6.0","versionEndExcluding":"14.6.2","matchCriteriaId":"3881FF6F-04B1-4780-A445-8FD3C5E70211"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.6.0","versionEndExcluding":"14.6.2","matchCriteriaId":"404671C6-4722-446A-B0B3-BA551FEAA4FC"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0152.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/347467","source":"cve@gitlab.com","tags":["Exploit","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0152.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/347467","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-0154","sourceIdentifier":"cve@gitlab.com","published":"2022-01-18T17:15:10.110","lastModified":"2026-06-17T04:20:03.763","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 7.7 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was vulnerable to a Cross-Site Request Forgery attack that allows a malicious user to have their GitHub project imported on another GitLab user account."},{"lang":"es","value":"Se ha detectado un problema en GitLab que afecta a todas las versiones a partir de la 7.7 anteriores a 14.4.5, a todas las versiones a partir de la 14.5.0 anteriores a 14.5.3, a todas las versiones a partir de la 14.6.0 anteriores a 14.6.2. GitLab era vulnerable a un ataque de tipo Cross-Site Request Forgery que permite a un usuario malicioso importar su proyecto de GitHub en otra cuenta de usuario de GitLab"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=7.7, <14.4.5","status":"affected"},{"version":">=14.5.0, <14.5.3","status":"affected"},{"version":">=14.6.0, <14.6.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.6,"impactScore":5.9},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","baseScore":8.0,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.1,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:P/I:P/A:P","baseScore":6.0,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":6.8,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-352"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"7.7","versionEndExcluding":"14.4.5","matchCriteriaId":"7B49BE59-FBD6-4D95-AEEE-DD84A3A710CE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"7.7","versionEndExcluding":"14.4.5","matchCriteriaId":"A76D8B85-1335-4970-8FED-5227375E9207"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.3","matchCriteriaId":"F4792D58-0D9A-43E6-879B-8DC10289BBED"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.3","matchCriteriaId":"2E89DBD2-9B16-4842-B103-B2B4096C046F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.6.0","versionEndExcluding":"14.6.2","matchCriteriaId":"3881FF6F-04B1-4780-A445-8FD3C5E70211"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.6.0","versionEndExcluding":"14.6.2","matchCriteriaId":"404671C6-4722-446A-B0B3-BA551FEAA4FC"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0154.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/29580","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/605576","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0154.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/29580","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/605576","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2022-0172","sourceIdentifier":"cve@gitlab.com","published":"2022-01-18T17:15:10.187","lastModified":"2026-06-17T04:20:05.660","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.3. Under certain conditions it was possible to bypass the IP restriction for public projects through GraphQL allowing unauthorised users to read titles of issues, merge requests and milestones."},{"lang":"es","value":"Se ha detectado un problema en GitLab CE/EE que afecta a todas las versiones a partir de la 12.3. Bajo determinadas condiciones era posible omitir la restricción de IP para proyectos públicos mediante GraphQL permitiendo a usuarios no autorizados leer títulos de incidencias, peticiones de fusión e hitos"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=14.6, <14.6.2","status":"affected"},{"version":">=14.5, <14.5.3","status":"affected"},{"version":">=13.2, <14.4.5","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":2.5}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:N","baseScore":6.4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.2","versionEndExcluding":"14.4.5","matchCriteriaId":"AE9D83D8-5918-4E88-9CF7-653A6993BDA0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.2","versionEndExcluding":"14.4.5","matchCriteriaId":"4E755CF1-D60D-4576-8595-AD5D6DE88EB2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.3","matchCriteriaId":"F4792D58-0D9A-43E6-879B-8DC10289BBED"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.3","matchCriteriaId":"2E89DBD2-9B16-4842-B103-B2B4096C046F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.6.0","versionEndExcluding":"14.6.2","matchCriteriaId":"3881FF6F-04B1-4780-A445-8FD3C5E70211"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.6.0","versionEndExcluding":"14.6.2","matchCriteriaId":"404671C6-4722-446A-B0B3-BA551FEAA4FC"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0172.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/348411","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0172.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/348411","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2022-0244","sourceIdentifier":"cve@gitlab.com","published":"2022-01-18T17:15:10.677","lastModified":"2026-06-17T04:20:13.063","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting with 14.5. Arbitrary file read was possible by importing a group was due to incorrect handling of file."},{"lang":"es","value":"Se ha detectado un problema en GitLab CE/EE que afecta a todas las versiones a partir de la 14.5. Una lectura arbitraria de archivos era posible al importar un grupo debido a un manejo incorrecto del archivo"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=14.6, <14.6.2","status":"affected"},{"version":">=14.5, <14.5.3","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N","baseScore":8.6,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":4.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-552"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.5","versionEndIncluding":"14.5.3","matchCriteriaId":"5651334E-7EF0-4BB9-ABA8-62231756B8F0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.5","versionEndIncluding":"14.5.3","matchCriteriaId":"8E33E0E5-24B7-429D-8ECC-83FF22EA783F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.6","versionEndIncluding":"14.6.2","matchCriteriaId":"EA6C66A5-5514-4704-8D1E-1604F9C5248F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.6","versionEndIncluding":"14.6.2","matchCriteriaId":"A3E3A05C-677E-46F1-A311-EE3EF6E2DE8E"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0244.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/349524","source":"cve@gitlab.com","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1439593","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0244.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/349524","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1439593","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-39943","sourceIdentifier":"cve@gitlab.com","published":"2022-02-09T23:15:16.023","lastModified":"2026-06-17T04:04:28.307","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An authorization logic error in the External Status Check API in GitLab EE affecting all versions starting from 14.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allowed a user to update the status of the check via an API call"},{"lang":"es","value":"Un error de lógica de autorización en la API de comprobación de estado externo en GitLab EE afectando a todas las versiones a partir de la 14.1 anteriores a 14.3.6, a todas las versiones a partir de la 14.4 anteriores a 14.4.4, a todas las versiones a partir de la 14.5 anteriores a 14.5.2, permitía a un usuario actualizar el estado de la comprobación por medio de una llamada a la API"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=14.5.0, <14.5.2","status":"affected"},{"version":">=14.4.0, <14.4.4","status":"affected"},{"version":">=14.1.0, <14.3.6","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"14.3.6","matchCriteriaId":"AB9412B6-04E5-4361-91FE-64F07CEB9500"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.4.0","versionEndExcluding":"14.4.4","matchCriteriaId":"7C38F838-02EA-4E2F-8493-57DD401EF911"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.2","matchCriteriaId":"64F26CC0-C99A-4748-963B-944F39E4B647"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39943.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/343604","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1375393","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39943.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/343604","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1375393","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-39876","sourceIdentifier":"cve@gitlab.com","published":"2022-03-28T19:15:07.893","lastModified":"2026-06-17T04:04:20.690","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In all versions of GitLab CE/EE since version 11.3, the endpoint for auto-completing Assignee discloses the members of private groups."},{"lang":"es","value":"En todas las versiones de GitLab CE/EE desde versión 11.3, el endpoint para autocompletar la asignación divulga los miembros de los grupos privados"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=11.3, <14.1.7","status":"affected"},{"version":">=14.2, <14.2.5","status":"affected"},{"version":">=14.3, <14.3.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.3","versionEndExcluding":"14.1.7","matchCriteriaId":"D9BCF01E-CB5F-450A-B8A7-D9FFAF389F5A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"14.1.7","matchCriteriaId":"5624D85C-0265-4D57-9054-E992F328DDFB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.2","versionEndExcluding":"14.2.5","matchCriteriaId":"A3352A07-9A5A-4CA9-B6F6-71BA3A1D4F9C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.2","versionEndExcluding":"14.2.5","matchCriteriaId":"CAAC78F3-28E1-4A0D-BA8A-78AE9393B988"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.3.0","versionEndExcluding":"14.3.1","matchCriteriaId":"F2308ED7-163D-4ECD-AFDC-35E2A694273C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.3.0","versionEndExcluding":"14.3.1","matchCriteriaId":"157A67E5-BAEB-4C73-A3D2-A9D8E189A15B"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39876.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/29683","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/627507","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39876.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/29683","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/627507","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-4191","sourceIdentifier":"cve@gitlab.com","published":"2022-03-28T19:15:08.093","lastModified":"2026-06-17T04:19:11.420","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2. Private GitLab instances with restricted sign-ups may be vulnerable to user enumeration to unauthenticated users through the GraphQL API."},{"lang":"es","value":"Se ha detectado un problema en GitLab CE/EE afectando las versiones 13.0 a 14.6.5, 14.7 a 14.7.4 y 14.8 a 14.8.2. Las instancias privadas de GitLab con registros restringidos pueden ser vulnerables a una enumeración de usuarios a usuarios no autenticados mediante la API GraphQL"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=14.8, <14.8.2","status":"affected"},{"version":">=14.7, <14.7.4","status":"affected"},{"version":">=13.0, <14.6.5","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.0.0","versionEndExcluding":"14.6.5","matchCriteriaId":"E86DDC12-65BD-493C-8682-9FB31C88B266"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.0.0","versionEndExcluding":"14.6.5","matchCriteriaId":"9D503931-6E2D-4918-A184-82F4238FBD88"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.7.0","versionEndExcluding":"14.7.4","matchCriteriaId":"DA9B6C10-6253-4C3F-8897-F0080B23414C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.7.0","versionEndExcluding":"14.7.4","matchCriteriaId":"9218E9A3-C643-4987-BF82-727E0AB868E5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.8","versionEndExcluding":"14.8.2","matchCriteriaId":"6AE10377-91D9-4F0F-984C-C36C8942F643"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.8","versionEndExcluding":"14.8.2","matchCriteriaId":"66B9F17C-CF83-47DD-8D56-0FE2FE384D86"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-4191.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/343898","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1089609","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-4191.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/343898","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1089609","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-0123","sourceIdentifier":"cve@gitlab.com","published":"2022-03-28T19:15:08.147","lastModified":"2026-06-17T04:20:00.730","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab does not validate SSL certificates for some of external CI services which makes it possible to perform MitM attacks on connections to these external services."},{"lang":"es","value":"Se ha detectado un problema afectando las versiones de GitLab anteriores a 14.4.5, entre la 14.5.0 y la 14.5.3, y entre la 14.6.0 y la 14.6.1. GitLab no comprueba los certificados SSL para algunos de los servicios externos de CI, lo que hace posible llevar a cabo ataques MitM en las conexiones a estos servicios externos"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":"<14.4.5","status":"affected"},{"version":">=14.5.0, <14.5.3","status":"affected"},{"version":">=14.6.0, <14.6.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":0.7,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","baseScore":6.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":5.2}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:P/I:P/A:N","baseScore":4.9,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":6.8,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-295"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionEndExcluding":"14.4.5","matchCriteriaId":"4F63AB5F-A74D-4549-9D70-624BB8D14BF1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.3","matchCriteriaId":"7E06B612-B21F-4464-AF54-27EB09594216"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"14.6.0","versionEndExcluding":"14.6.1","matchCriteriaId":"6705A81F-BEB2-4F46-B3B4-252DAA706755"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0123.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/296632","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0123.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/296632","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2022-0136","sourceIdentifier":"cve@gitlab.com","published":"2022-03-28T19:15:08.203","lastModified":"2026-06-17T04:20:01.930","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability was discovered in GitLab versions 10.5 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1. GitLab was vulnerable to a blind SSRF attack through the Project Import feature."},{"lang":"es","value":"Se ha detectado una vulnerabilidad en GitLab versiones 10.5 a 14.5.4, 14.6 a 14.6.4 y 14.7 a 14.7.1. GitLab era vulnerable a un ataque de tipo SSRF ciego mediante la funcionalidad Project Import"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=14.7, <14.7.1","status":"affected"},{"version":">=14.6, <14.6.4","status":"affected"},{"version":">=10.5, <14.5.4","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":2.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":5.2}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:N","baseScore":5.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"10.5.0","versionEndIncluding":"14.5.4","matchCriteriaId":"63DDC36D-7F18-47B2-878C-FDCE92B1D636"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"14.6","versionEndIncluding":"14.6.4","matchCriteriaId":"4F6FF51A-0426-4DD0-9AA3-6D0EBAA18C09"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"14.7.0","versionEndIncluding":"14.7.1","matchCriteriaId":"EE17158E-7025-47E1-BB08-73F40400EBC6"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0136.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/28561","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/560658","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0136.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/28561","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/560658","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-0249","sourceIdentifier":"cve@gitlab.com","published":"2022-03-28T19:15:08.257","lastModified":"2026-06-17T04:20:13.587","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability was discovered in GitLab starting with version 12. GitLab was vulnerable to a blind SSRF attack since requests to shared address space were not blocked."},{"lang":"es","value":"Se ha detectado una vulnerabilidad en GitLab a partir de la versión 12. GitLab era vulnerable a un ataque de tipo SSRF ciego ya que no son bloqueados las peticiones al espacio de direcciones compartido"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=14.7, <14.7.1","status":"affected"},{"version":">=14.6, <14.6.4","status":"affected"},{"version":">=12.0, <14.5.4","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":3.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":5.2}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:N","baseScore":6.4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"12.0","versionEndIncluding":"14.5.4","matchCriteriaId":"6D0DE243-F3FD-4711-90DD-8D679082AFA7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"14.6","versionEndIncluding":"14.6.4","matchCriteriaId":"4F6FF51A-0426-4DD0-9AA3-6D0EBAA18C09"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"14.7","versionEndIncluding":"14.7.1","matchCriteriaId":"E433780A-3EA7-4510-8150-C58DA2DBAAE9"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0249.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/29395","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/579934","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0249.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/29395","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/579934","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-0283","sourceIdentifier":"cve@gitlab.com","published":"2022-03-28T19:15:08.310","lastModified":"2026-06-17T04:20:16.800","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered affecting GitLab versions prior to 13.5. An open redirect vulnerability was fixed in GitLab integration with Jira that a could cause the web application to redirect the request to the attacker specified URL."},{"lang":"es","value":"Se ha detectado un problema afectando GitLab versiones anteriores a 13.5. Ha sido corregido una vulnerabilidad de redireccionamiento abierto en la integración de GitLab con Jira que podía causar que la aplicación web redirigiera la petición a la URL especificada por el atacante"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=14.7, <14.7.1","status":"affected"},{"version":">=14.6, <14.6.4","status":"affected"},{"version":">=13.5, <14.5.4","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N","baseScore":4.7,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:N","baseScore":5.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-601"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.5","versionEndExcluding":"14.5.4","matchCriteriaId":"72E3D69E-887B-436E-8770-9E7777C3E526"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"14.6","versionEndExcluding":"14.6.4","matchCriteriaId":"C9E13375-EF82-4CF4-A932-9562C9BCE9E6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.7:*:*:*:*:*:*:*","matchCriteriaId":"8D887CE5-9D6A-4D63-AB37-545502C1F98C"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0283.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/349422","source":"cve@gitlab.com","tags":["Broken Link","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0283.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/349422","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-0344","sourceIdentifier":"cve@gitlab.com","published":"2022-03-28T19:15:08.363","lastModified":"2026-06-17T04:20:25.833","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 10.0 before 14.5.4, all versions starting from 10.1 before 14.6.4, all versions starting from 10.2 before 14.7.1. Private project paths can be disclosed to unauthorized users via system notes when an Issue is closed via a Merge Request and later moved to a public project"},{"lang":"es","value":"Se ha detectado un problema en GitLab afectando a todas las versiones a partir de la 10.0 anteriores a 14.5.4, todas las versiones a partir de la 10.1 anteriores a 14.6.4, todas las versiones a partir de la 10.2 anteriores a 14.7.1. Las rutas privadas de los proyectos pueden ser divulgadas a usuarios no autorizados por medio de las notas del sistema cuando una incidencia es cerrada mediante una petición de fusión y posteriormente es movida a un proyecto público"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=10.0, <14.5.4","status":"affected"},{"version":">=14.6, <14.6.4","status":"affected"},{"version":">=14.7, <14.7.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N","baseScore":3.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"10.0","versionEndExcluding":"14.5.4","matchCriteriaId":"AD73A8F0-726E-4B3B-87EC-F127DB8C4E76"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"14.6.0","versionEndExcluding":"14.6.4","matchCriteriaId":"37DBCA07-F134-490A-A96A-699B057B7669"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.7.0:*:*:*:*:*:*:*","matchCriteriaId":"877C0EA4-E5C3-4A35-87DE-E642A53B48DB"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0344.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/37015","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/724880","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0344.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/37015","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/724880","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-0371","sourceIdentifier":"cve@gitlab.com","published":"2022-03-28T19:15:08.417","lastModified":"2026-06-17T04:20:28.753","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.4 before 14.5.4, all versions starting from 14.6 before 14.6.4, all versions starting from 14.7 before 14.7.1. GitLab search may allow authenticated users to search other users by their respective private emails even if a user set their email to private."},{"lang":"es","value":"Se ha detectado un problema en GitLab CE/EE afectando a todas las versiones a partir de la 11.4 anteriores a 14.5.4, todas las versiones a partir de la 14.6 anteriores a 14.6.4, todas las versiones a partir de la 14.7 anteriores a 14.7.1. La búsqueda de GitLab puede permitir a usuarios autenticados buscar a otros usuarios por sus respectivos correos electrónicos privados, incluso si un usuario ha configurado su correo electrónico como privado"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=14.7, <14.7.1","status":"affected"},{"version":">=14.6, <14.6.4","status":"affected"},{"version":">=11.4, <14.5.4","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.4","versionEndExcluding":"14.5.4","matchCriteriaId":"49EAFB38-A6F7-46C8-A1CF-D3894FAA461E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.4","versionEndExcluding":"14.5.4","matchCriteriaId":"1A860086-27E1-40FF-822A-81E617B189A4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.6","versionEndExcluding":"14.6.4","matchCriteriaId":"3C0189DE-9664-4C19-8614-1E612871E3FC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.6","versionEndExcluding":"14.6.4","matchCriteriaId":"6E5B30E6-2263-4AB0-993A-7CC28682E3E5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.7","versionEndExcluding":"14.7.1","matchCriteriaId":"B1A305AE-2577-43BB-8FE3-B1AFF07ECF65"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.7","versionEndExcluding":"14.7.1","matchCriteriaId":"D2EC48F3-83A4-4010-8EAD-50094108D8B2"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0371.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/350476","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0371.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/350476","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2022-0427","sourceIdentifier":"cve@gitlab.com","published":"2022-03-28T19:15:08.463","lastModified":"2026-06-17T04:20:34.933","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Missing sanitization of HTML attributes in Jupyter notebooks in all versions of GitLab CE/EE since version 14.5 allows an attacker to perform arbitrary HTTP POST requests on a user's behalf leading to potential account takeover"},{"lang":"es","value":"Una falta de saneo de los atributos HTML en los cuadernos Jupyter en todas las versiones de GitLab CE/EE desde la versión 14.5 permite a un atacante llevar a cabo peticiones HTTP POST arbitrarias en nombre de un usuario, conllevando a una potencial toma de posesión de la cuenta"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=14.5, <14.5.4","status":"affected"},{"version":">=14.6, <14.6.4","status":"affected"},{"version":">=14.7, <14.7.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":7.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.3,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-352"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.5","versionEndExcluding":"14.5.4","matchCriteriaId":"68A7CE14-512A-4BB3-AACE-F3AF2E3F9B1F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.5","versionEndExcluding":"14.5.4","matchCriteriaId":"8BD6DBE6-4291-4780-B0F9-D5E9DF19EA58"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.6","versionEndExcluding":"14.6.4","matchCriteriaId":"3C0189DE-9664-4C19-8614-1E612871E3FC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.6","versionEndExcluding":"14.6.4","matchCriteriaId":"6E5B30E6-2263-4AB0-993A-7CC28682E3E5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.7","versionEndExcluding":"14.7.1","matchCriteriaId":"B1A305AE-2577-43BB-8FE3-B1AFF07ECF65"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.7","versionEndExcluding":"14.7.1","matchCriteriaId":"D2EC48F3-83A4-4010-8EAD-50094108D8B2"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0427.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/347284","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1409788","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0427.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/347284","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1409788","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-0488","sourceIdentifier":"cve@gitlab.com","published":"2022-03-28T19:15:08.517","lastModified":"2026-06-17T04:20:42.683","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting with version 8.10. It was possible to trigger a timeout on a page with markdown by using a specific amount of block-quotes."},{"lang":"es","value":"Se ha detectado un problema en GitLab CE/EE afectando a todas las versiones a partir de la 8.10. Era posible desencadenar un tiempo de espera en una página con markdown al usar una cantidad específica de comillas de bloque"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=14.7, <14.7.1","status":"affected"},{"version":">=14.6, <14.6.4","status":"affected"},{"version":">=8.10, <14.5.4","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L","baseScore":3.5,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.1,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:N/A:P","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-400"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.10","versionEndIncluding":"14.5.4","matchCriteriaId":"81E25CE7-1915-431B-AE7F-37C411178940"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.10","versionEndIncluding":"14.5.4","matchCriteriaId":"5C34F88E-1219-4C65-9472-EC59C0325DEC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.6","versionEndIncluding":"14.6.4","matchCriteriaId":"A5E65ED8-F89B-4E0F-9762-86A358E04627"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.6","versionEndIncluding":"14.6.4","matchCriteriaId":"80EEA50F-663A-47AB-9BF6-AA5BF39C2D47"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.7","versionEndIncluding":"14.7.1","matchCriteriaId":"F0DE9296-23A3-4A22-9A7B-FBA1309C98AA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.7","versionEndIncluding":"14.7.1","matchCriteriaId":"A736A0CB-B98E-4FB8-9BBB-B4E8F267492F"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0488.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/23520","source":"cve@gitlab.com","tags":["Broken Link","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0488.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/23520","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2022-0549","sourceIdentifier":"cve@gitlab.com","published":"2022-03-28T19:15:08.567","lastModified":"2026-06-17T04:20:49.253","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Under certain conditions, GitLab REST API may allow unprivileged users to add other users to groups even if that is not possible to do through the Web UI."},{"lang":"es","value":"Se ha detectado un problema en GitLab CE/EE afectando a todas las versiones anteriores a 14.3.6, todas las versiones a partir de la 14.4 anteriores a 14.4.4, todas las versiones a partir de la 14.5 anteriores a 14.5.2. En determinadas condiciones, la API REST de GitLab puede permitir a usuarios no privilegiados añadir a otros usuarios a grupos aunque no sea posible hacerlo mediante la interfaz web"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=14.5, <14.5.2","status":"affected"},{"version":">=14.4, <14.4.4","status":"affected"},{"version":">=13.2, <14.3.6","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.2","versionEndExcluding":"14.6.5","matchCriteriaId":"19F8E2DA-F708-4029-BB5F-7D04D67A8988"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.2","versionEndExcluding":"14.6.5","matchCriteriaId":"7C9603EE-C287-4347-9310-BC939B50389D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.7","versionEndExcluding":"14.7.4","matchCriteriaId":"67415A40-1BCC-4DEA-96C0-7B5BAF2F3314"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.7","versionEndExcluding":"14.7.4","matchCriteriaId":"AB98E155-8C3B-4BBB-8D01-98C51EACA5A9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.8","versionEndExcluding":"14.8.2","matchCriteriaId":"6AE10377-91D9-4F0F-984C-C36C8942F643"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.8","versionEndExcluding":"14.8.2","matchCriteriaId":"66B9F17C-CF83-47DD-8D56-0FE2FE384D86"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0549.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/342448","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0549.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/342448","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2022-0735","sourceIdentifier":"cve@gitlab.com","published":"2022-03-28T19:15:08.680","lastModified":"2026-06-17T04:21:09.110","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.6.5, all versions starting from 14.7 before 14.7.4, all versions starting from 14.8 before 14.8.2. An unauthorised user was able to steal runner registration tokens through an information disclosure vulnerability using quick actions commands."},{"lang":"es","value":"Se ha detectado un problema en GitLab CE/EE afectando a todas las versiones a partir de la 12.10 anteriores a 14.6.5, todas las versiones a partir de la 14.7 anteriores a 14.7.4, todas las versiones a partir de la 14.8 anteriores a 14.8.2. Un usuario no autorizado podía robar tokens de registro de corredores mediante una vulnerabilidad de divulgación de información usando comandos de acciones rápidas"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=14.8, <14.8.2","status":"affected"},{"version":">=14.7, <14.7.4","status":"affected"},{"version":">=12.10, <14.6.5","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","baseScore":10.0,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":6.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.0","versionEndExcluding":"14.6.5","matchCriteriaId":"2661B534-B1C3-4921-B8FE-CD4CB468EDDD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.0","versionEndExcluding":"14.6.5","matchCriteriaId":"93F2C9CA-1D32-4E1A-9E4C-42B465B5AAD9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.7","versionEndExcluding":"14.7.4","matchCriteriaId":"67415A40-1BCC-4DEA-96C0-7B5BAF2F3314"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.7","versionEndExcluding":"14.7.4","matchCriteriaId":"AB98E155-8C3B-4BBB-8D01-98C51EACA5A9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.8","versionEndExcluding":"14.8.2","matchCriteriaId":"6AE10377-91D9-4F0F-984C-C36C8942F643"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.8","versionEndExcluding":"14.8.2","matchCriteriaId":"66B9F17C-CF83-47DD-8D56-0FE2FE384D86"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0735.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/353529","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0735.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/353529","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2022-0738","sourceIdentifier":"cve@gitlab.com","published":"2022-03-28T19:15:08.733","lastModified":"2026-06-17T04:21:09.430","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 14.6 before 14.6.5, all versions starting from 14.7 before 14.7.4, all versions starting from 14.8 before 14.8.2. GitLab was leaking user passwords when adding mirrors with SSH credentials under specific conditions."},{"lang":"es","value":"Se ha detectado un problema en GitLab afectando a todas las versiones a partir de la 14.6 anteriores a 14.6.5, todas las versiones a partir de la 14.7 anteriores a 14.7.4, todas las versiones a partir de la 14.8 anteriores a 14.8.2. GitLab filtraba las contraseñas de los usuarios cuando eran añadidas réplicas con credenciales SSH en determinadas condiciones"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=14.6, <14.6.5","status":"affected"},{"version":">=14.7.0, <14.7.4","status":"affected"},{"version":">=14.8.0, <14.8.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N","baseScore":4.2,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":0.5,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-522"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.0","versionEndExcluding":"14.6.5","matchCriteriaId":"6495974A-C87F-48DB-8457-22AE7AE92D1C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.0","versionEndExcluding":"14.6.5","matchCriteriaId":"21F9F778-C8AA-4BAB-88A1-A0BF4FD26C11"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.7","versionEndExcluding":"14.7.4","matchCriteriaId":"67415A40-1BCC-4DEA-96C0-7B5BAF2F3314"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.7","versionEndExcluding":"14.7.4","matchCriteriaId":"AB98E155-8C3B-4BBB-8D01-98C51EACA5A9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.8","versionEndExcluding":"14.8.2","matchCriteriaId":"6AE10377-91D9-4F0F-984C-C36C8942F643"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.8","versionEndExcluding":"14.8.2","matchCriteriaId":"66B9F17C-CF83-47DD-8D56-0FE2FE384D86"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0738.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/27395","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0738.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/27395","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2022-0751","sourceIdentifier":"cve@gitlab.com","published":"2022-03-28T19:15:08.783","lastModified":"2026-06-17T04:21:10.867","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Inaccurate display of Snippet files containing special characters in all versions of GitLab CE/EE allows an attacker to create Snippets with misleading content which could trick unsuspecting users into executing arbitrary commands"},{"lang":"es","value":"Una visualización imprecisa de los archivos Snippet que contienen caracteres especiales en todas las versiones de GitLab CE/EE permite a un atacante crear Snippets con contenido engañoso que podría engañar a usuarios desprevenidos para que ejecuten comandos arbitrario"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=10.0, <14.6.5","status":"affected"},{"version":">=14.7, <14.7.4","status":"affected"},{"version":">=14.8, <14.8.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.0","versionEndExcluding":"14.6.5","matchCriteriaId":"6495974A-C87F-48DB-8457-22AE7AE92D1C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.0","versionEndExcluding":"14.6.5","matchCriteriaId":"21F9F778-C8AA-4BAB-88A1-A0BF4FD26C11"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.7","versionEndExcluding":"14.7.4","matchCriteriaId":"67415A40-1BCC-4DEA-96C0-7B5BAF2F3314"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.7","versionEndExcluding":"14.7.4","matchCriteriaId":"AB98E155-8C3B-4BBB-8D01-98C51EACA5A9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.8","versionEndExcluding":"14.8.2","matchCriteriaId":"6AE10377-91D9-4F0F-984C-C36C8942F643"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.8","versionEndExcluding":"14.8.2","matchCriteriaId":"66B9F17C-CF83-47DD-8D56-0FE2FE384D86"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0751.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/349382","source":"cve@gitlab.com","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1420660","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0751.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/349382","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1420660","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-39908","sourceIdentifier":"cve@gitlab.com","published":"2022-04-01T23:15:10.407","lastModified":"2026-06-17T04:04:24.330","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In all versions of GitLab CE/EE starting from 0.8.0 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 certain Unicode characters can be abused to commit malicious code into projects without being noticed in merge request or source code viewer UI."},{"lang":"es","value":"En todas las versiones de GitLab CE/EE a partir de la 0.8.0 antes de la 14.2.6, en todas las versiones a partir de la 14.3 antes de la 14.3.4, y en todas las versiones a partir de la 14.4 antes de la 14.4.1 se puede abusar de ciertos caracteres Unicode para enviar código malicioso a los proyectos sin que se note en la solicitud de fusión o en la interfaz del visor de código fuente"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=0.8.0, <14.2.6","status":"affected"},{"version":">=14.3, <14.3.4","status":"affected"},{"version":">=14.4, <14.4.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-94"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"0.8.0","versionEndExcluding":"14.2.6","matchCriteriaId":"EE2068DD-BD45-4EDF-A544-C7C62E94A49C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"0.8.0","versionEndExcluding":"14.2.6","matchCriteriaId":"649F8BEC-EC6C-4C04-94E2-8B56CFBCAC0F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.3.0","versionEndExcluding":"14.3.4","matchCriteriaId":"89D408A9-D433-4674-9EFF-94C13094C8D1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.3.0","versionEndExcluding":"14.3.4","matchCriteriaId":"79C91F49-B540-4D22-8CC9-E5CAD399E520"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.4.0:*:*:*:community:*:*:*","matchCriteriaId":"33F825B9-51B3-44A9-ADC5-395B99F866E4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.4.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"0FC6A40A-F861-445A-BD61-1ACF7D7849B1"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39908.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/337193","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1280077","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39908.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/337193","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1280077","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-0373","sourceIdentifier":"cve@gitlab.com","published":"2022-04-01T23:15:10.903","lastModified":"2026-06-17T04:20:28.970","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Improper access control in GitLab CE/EE versions 12.4 to 14.5.4, 14.5 to 14.6.4, and 12.6 to 14.7.1 allows project non-members to retrieve the service desk email address"},{"lang":"es","value":"Un control de acceso inapropiado en GitLab CE/EE versiones 12.4 a 14.5.4, 14.5 a 14.6.4 y 12.6 a 14.7.1, permite que personas que no son miembros del proyecto recuperen la dirección de correo electrónico del servicio de asistencia técnica"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.4, <14.5.4","status":"affected"},{"version":">=14.6, <14.6.4","status":"affected"},{"version":">=14.7, <14.7.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:P/I:N/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.4.0","versionEndExcluding":"14.7.1","matchCriteriaId":"EF019304-B0BF-419E-AE02-B78EA53BDFC1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.4.0","versionEndExcluding":"14.7.1","matchCriteriaId":"29BC3D24-9478-4F4A-9262-317A91BA7716"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0373.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/349881","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking","Third Party Advisory"]},{"url":"https://hackerone.com/reports/1439254","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0373.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/349881","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Third Party Advisory"]},{"url":"https://hackerone.com/reports/1439254","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-0390","sourceIdentifier":"cve@gitlab.com","published":"2022-04-01T23:15:11.120","lastModified":"2026-06-17T04:20:30.907","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Improper access control in Gitlab CE/EE versions 12.7 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1 allowed for project non-members to retrieve issue details when it was linked to an item from the vulnerability dashboard."},{"lang":"es","value":"Un control de acceso inapropiado en Gitlab CE/EE versiones 12.7 a 14.5.4, 14.6 a 14.6.4 y 14.7 a 14.7.1, permitía a personas que no eran miembros del proyecto recuperar los detalles de las incidencias cuando estaban vinculadas a un elemento del panel de control de vulnerabilidades"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=14.7, <14.7.1","status":"affected"},{"version":">=14.6, <14.6.4","status":"affected"},{"version":">=12.7, <14.5.4","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:H/Au:S/C:P/I:N/A:N","baseScore":2.1,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.7.0","versionEndIncluding":"14.5.4","matchCriteriaId":"A3E62CCA-B6FF-4834-9264-CED86BF0FEB1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.7.0","versionEndIncluding":"14.5.4","matchCriteriaId":"A4A5D04B-E18D-461F-95C4-A5409E730EAC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.6.0","versionEndIncluding":"14.6.4","matchCriteriaId":"6614BCF7-A0FF-47DD-8FEC-EE85002B95FA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.6.0","versionEndIncluding":"14.6.4","matchCriteriaId":"BC7C0DFD-980D-4B75-8EA1-6E92D07691FF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.7.0:*:*:*:community:*:*:*","matchCriteriaId":"E1777EA5-F6AF-4ED5-8FC9-831E07928413"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.7.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"54B6C3BE-A861-456C-9319-A61E2041BE32"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0390.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/330030","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking","Third Party Advisory"]},{"url":"https://hackerone.com/reports/1179733","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0390.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/330030","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Third Party Advisory"]},{"url":"https://hackerone.com/reports/1179733","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-0425","sourceIdentifier":"cve@gitlab.com","published":"2022-04-01T23:15:11.333","lastModified":"2026-06-17T04:20:34.723","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A DNS rebinding vulnerability in the Irker IRC Gateway integration in all versions of GitLab CE/EE since version 7.9 allows an attacker to trigger Server Side Request Forgery (SSRF) attacks."},{"lang":"es","value":"Una vulnerabilidad de reenganche de DNS en la integración de Irker IRC Gateway en todas las versiones de GitLab CE/EE desde la versión 7.9, permite a un atacante desencadenar ataques de tipo Server Side Request Forgery (SSRF)"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=7.9, <14.5.4","status":"affected"},{"version":">=14.6, <14.6.4","status":"affected"},{"version":">=14.7, <14.7.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H","baseScore":7.6,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":4.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"7.9.0","versionEndIncluding":"14.7.1","matchCriteriaId":"CABAE3BA-0CC8-4F46-AAE8-D01ADE447437"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"7.9.0","versionEndIncluding":"14.7.1","matchCriteriaId":"DB6EABDA-E5E0-4BE1-8738-8DD615A626BC"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0425.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/22350","source":"cve@gitlab.com","tags":["Broken Link","Issue Tracking","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0425.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/22350","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Issue Tracking","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-0489","sourceIdentifier":"cve@gitlab.com","published":"2022-04-01T23:15:11.523","lastModified":"2026-06-17T04:20:42.800","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting with 8.15 . It was possible to trigger a DOS by using the math feature with a specific formula in issue comments."},{"lang":"es","value":"Se ha detectado un problema en GitLab CE/EE afectando a todas las versiones a partir de la 8.15 . Era posible desencadenar un DOS usando la función de matemáticas con una fórmula específica en los comentarios de la edición"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=14.8, <14.8.2","status":"affected"},{"version":">=14.7, <14.7.4","status":"affected"},{"version":">=8.15, <14.6.5","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L","baseScore":3.5,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.1,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","baseScore":5.7,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.1,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:N/A:P","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-400"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.15.0","versionEndExcluding":"14.6.5","matchCriteriaId":"7D3393DB-D324-4646-B390-467515F6E3BB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.15.0","versionEndExcluding":"14.6.5","matchCriteriaId":"37378EB1-A312-4213-97EE-150ADEE6C794"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.7.0","versionEndIncluding":"14.7.4","matchCriteriaId":"626DC589-ABBD-439F-9539-C3EF7850706D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.7.0","versionEndIncluding":"14.7.4","matchCriteriaId":"41D63146-7D22-49F1-A27D-DE729D626265"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.8.0","versionEndExcluding":"14.8.2","matchCriteriaId":"28DF0C1C-6F5A-442F-8302-0198C06228C1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.8.0","versionEndExcluding":"14.8.2","matchCriteriaId":"8746B94D-12B9-493E-97A2-CC8DCBA0BD18"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0489.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/341832","source":"cve@gitlab.com","tags":["Exploit","Patch","Third Party Advisory"]},{"url":"https://hackerone.com/reports/1350793","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0489.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/341832","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Patch","Third Party Advisory"]},{"url":"https://hackerone.com/reports/1350793","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-0741","sourceIdentifier":"cve@gitlab.com","published":"2022-04-01T23:15:11.737","lastModified":"2026-06-17T04:21:09.747","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Improper input validation in all versions of GitLab CE/EE using sendmail to send emails allowed an attacker to steal environment variables via specially crafted email addresses."},{"lang":"es","value":"Una comprobación de entrada inapropiada en todas las versiones de GitLab CE/EE usando sendmail para enviar correos electrónicos permitía a un atacante robar variables de entorno por medio de direcciones de correo electrónico especialmente diseñadas"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=10.0, <14.6.5","status":"affected"},{"version":">=14.7, <14.7.4","status":"affected"},{"version":">=14.8, <14.8.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N","baseScore":5.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.3,"impactScore":4.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-116"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.0.0","versionEndExcluding":"14.6.5","matchCriteriaId":"ECC15A05-90A3-474F-8F18-AFDBE68B2C28"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.0.0","versionEndExcluding":"14.6.5","matchCriteriaId":"5997FCB7-1CC3-4157-A98C-E247436EE5E5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.7.0","versionEndExcluding":"14.7.4","matchCriteriaId":"DA9B6C10-6253-4C3F-8897-F0080B23414C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.7.0","versionEndExcluding":"14.7.4","matchCriteriaId":"9218E9A3-C643-4987-BF82-727E0AB868E5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.8.0","versionEndExcluding":"14.8.2","matchCriteriaId":"28DF0C1C-6F5A-442F-8302-0198C06228C1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.8.0","versionEndExcluding":"14.8.2","matchCriteriaId":"8746B94D-12B9-493E-97A2-CC8DCBA0BD18"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0741.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/337601","source":"cve@gitlab.com","tags":["Issue Tracking","Third Party Advisory"]},{"url":"https://hackerone.com/reports/1286317","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0741.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/337601","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Third Party Advisory"]},{"url":"https://hackerone.com/reports/1286317","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-0740","sourceIdentifier":"cve@gitlab.com","published":"2022-04-04T20:15:09.547","lastModified":"2026-06-17T04:21:09.633","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Incorrect authorization in the Asana integration's branch restriction feature in all versions of GitLab CE/EE starting from version 7.8.0 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 makes it possible to close Asana tasks from unrestricted branches."},{"lang":"es","value":"Una autorización incorrecta en la funcionalidad integration's branch restriction de Asana en todas las versiones de GitLab CE/EE a partir de la versión 7.8.0 antes de la 14.7.7, todas las versiones a partir de la 14.8 anteriores a 14.8.5, todas las versiones a partir de la 14.9 anteriores a 14.9.2 permite cerrar tareas de Asana desde ramas no restringidas"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=7.8, <14.7.7","status":"affected"},{"version":">=14.8, <14.8.5","status":"affected"},{"version":">=14.9, <14.9.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":3.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"7.8.0","versionEndExcluding":"14.7.7","matchCriteriaId":"6379D400-D578-4370-A80B-CC9A8C9E1F4E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"7.8.0","versionEndExcluding":"14.7.7","matchCriteriaId":"9BF5E386-1E01-4771-A745-E0D3D55D13BF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.8.0","versionEndExcluding":"14.8.5","matchCriteriaId":"723E51BE-5A83-439E-8D37-EACDC4E5E6B2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.8.0","versionEndExcluding":"14.8.5","matchCriteriaId":"B21DB80A-89B0-4821-AACD-A0DB4102C123"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.2","matchCriteriaId":"50473ACF-87F3-4919-A1C8-1C1D3AED7024"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.2","matchCriteriaId":"84DA7B4F-42A6-4940-98D5-3BF151FD3287"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0740.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/349359","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1411216","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0740.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/349359","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1411216","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-1099","sourceIdentifier":"cve@gitlab.com","published":"2022-04-04T20:15:09.597","lastModified":"2026-06-17T04:21:49.500","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Adding a very large number of tags to a runner in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an attacker to impact the performance of GitLab"},{"lang":"es","value":"La adición de un número muy grande de etiquetas a un corredor en GitLab CE/EE afectando a todas las versiones anteriores a 14.7.7, 14.8 anteriores a 14.8.5 y 14.9 anteriores a 14.9.2 permite a un atacante afectar al rendimiento de GitLab"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":"<14.7.7","status":"affected"},{"version":">=14.8, <14.8.5","status":"affected"},{"version":">=14.9, <14.9.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:N/A:P","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-400"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"14.7.7","matchCriteriaId":"8974DCCE-04EB-4C60-804B-DB14AF98097B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"14.7.7","matchCriteriaId":"235F4C2C-2274-43A8-9513-4F598ED9CF06"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.8.0","versionEndExcluding":"14.8.5","matchCriteriaId":"723E51BE-5A83-439E-8D37-EACDC4E5E6B2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.8.0","versionEndExcluding":"14.8.5","matchCriteriaId":"B21DB80A-89B0-4821-AACD-A0DB4102C123"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.2","matchCriteriaId":"50473ACF-87F3-4919-A1C8-1C1D3AED7024"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.2","matchCriteriaId":"84DA7B4F-42A6-4940-98D5-3BF151FD3287"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1099.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/328593","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1099.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/328593","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2022-1100","sourceIdentifier":"cve@gitlab.com","published":"2022-04-04T20:15:09.647","lastModified":"2026-06-17T04:21:49.607","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 13.1 prior to 14.7.7, 14.8.0 prior to 14.8.5, and 14.9.0 prior to 14.9.2. The api to update an asset as a link from a release had a regex check which caused exponential number of backtracks for certain user supplied values resulting in high CPU usage."},{"lang":"es","value":"Se ha detectado una posible vulnerabilidad de DOS en GitLab CE/EE afectando a todas las versiones desde 13.1 anteriores a 14.7.7, 14.8.0 anteriores a 14.8.5 y 14.9.0 anteriores a 14.9.2. La api para actualizar un activo como enlace desde una versión tenía una comprobación regex que causaba un número exponencial de retrocesos para determinados valores suministrados por el usuario, resultando en un alto uso de la CPU"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.1, <14.7.7","status":"affected"},{"version":">=14.8, <14.8.5","status":"affected"},{"version":">=14.9, <14.9.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:N/A:P","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-772"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"14.7.7","matchCriteriaId":"658BBB28-2037-49CA-979C-B86B3D9C2C7F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"14.7.7","matchCriteriaId":"F2F68377-44D9-42B8-8412-16EFA07CBDD1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.8.0","versionEndExcluding":"14.8.5","matchCriteriaId":"723E51BE-5A83-439E-8D37-EACDC4E5E6B2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.8.0","versionEndExcluding":"14.8.5","matchCriteriaId":"B21DB80A-89B0-4821-AACD-A0DB4102C123"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.2","matchCriteriaId":"50473ACF-87F3-4919-A1C8-1C1D3AED7024"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.2","matchCriteriaId":"84DA7B4F-42A6-4940-98D5-3BF151FD3287"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1100.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/273771","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1100.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/273771","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2022-1105","sourceIdentifier":"cve@gitlab.com","published":"2022-04-04T20:15:09.703","lastModified":"2026-06-17T04:21:50.177","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An improper access control vulnerability in GitLab CE/EE affecting all versions from 13.11 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an unauthorized user to access pipeline analytics even when public pipelines are disabled"},{"lang":"es","value":"Una vulnerabilidad de control de acceso inapropiado en GitLab CE/EE afectando a todas las versiones desde 13.11 hasta 14.7.7, 14.8 hasta 14.8.5 y 14.9 hasta 14.9.2, permite que un usuario no autorizado acceda a los análisis de canalizaciones incluso cuando las canalizaciones públicas están deshabilitadas"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.11, <14.7.7","status":"affected"},{"version":">=14.8, <14.8.5","status":"affected"},{"version":">=14.9, <14.9.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.11.0","versionEndExcluding":"14.7.7","matchCriteriaId":"2F61287B-7BCA-45AA-BC79-3FECEFFCAA6F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.11.0","versionEndExcluding":"14.7.7","matchCriteriaId":"DAF7F003-7EA5-47B3-8088-702D9EF48CA0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.8.0","versionEndExcluding":"14.8.5","matchCriteriaId":"723E51BE-5A83-439E-8D37-EACDC4E5E6B2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.8.0","versionEndExcluding":"14.8.5","matchCriteriaId":"B21DB80A-89B0-4821-AACD-A0DB4102C123"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.2","matchCriteriaId":"50473ACF-87F3-4919-A1C8-1C1D3AED7024"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.2","matchCriteriaId":"84DA7B4F-42A6-4940-98D5-3BF151FD3287"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1105.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/335933","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1105.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/335933","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2022-1111","sourceIdentifier":"cve@gitlab.com","published":"2022-04-04T20:15:09.750","lastModified":"2026-06-17T04:21:50.863","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A business logic error in Project Import in GitLab CE/EE versions 14.9 prior to 14.9.2, 14.8 prior to 14.8.5, and 14.0 prior to 14.7.7 under certain conditions caused imported projects to show an incorrect user in the 'Access Granted' column in the project membership pages"},{"lang":"es","value":"Un error de lógica empresarial en la Importación de Proyectos en GitLab CE/EE versiones 14.9 anteriores a 14.9.2, 14.8 anteriores a 14.8.5 y 14.0 anteriores a 14.7.7 causaba, en determinadas condiciones, que los proyectos importados mostraran un usuario incorrecto en la columna \"Access Granted\" de las páginas de pertenencia al proyecto"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=14.9, <14.9.2","status":"affected"},{"version":">=14.8.0, <14.8.5","status":"affected"},{"version":">=14.0, <14.7.7","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N","baseScore":2.4,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":0.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N","baseScore":2.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.7.7","matchCriteriaId":"927C8227-59BF-4D78-9CC6-8D5DE56C69ED"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.7.7","matchCriteriaId":"8B99B199-41E9-49D3-8EC1-2E10CCB9F876"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.8.0","versionEndExcluding":"14.8.5","matchCriteriaId":"723E51BE-5A83-439E-8D37-EACDC4E5E6B2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.8.0","versionEndExcluding":"14.8.5","matchCriteriaId":"B21DB80A-89B0-4821-AACD-A0DB4102C123"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.2","matchCriteriaId":"50473ACF-87F3-4919-A1C8-1C1D3AED7024"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.2","matchCriteriaId":"84DA7B4F-42A6-4940-98D5-3BF151FD3287"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1111.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/345236","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1111.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/345236","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2022-1120","sourceIdentifier":"cve@gitlab.com","published":"2022-04-04T20:15:09.800","lastModified":"2026-06-17T04:21:52.020","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Missing filtering in an error message in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 exposed sensitive information when an include directive fails in the CI/CD configuration."},{"lang":"es","value":"Una falta de filtrado en un mensaje de error en GitLab CE/EE afectando a todas las versiones anteriores a 14.7.7, 14.8 anteriores a 14.8.5 y 14.9 anteriores a 14.9.2, expone información confidencial cuando falla una directiva de inclusión en la configuración de CI/CD"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":"<14.7.7","status":"affected"},{"version":">=14.8, <14.8.5","status":"affected"},{"version":">=14.9, <14.9.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N","baseScore":4.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-209"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"14.7.7","matchCriteriaId":"8974DCCE-04EB-4C60-804B-DB14AF98097B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"14.7.7","matchCriteriaId":"235F4C2C-2274-43A8-9513-4F598ED9CF06"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.8.0","versionEndExcluding":"14.8.5","matchCriteriaId":"723E51BE-5A83-439E-8D37-EACDC4E5E6B2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.8.0","versionEndExcluding":"14.8.5","matchCriteriaId":"B21DB80A-89B0-4821-AACD-A0DB4102C123"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.2","matchCriteriaId":"50473ACF-87F3-4919-A1C8-1C1D3AED7024"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.2","matchCriteriaId":"84DA7B4F-42A6-4940-98D5-3BF151FD3287"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1120.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/343466","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1408731","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1120.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/343466","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1408731","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-1121","sourceIdentifier":"cve@gitlab.com","published":"2022-04-04T20:15:09.847","lastModified":"2026-06-17T04:21:52.133","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A lack of appropriate timeouts in GitLab Pages included in GitLab CE/EE all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an attacker to cause unlimited resource consumption."},{"lang":"es","value":"Una falta de tiempos de espera apropiados en GitLab Pages incluidos en GitLab CE/EE todas las versiones anteriores a 14.7.7, 14.8 anteriores a 14.8.5 y 14.9 anteriores a 14.9.2, permite a un atacante causar un consumo no limitado de recursos"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab Pages","versions":[{"version":"<14.7.7","status":"affected"},{"version":">=14.8, <14.8.5","status":"affected"},{"version":">=14.9, <14.9.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"14.7.7","matchCriteriaId":"8974DCCE-04EB-4C60-804B-DB14AF98097B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"14.7.7","matchCriteriaId":"235F4C2C-2274-43A8-9513-4F598ED9CF06"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.8.0","versionEndExcluding":"14.8.5","matchCriteriaId":"723E51BE-5A83-439E-8D37-EACDC4E5E6B2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.8.0","versionEndExcluding":"14.8.5","matchCriteriaId":"B21DB80A-89B0-4821-AACD-A0DB4102C123"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.2","matchCriteriaId":"50473ACF-87F3-4919-A1C8-1C1D3AED7024"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.2","matchCriteriaId":"84DA7B4F-42A6-4940-98D5-3BF151FD3287"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1121.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-pages/-/issues/684","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1121.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-pages/-/issues/684","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2022-1148","sourceIdentifier":"cve@gitlab.com","published":"2022-04-04T20:15:09.897","lastModified":"2026-06-17T04:21:54.590","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Improper authorization in GitLab Pages included with GitLab CE/EE affecting all versions from 11.5 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an attacker to steal a user's access token on an attacker-controlled private GitLab Pages website and reuse that token on the victim's other private websites"},{"lang":"es","value":"Una autorización inapropiada en GitLab Pages incluida en GitLab CE/EE afectando a todas las versiones desde la 11.5 anteriores a 14.7.7, 14.8 anteriores a 14.8.5 y 14.9 anteriores a 14.9.2, permitía a un atacante robar el token de acceso de un usuario en un sitio web privado de GitLab Pages controlado por el atacante y reusar ese token en otros sitios web privados de la víctima"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=11.5, <14.7.7","status":"affected"},{"version":">=14.8, <14.8.5","status":"affected"},{"version":">=14.9, <14.9.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-565"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"14.7.7","matchCriteriaId":"65ACAA64-7197-43D5-B0F8-90E240D9DB60"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"14.7.7","matchCriteriaId":"A6C78B2C-B5E2-4852-8863-C551CA0A9940"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.8.0","versionEndExcluding":"14.8.5","matchCriteriaId":"723E51BE-5A83-439E-8D37-EACDC4E5E6B2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.8.0","versionEndExcluding":"14.8.5","matchCriteriaId":"B21DB80A-89B0-4821-AACD-A0DB4102C123"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.2","matchCriteriaId":"50473ACF-87F3-4919-A1C8-1C1D3AED7024"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.2","matchCriteriaId":"84DA7B4F-42A6-4940-98D5-3BF151FD3287"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1148.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/350687","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1439552","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1148.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/350687","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1439552","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-1162","sourceIdentifier":"cve@gitlab.com","published":"2022-04-04T20:15:09.943","lastModified":"2026-06-17T04:21:55.940","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE versions 14.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowing attackers to potentially take over accounts"},{"lang":"es","value":"En GitLab CE/EE versiones 14.7 anteriores a 14.7.7, 14.8 anteriores a 14.8.5 y 14.9 anteriores a 14.9.2, era establecida una contraseña embebida para las cuentas registradas mediante un proveedor de OmniAuth (por ejemplo, OAuth, LDAP, SAML), permitiendo a atacantes tomar el control de las cuentas"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=14.9, <14.9.2","status":"affected"},{"version":">=14.8, <14.8.5","status":"affected"},{"version":">=14.7, <14.7.7","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-798"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.7.0","versionEndExcluding":"14.7.7","matchCriteriaId":"17FD611E-ECF1-4A65-BFB2-7339D19B4639"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.7.0","versionEndExcluding":"14.7.7","matchCriteriaId":"55316730-18A2-4B52-B915-1F831EA311F0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.8.0","versionEndExcluding":"14.8.5","matchCriteriaId":"723E51BE-5A83-439E-8D37-EACDC4E5E6B2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.8.0","versionEndExcluding":"14.8.5","matchCriteriaId":"B21DB80A-89B0-4821-AACD-A0DB4102C123"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.2","matchCriteriaId":"50473ACF-87F3-4919-A1C8-1C1D3AED7024"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.2","matchCriteriaId":"84DA7B4F-42A6-4940-98D5-3BF151FD3287"}]}]}],"references":[{"url":"http://packetstormsecurity.com/files/166828/Gitlab-14.9-Authentication-Bypass.html","source":"cve@gitlab.com","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1162.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/357210","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"http://packetstormsecurity.com/files/166828/Gitlab-14.9-Authentication-Bypass.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1162.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/357210","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2022-1174","sourceIdentifier":"cve@gitlab.com","published":"2022-04-04T20:15:09.990","lastModified":"2026-06-17T04:21:57.170","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A potential DoS vulnerability was discovered in Gitlab CE/EE versions 13.7 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 allowed an attacker to trigger high CPU usage via a special crafted input added in Issues, Merge requests, Milestones, Snippets, Wiki pages, etc."},{"lang":"es","value":"Se ha detectado una potencial vulnerabilidad DoS en Gitlab CE/EE versiones 13.7 anteriores a 14.7.7, todas las versiones a partir de 14.8 anteriores a 14.8.5, todas las versiones a partir de 14.9 anteriores a 14.9.2, que permitía a un atacante desencadenar un alto uso de la CPU por medio de una entrada especialmente diseñada añadida en Issues, Merge requests, Milestones, Snippets, Wiki pages, etc"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.7, <14.7.7","status":"affected"},{"version":">=14.8, <14.8.5","status":"affected"},{"version":">=14.9, <14.9.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-1284"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"14.7.7","matchCriteriaId":"A85C2586-2AF7-472C-A5E6-814F79B0C121"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"14.7.7","matchCriteriaId":"DCFDAD24-542B-46BA-AA4F-366BA9887C29"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.8.0","versionEndExcluding":"14.8.5","matchCriteriaId":"723E51BE-5A83-439E-8D37-EACDC4E5E6B2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.8.0","versionEndExcluding":"14.8.5","matchCriteriaId":"B21DB80A-89B0-4821-AACD-A0DB4102C123"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.2","matchCriteriaId":"50473ACF-87F3-4919-A1C8-1C1D3AED7024"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.2","matchCriteriaId":"84DA7B4F-42A6-4940-98D5-3BF151FD3287"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1174.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/338721","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1305431","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1174.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/338721","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1305431","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-1175","sourceIdentifier":"cve@gitlab.com","published":"2022-04-04T20:15:10.040","lastModified":"2026-06-17T04:21:57.290","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Improper neutralization of user input in GitLab CE/EE versions 14.4 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 allowed an attacker to exploit XSS by injecting HTML in notes."},{"lang":"es","value":"Una neutralización inapropiada de la entrada del usuario en GitLab CE/EE versiones 14.4 anteriores a 14.7.7, todas las versiones a partir de 14.8 anteriores a 14.8.5, todas las versiones a partir de 14.9 anteriores a 14.9.2, permitió a un atacante explotar un ataque de tipo XSS mediante una inyección de HTML en las notas"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=14.4, <14.7.7","status":"affected"},{"version":">=14.8, <14.8.5","status":"affected"},{"version":">=14.9, <14.9.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.4.0","versionEndExcluding":"14.7.7","matchCriteriaId":"4CA4FC26-1469-446B-8CC9-A4854B179F23"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.4.0","versionEndExcluding":"14.7.7","matchCriteriaId":"66B63514-0A14-4D94-8579-82D6EC061C6F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.8.0","versionEndExcluding":"14.8.5","matchCriteriaId":"723E51BE-5A83-439E-8D37-EACDC4E5E6B2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.8.0","versionEndExcluding":"14.8.5","matchCriteriaId":"B21DB80A-89B0-4821-AACD-A0DB4102C123"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.2","matchCriteriaId":"50473ACF-87F3-4919-A1C8-1C1D3AED7024"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.2","matchCriteriaId":"84DA7B4F-42A6-4940-98D5-3BF151FD3287"}]}]}],"references":[{"url":"http://packetstormsecurity.com/files/166829/Gitlab-14.9-Cross-Site-Scripting.html","source":"cve@gitlab.com","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1175.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/353370","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1481207","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"http://packetstormsecurity.com/files/166829/Gitlab-14.9-Cross-Site-Scripting.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1175.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/353370","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1481207","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-1185","sourceIdentifier":"cve@gitlab.com","published":"2022-04-04T20:15:10.247","lastModified":"2026-06-17T04:21:58.380","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A denial of service vulnerability when rendering RDoc files in GitLab CE/EE versions 10 to 14.7.7, 14.8.0 to 14.8.5, and 14.9.0 to 14.9.2 allows an attacker to crash the GitLab web application with a maliciously crafted RDoc file"},{"lang":"es","value":"Una vulnerabilidad de denegación de servicio cuando son renderizados archivos RDoc en GitLab CE/EE versiones 10 a 14.7.7, 14.8.0 a 14.8.5 y 14.9.0 a 14.9.2, permite a un atacante bloquear la aplicación web de GitLab con un archivo RDoc maliciosamente diseñado"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=10.0, <14.7.7","status":"affected"},{"version":">=14.8, <14.8.5","status":"affected"},{"version":">=14.9, <14.9.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:N/A:P","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-787"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.0.0","versionEndExcluding":"14.7.7","matchCriteriaId":"CCB5FB76-38AE-4BD4-A134-D2C2053EBF96"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.0.0","versionEndExcluding":"14.7.7","matchCriteriaId":"A273B55D-FC4D-4BF7-AFEC-BDEE52480250"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.8.0","versionEndExcluding":"14.8.5","matchCriteriaId":"723E51BE-5A83-439E-8D37-EACDC4E5E6B2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.8.0","versionEndExcluding":"14.8.5","matchCriteriaId":"B21DB80A-89B0-4821-AACD-A0DB4102C123"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.2","matchCriteriaId":"50473ACF-87F3-4919-A1C8-1C1D3AED7024"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.2","matchCriteriaId":"84DA7B4F-42A6-4940-98D5-3BF151FD3287"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1185.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/349148","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1415071","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1185.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/349148","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1415071","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-1188","sourceIdentifier":"cve@gitlab.com","published":"2022-04-04T20:15:10.300","lastModified":"2026-06-17T04:21:58.720","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.1 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 where a blind SSRF attack through the repository mirroring feature was possible."},{"lang":"es","value":"Se ha detectado un problema en GitLab CE/EE afectando a todas las versiones a partir de la 12.1 anteriores a 14.7.7, a todas las versiones a partir de la 14.8 anteriores a 14.8.5, a todas las versiones a partir de la 14.9 anteriores a 14.9.2, en las que era posible un ataque de tipo SSRF ciego mediante la funcionalidad repository mirroring"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.1, <14.7.7","status":"affected"},{"version":">=14.8, <14.8.5","status":"affected"},{"version":">=14.9, <14.9.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":3.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"14.7.7","matchCriteriaId":"C0129455-6CB0-46B6-A0EF-2BB774AA592A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"14.7.7","matchCriteriaId":"380B038A-8B24-40D7-B087-92443EDCBBBE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.8.0","versionEndExcluding":"14.8.5","matchCriteriaId":"723E51BE-5A83-439E-8D37-EACDC4E5E6B2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.8.0","versionEndExcluding":"14.8.5","matchCriteriaId":"B21DB80A-89B0-4821-AACD-A0DB4102C123"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.2","matchCriteriaId":"50473ACF-87F3-4919-A1C8-1C1D3AED7024"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.2","matchCriteriaId":"84DA7B4F-42A6-4940-98D5-3BF151FD3287"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1188.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/354059","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1486659","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1188.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/354059","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1486659","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-1189","sourceIdentifier":"cve@gitlab.com","published":"2022-04-04T20:15:10.350","lastModified":"2026-06-17T04:21:58.840","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.2 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 that allowed for an unauthorised user to read the the approval rules of a private project."},{"lang":"es","value":"Se ha detectado un problema en GitLab CE/EE afectando a todas las versiones a partir de la 12.2 anteriores a 14.7.7, a todas las versiones a partir de la 14.8 anteriores a 14.8.5, a todas las versiones a partir de la 14.9 anteriores a 14.9.2 que permitía a un usuario no autorizado leer las reglas de aprobación de un proyecto privado"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.2, <14.7.7","status":"affected"},{"version":">=14.8, <14.8.5","status":"affected"},{"version":">=14.9, <14.9.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":3.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"14.7.7","matchCriteriaId":"E772818B-3956-4954-92C6-22D42C7A7A28"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"14.7.7","matchCriteriaId":"08473C81-D7DD-4851-8431-AD98BD4796BE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.8.0","versionEndExcluding":"14.8.5","matchCriteriaId":"723E51BE-5A83-439E-8D37-EACDC4E5E6B2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.8.0","versionEndExcluding":"14.8.5","matchCriteriaId":"B21DB80A-89B0-4821-AACD-A0DB4102C123"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.2","matchCriteriaId":"50473ACF-87F3-4919-A1C8-1C1D3AED7024"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.2","matchCriteriaId":"84DA7B4F-42A6-4940-98D5-3BF151FD3287"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1189.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/353718","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1189.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/353718","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2022-1190","sourceIdentifier":"cve@gitlab.com","published":"2022-04-04T20:15:10.400","lastModified":"2026-06-17T04:21:58.947","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Improper handling of user input in GitLab CE/EE versions 8.3 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an attacker to exploit a stored XSS by abusing multi-word milestone references in issue descriptions, comments, etc."},{"lang":"es","value":"Un manejo inapropiado de la entrada del usuario en GitLab CE/EE versiones 8.3 anteriores a 14.7.7, 14.8 anteriores a 14.8.5 y 14.9 anteriores a 14.9.2, permitía a un atacante explotar un ataque de tipo XSS almacenado al abusar de las referencias de hitos de varias palabras en las descripciones de incidencias, comentarios, etc"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=8.3.0, <14.7.7","status":"affected"},{"version":">=14.8.0, <14.8.5","status":"affected"},{"version":">=14.9.0, <14.9.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.3.0","versionEndExcluding":"14.7.7","matchCriteriaId":"9CFB6049-4DF1-4325-A9FF-BF2EE9967980"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.3.0","versionEndExcluding":"14.7.7","matchCriteriaId":"9F28AB38-47F6-43BE-AF34-12220F0F34E7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.8.0","versionEndExcluding":"14.8.5","matchCriteriaId":"723E51BE-5A83-439E-8D37-EACDC4E5E6B2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.8.0","versionEndExcluding":"14.8.5","matchCriteriaId":"B21DB80A-89B0-4821-AACD-A0DB4102C123"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.2","matchCriteriaId":"50473ACF-87F3-4919-A1C8-1C1D3AED7024"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.2","matchCriteriaId":"84DA7B4F-42A6-4940-98D5-3BF151FD3287"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1190.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/352392","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1455036","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1190.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/352392","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1455036","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-1157","sourceIdentifier":"cve@gitlab.com","published":"2022-04-11T20:15:17.397","lastModified":"2026-06-17T04:21:55.230","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Missing sanitization of logged exception messages in all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 of GitLab CE/EE causes potential sensitive values in invalid URLs to be logged"},{"lang":"es","value":"Una falta de saneo de los mensajes de excepción registrados en todas las versiones anteriores a 14.7.7, 14.8 anteriores a 14.8.5 y 14.9 anteriores a 14.9.2 de GitLab CE/EE causa el registro de posibles valores confidenciales en URLs no válidas"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":"<14.7.7","status":"affected"},{"version":">=14.8, <14.8.5","status":"affected"},{"version":">=14.9, <14.9.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:L/I:N/A:N","baseScore":2.6,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.0,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N","baseScore":2.4,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":0.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:P/I:N/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-532"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"14.7.7","matchCriteriaId":"8974DCCE-04EB-4C60-804B-DB14AF98097B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"14.7.7","matchCriteriaId":"235F4C2C-2274-43A8-9513-4F598ED9CF06"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.8.0","versionEndExcluding":"14.8.5","matchCriteriaId":"723E51BE-5A83-439E-8D37-EACDC4E5E6B2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.8.0","versionEndExcluding":"14.8.5","matchCriteriaId":"B21DB80A-89B0-4821-AACD-A0DB4102C123"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.2","matchCriteriaId":"50473ACF-87F3-4919-A1C8-1C1D3AED7024"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.2","matchCriteriaId":"84DA7B4F-42A6-4940-98D5-3BF151FD3287"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1157.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/37261","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1157.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/37261","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2022-1193","sourceIdentifier":"cve@gitlab.com","published":"2022-04-11T20:15:18.093","lastModified":"2026-06-17T04:21:59.260","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Improper access control in GitLab CE/EE versions 10.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows a malicious actor to obtain details of the latest commit in a private project via Merge Requests under certain circumstances"},{"lang":"es","value":"Un control de acceso inadecuado en las versiones 10.7 anterior a 14.7.7, 14.8 anterior a 14.8.5 y 14.9 anterior a 14.9.2 de GitLab CE/EE permite a un actor malintencionado obtener detalles del último commit de un proyecto privado a través de Merge Requests en determinadas circunstancias"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=10.7, <14.7.7","status":"affected"},{"version":">=14.8, <14.8.5","status":"affected"},{"version":">=14.9, <14.9.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:P/I:N/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.7.0","versionEndExcluding":"14.7.7","matchCriteriaId":"E89DD5F0-40D2-4C08-AC7F-363E169EAB62"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.7.0","versionEndExcluding":"14.7.7","matchCriteriaId":"0E906D39-AE87-4823-A54E-ACA8211742CC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.8.0","versionEndExcluding":"14.8.5","matchCriteriaId":"723E51BE-5A83-439E-8D37-EACDC4E5E6B2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.8.0","versionEndExcluding":"14.8.5","matchCriteriaId":"B21DB80A-89B0-4821-AACD-A0DB4102C123"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.2","matchCriteriaId":"50473ACF-87F3-4919-A1C8-1C1D3AED7024"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.2","matchCriteriaId":"84DA7B4F-42A6-4940-98D5-3BF151FD3287"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1193.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/351823","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking","Third Party Advisory"]},{"url":"https://hackerone.com/reports/1465994","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1193.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/351823","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Third Party Advisory"]},{"url":"https://hackerone.com/reports/1465994","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-0477","sourceIdentifier":"cve@gitlab.com","published":"2022-04-25T17:15:36.467","lastModified":"2026-06-17T04:20:41.480","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 11.9 before 14.5.4, all versions starting from 14.6.0 before 14.6.4, all versions starting from 14.7.0 before 14.7.1. GitLab was not correctly handling bulk requests to delete existing packages from the package registries which could result in a Denial of Service under specific conditions."},{"lang":"es","value":"Se ha detectado un problema en GitLab que afecta a todas las versiones a partir de la 11.9 anteriores a 14.5.4, todas las versiones a partir de la 14.6.0 anteriores a 14.6.4, todas las versiones a partir de la 14.7.0 anteriores a 14.7.1. GitLab no manejaba correctamente las peticiones masivas para eliminar paquetes existentes de los registros de paquetes, lo que podía resultar en una Denegación de Servicio en determinadas condiciones"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=11.9, <14.5.4","status":"affected"},{"version":">=14.6.0, <14.6.4","status":"affected"},{"version":">=14.7.0, <14.7.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":1.2,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":1.2,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:N/A:P","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"11.9","versionEndExcluding":"14.5.4","matchCriteriaId":"90B6EDEA-0494-44F8-8CE1-2F0B083ED183"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"14.6.0","versionEndExcluding":"14.6.4","matchCriteriaId":"37DBCA07-F134-490A-A96A-699B057B7669"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.7.0:*:*:*:*:*:*:*","matchCriteriaId":"877C0EA4-E5C3-4A35-87DE-E642A53B48DB"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0477.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/348166","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0477.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/348166","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2022-1417","sourceIdentifier":"cve@gitlab.com","published":"2022-05-10T21:15:08.870","lastModified":"2026-06-17T04:22:24.967","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Improper access control in GitLab CE/EE affecting all versions starting from 8.12 before 14.8.6, all versions starting from 14.9 before 14.9.4, and all versions starting from 14.10 before 14.10.1 allows non-project members to access contents of Project Members-only Wikis via malicious CI jobs"},{"lang":"es","value":"Un control de acceso inadecuado en GitLab CE/EE que afecta a todas las versiones a partir de la 8.12 antes de la 14.8.6, a todas las versiones a partir de la 14.9 antes de la 14.9.4, y a todas las versiones a partir de la 14.10 antes de la 14.10.1 permite que personas que no son miembros del proyecto accedan al contenido de los wikis exclusivos para miembros del proyecto a través de trabajos de CI maliciosos"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=8.12, <14.8.6","status":"affected"},{"version":">=14.9, <14.9.4","status":"affected"},{"version":">=14.10, <14.10.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.12.0","versionEndExcluding":"14.8.6","matchCriteriaId":"2D5984FA-0E42-47F2-9CE6-A23697AD66DB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.12.0","versionEndExcluding":"14.8.6","matchCriteriaId":"58F524A4-73BA-4240-A14D-2086F5E0D432"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.4","matchCriteriaId":"BCD83B23-0868-4545-9E4E-98F0DF151924"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.4","matchCriteriaId":"2B4C393E-6B88-4AF8-9071-2C43935A1AEC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.10.0:*:*:*:community:*:*:*","matchCriteriaId":"41411D82-66AE-4AE4-9093-D019F80ED990"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.10.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"9643D908-345C-48F9-BEDE-08F69EC16931"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1417.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/297282","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1075586","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1417.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/297282","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1075586","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-1431","sourceIdentifier":"cve@gitlab.com","published":"2022-05-10T21:15:08.937","lastModified":"2026-06-17T04:22:26.457","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 12.10 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not correctly handling malicious requests to the PyPi API endpoint allowing the attacker to cause uncontrolled resource consumption."},{"lang":"es","value":"Se ha detectado un problema en GitLab que afecta a todas las versiones a partir de 12.10 anteriores a 14.8.6, todas las versiones a partir de 14.9 anteriores a 14.9.4, todas las versiones a partir de 14.10 antes de 14.10.1. GitLab no manejaba correctamente las peticiones maliciosas al endpoint de la API de PyPi, lo que permitía al atacante causar un consumo no controlado de recursos"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.10, <14.8.6","status":"affected"},{"version":">=14.9, <14.9.4","status":"affected"},{"version":">=14.10, <14.10.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-20"},{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.10.0","versionEndExcluding":"14.8.6","matchCriteriaId":"5EAF6CC8-9914-4311-8504-788ADBE2D840"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.10.0","versionEndExcluding":"14.8.6","matchCriteriaId":"DCF271C9-0713-4D76-AF05-AC786E9265D2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.4","matchCriteriaId":"BCD83B23-0868-4545-9E4E-98F0DF151924"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.4","matchCriteriaId":"2B4C393E-6B88-4AF8-9071-2C43935A1AEC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.10.0:*:*:*:community:*:*:*","matchCriteriaId":"41411D82-66AE-4AE4-9093-D019F80ED990"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.10.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"9643D908-345C-48F9-BEDE-08F69EC16931"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1431.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/262724","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/996850","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1431.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/262724","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/996850","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-1124","sourceIdentifier":"cve@gitlab.com","published":"2022-05-11T15:15:08.713","lastModified":"2026-06-17T04:21:52.477","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An improper authorization issue has been discovered in GitLab CE/EE affecting all versions prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0, allowing Guest project members to access trace log of jobs when it is enabled"},{"lang":"es","value":"Se ha detectado un problema de autorización incorrecta en GitLab CE/EE afectando a todas las versiones anteriores a 14.8.6, todas las versiones de la 14.9.0 anteriores a 14.9.4 y 14.10.0, y que permite a miembros del proyecto invitados acceder al registro de seguimiento de trabajos cuando está habilitado"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":"<14.8.6","status":"affected"},{"version":">=14.9.0, <14.9.4","status":"affected"},{"version":">=14.10.0, <14.10.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:P/I:N/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"14.8.6","matchCriteriaId":"F6BEDF75-ACB0-4243-BDB8-B855CC160CB1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"14.8.6","matchCriteriaId":"F3780334-BD2E-44EE-83BE-144B45F8F722"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.4","matchCriteriaId":"BCD83B23-0868-4545-9E4E-98F0DF151924"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.4","matchCriteriaId":"2B4C393E-6B88-4AF8-9071-2C43935A1AEC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.10.0:*:*:*:community:*:*:*","matchCriteriaId":"41411D82-66AE-4AE4-9093-D019F80ED990"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.10.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"9643D908-345C-48F9-BEDE-08F69EC16931"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1124.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/323552","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1113405","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1124.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/323552","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1113405","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-1352","sourceIdentifier":"cve@gitlab.com","published":"2022-05-11T15:15:08.793","lastModified":"2026-06-17T04:22:16.377","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Due to an insecure direct object reference vulnerability in Gitlab EE/CE affecting all versions from 11.0 prior to 14.8.6, 14.9 prior to 14.9.4, and 14.10 prior to 14.10.1, an endpoint may reveal the issue title to a user who crafted an API call with the ID of the issue from a public project that restricts access to issue only to project members."},{"lang":"es","value":"Debido a una vulnerabilidad de referencia directa a objetos insegura en Gitlab EE/CE afectando a todas las versiones desde 11.0 anteriores a 14.8.6, 14.9 anteriores a 14.9.4 y 14.10 anteriores a 14.10.1, un endpoint puede revelar el título de la incidencia a un usuario que haya diseñado una llamada a la API con el ID de la incidencia desde un proyecto público que restringe el acceso a la incidencia sólo a miembros del proyecto"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=11.0, <14.8.6","status":"affected"},{"version":">=14.9, <14.9.4","status":"affected"},{"version":">=14.10, <14.10.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-639"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"14.8.6","matchCriteriaId":"B1D1FAF9-C10B-4D76-B219-C14FFF4E55E2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"14.8.6","matchCriteriaId":"B998EBA3-C672-42DF-B04B-44D6016FA878"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.4","matchCriteriaId":"BCD83B23-0868-4545-9E4E-98F0DF151924"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.4","matchCriteriaId":"2B4C393E-6B88-4AF8-9071-2C43935A1AEC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.10.0:*:*:*:community:*:*:*","matchCriteriaId":"41411D82-66AE-4AE4-9093-D019F80ED990"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.10.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"9643D908-345C-48F9-BEDE-08F69EC16931"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1352.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/350691","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1450306","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1352.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/350691","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1450306","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-1406","sourceIdentifier":"cve@gitlab.com","published":"2022-05-11T15:15:08.847","lastModified":"2026-06-17T04:22:23.687","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Improper input validation in GitLab CE/EE affecting all versions from 8.12 prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0 allows a Developer to read protected Group or Project CI/CD variables by importing a malicious project"},{"lang":"es","value":"Una comprobación de entrada inapropiada en GitLab CE/EE afectando a todas las versiones desde la 8.12 anteriores a 14.8.6, todas las versiones desde la 14.9.0 anteriores a 14.9.4 y 14.10.0, permite a un desarrollador leer variables de CI/CD protegidas de grupos o proyectos al importar un proyecto malicioso"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=14.10.0, <14.10.1","status":"affected"},{"version":">=14.9.0, <14.9.4","status":"affected"},{"version":">=8.12.0, <14.8.6","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-20"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.12.0","versionEndExcluding":"14.8.6","matchCriteriaId":"2D5984FA-0E42-47F2-9CE6-A23697AD66DB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.12.0","versionEndExcluding":"14.8.6","matchCriteriaId":"58F524A4-73BA-4240-A14D-2086F5E0D432"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.4","matchCriteriaId":"BCD83B23-0868-4545-9E4E-98F0DF151924"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.4","matchCriteriaId":"2B4C393E-6B88-4AF8-9071-2C43935A1AEC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.10.0:*:*:*:community:*:*:*","matchCriteriaId":"41411D82-66AE-4AE4-9093-D019F80ED990"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.10.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"9643D908-345C-48F9-BEDE-08F69EC16931"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1406.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/353958","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1485381","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1406.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/353958","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1485381","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-1426","sourceIdentifier":"cve@gitlab.com","published":"2022-05-11T15:15:08.907","lastModified":"2026-06-17T04:22:25.913","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 12.6 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not correctly authenticating a user that had some certain amount of information which allowed an user to authenticate without a personal access token."},{"lang":"es","value":"Se ha detectado un problema en GitLab afectando a todas las versiones a partir de la 12.6 anteriores a 14.8.6, todas las versiones a partir de la 14.9 anteriores a 14.9.4, todas las versiones a partir de la 14.10 anteriores a 14.10.1. GitLab no autenticaba correctamente a un usuario que tenía determinada información que le permitía autenticarse sin un token de acceso personal"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.6, <14.8.6","status":"affected"},{"version":">=14.9, <14.9.4","status":"affected"},{"version":">=14.10, <14.10.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N","baseScore":2.0,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":0.5,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":3.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-287"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.6.0","versionEndExcluding":"14.8.6","matchCriteriaId":"E5F7F0C4-B688-4175-9177-493DA89E4F8B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.6.0","versionEndExcluding":"14.8.6","matchCriteriaId":"CC39EE3A-855E-490C-BDB8-40479B024AE5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.4","matchCriteriaId":"BCD83B23-0868-4545-9E4E-98F0DF151924"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.4","matchCriteriaId":"2B4C393E-6B88-4AF8-9071-2C43935A1AEC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.10.0:*:*:*:community:*:*:*","matchCriteriaId":"41411D82-66AE-4AE4-9093-D019F80ED990"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.10.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"9643D908-345C-48F9-BEDE-08F69EC16931"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1426.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/296866","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1070097","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1426.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/296866","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1070097","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-1428","sourceIdentifier":"cve@gitlab.com","published":"2022-05-11T15:15:08.960","lastModified":"2026-06-17T04:22:26.140","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was incorrectly verifying throttling limits for authenticated package requests which resulted in limits not being enforced."},{"lang":"es","value":"Se ha detectado un problema en GitLab afectando a todas las versiones anteriores a 14.8.6, a todas las versiones a partir de la 14.9 anteriores a 14.9.4 y todas las versiones a partir de la 14.10 anteriores a 14.10.1. GitLab estaba verificando incorrectamente los límites de estrangulamiento para las peticiones de paquetes autenticados, lo que provocaba que los límites no se aplicaran"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":"<14.8.6","status":"affected"},{"version":">=14.9, <14.9.4","status":"affected"},{"version":">=14.10, <14.10.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:N/A:P","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"14.8.6","matchCriteriaId":"F6BEDF75-ACB0-4243-BDB8-B855CC160CB1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"14.8.6","matchCriteriaId":"F3780334-BD2E-44EE-83BE-144B45F8F722"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.4","matchCriteriaId":"BCD83B23-0868-4545-9E4E-98F0DF151924"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.4","matchCriteriaId":"2B4C393E-6B88-4AF8-9071-2C43935A1AEC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.10.0:*:*:*:community:*:*:*","matchCriteriaId":"41411D82-66AE-4AE4-9093-D019F80ED990"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.10.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"9643D908-345C-48F9-BEDE-08F69EC16931"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1428.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/342481","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1428.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/342481","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2022-1433","sourceIdentifier":"cve@gitlab.com","published":"2022-05-11T15:15:09.013","lastModified":"2026-06-17T04:22:26.677","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 14.4 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. Missing invalidation of Markdown caching causes potential payloads from a previously exploitable XSS vulnerability (CVE-2022-1175) to persist and execute."},{"lang":"es","value":"Se ha detectado un problema en GitLab afectando a todas las versiones a partir de la 14.4 anteriores a 14.8.6, todas las versiones a partir de la 14.9 anteriores a 14.9.4, todas las versiones a partir de la 14.10 anteriores a 14.10.1. Una falta de no comprobación del almacenamiento en caché de Markdown causa que persistan y sean ejecutadas cargas útiles potenciales de una vulnerabilidad de tipo XSS explotable previamente. (CVE-2022-1175)"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=14.4, <14.8.6","status":"affected"},{"version":">=14.9, <14.9.4","status":"affected"},{"version":">=14.10, <14.10.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N","baseScore":2.6,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.4.0","versionEndExcluding":"14.8.6","matchCriteriaId":"465C36BD-4DBD-4086-80FF-7094437A4C84"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.4.0","versionEndExcluding":"14.8.6","matchCriteriaId":"A6FB3304-CCBC-49CE-BD81-0AD8951A01C5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.4","matchCriteriaId":"BCD83B23-0868-4545-9E4E-98F0DF151924"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.4","matchCriteriaId":"2B4C393E-6B88-4AF8-9071-2C43935A1AEC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.10.0:*:*:*:community:*:*:*","matchCriteriaId":"41411D82-66AE-4AE4-9093-D019F80ED990"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.10.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"9643D908-345C-48F9-BEDE-08F69EC16931"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1433.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/357930","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1528829","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1433.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/357930","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1528829","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-1460","sourceIdentifier":"cve@gitlab.com","published":"2022-05-11T15:15:09.067","lastModified":"2026-06-17T04:22:29.527","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 9.2 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not performing correct authorizations on scheduled pipelines allowing a malicious user to run a pipeline in the context of another user."},{"lang":"es","value":"Se ha detectado un problema en GitLab afectando a todas las versiones a partir de la 9.2 anteriores a 14.8.6, todas las versiones a partir de la 14.9 anteriores a 14.9.4, todas las versiones a partir de la 14.10 anteriores a 14.10.1. GitLab no llevaba a cabo las autorizaciones correctas en los pipelines programados, lo que permitía a un usuario malicioso ejecutar un pipeline en el contexto de otro usuario"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=9.2, <14.8.6","status":"affected"},{"version":">=14.9, <14.9.4","status":"affected"},{"version":">=14.10, <14.10.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":0.9,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"9.2.0","versionEndExcluding":"14.8.6","matchCriteriaId":"6FCB3554-2BE3-4B94-B34E-55D18F8CF19D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"9.2.0","versionEndExcluding":"14.8.6","matchCriteriaId":"95250D83-5A96-4B3A-BFC2-FE847802CD3D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.4","matchCriteriaId":"BCD83B23-0868-4545-9E4E-98F0DF151924"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.4","matchCriteriaId":"2B4C393E-6B88-4AF8-9071-2C43935A1AEC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.10.0:*:*:*:community:*:*:*","matchCriteriaId":"41411D82-66AE-4AE4-9093-D019F80ED990"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.10.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"9643D908-345C-48F9-BEDE-08F69EC16931"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1460.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/118782","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/755078","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1460.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/118782","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/755078","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-1510","sourceIdentifier":"cve@gitlab.com","published":"2022-05-11T15:15:09.120","lastModified":"2026-06-17T04:22:35.043","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 13.9 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not correctly handling malicious text in the CI Editor and CI Pipeline details page allowing the attacker to cause uncontrolled resource consumption."},{"lang":"es","value":"Se ha detectado un problema en GitLab afectando a todas las versiones a partir de la 13.9 anteriores a 14.8.6, a todas las versiones a partir de la 14.9 anteriores a 14.9.4 y a todas las versiones a partir de la 14.10 anteriores a 14.10.1. GitLab no manejaba correctamente el texto malicioso en la página de detalles del editor de CI y de la tubería de CI, permitiendo al atacante causar un consumo no controlado de recursos"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.9, <14.8.6","status":"affected"},{"version":">=14.9, <14.9.4","status":"affected"},{"version":">=14.10, <14.10.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-1333"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.9.0","versionEndExcluding":"14.8.6","matchCriteriaId":"CFA25184-CDA9-49B0-AB37-F4149A6C5BA1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.9.0","versionEndExcluding":"14.8.6","matchCriteriaId":"D2C5CECD-F03B-484A-87CC-B47B630DE815"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.4","matchCriteriaId":"BCD83B23-0868-4545-9E4E-98F0DF151924"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.4","matchCriteriaId":"2B4C393E-6B88-4AF8-9071-2C43935A1AEC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.10.0:*:*:*:community:*:*:*","matchCriteriaId":"41411D82-66AE-4AE4-9093-D019F80ED990"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.10.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"9643D908-345C-48F9-BEDE-08F69EC16931"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1510.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/343276","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1353058","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1510.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/343276","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1353058","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-1545","sourceIdentifier":"cve@gitlab.com","published":"2022-05-11T15:15:09.180","lastModified":"2026-06-17T04:22:38.990","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"It was possible to disclose details of confidential notes created via the API in Gitlab CE/EE affecting all versions from 13.2 prior to 14.8.6, 14.9 prior to 14.9.4, and 14.10 prior to 14.10.1 if an unauthorised project member was tagged in the note."},{"lang":"es","value":"Era posible divulgar detalles de notas confidenciales creadas por medio de la API en Gitlab CE/EE, afectando a todas las versiones desde la 13.2 hasta la 14.8.6, 14.9 anteriores a 14.9.4 y 14.10 anteriores a 14.10.1, si un miembro del proyecto no autorizado era etiquetado en la nota"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.2, <14.8.6","status":"affected"},{"version":">=14.9, <14.9.4","status":"affected"},{"version":">=14.10, <14.10.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"14.8.6","matchCriteriaId":"9BE2CE33-FF2B-4655-99F0-45F8E85F6C88"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"14.8.6","matchCriteriaId":"A145FE4C-CEB0-4A95-94C8-612F6763D5F9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.4","matchCriteriaId":"BCD83B23-0868-4545-9E4E-98F0DF151924"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.4","matchCriteriaId":"2B4C393E-6B88-4AF8-9071-2C43935A1AEC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.10.0:*:*:*:community:*:*:*","matchCriteriaId":"41411D82-66AE-4AE4-9093-D019F80ED990"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.10.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"9643D908-345C-48F9-BEDE-08F69EC16931"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1545.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/351030","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1545.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/351030","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2022-1413","sourceIdentifier":"cve@gitlab.com","published":"2022-05-19T18:15:09.430","lastModified":"2026-06-17T04:22:24.427","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Missing input masking in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 causes potentially sensitive integration properties to be disclosed in the web interface"},{"lang":"es","value":"Una falta de enmascaramiento de entradas en GitLab CE/EE, afectando a todas las versiones a partir de la 1.0.2 anteriores a 14.8.6, todas las versiones a partir de la 14.9.0 anteriores a 14.9.4 y todas las versiones a partir de la 14.10.0 anteriores a 14.10.1, causa una divulgación de propiedades de integración potencialmente confidenciales en la interfaz web"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=1.0.2, <14.8.6","status":"affected"},{"version":">=14.9.0, <14.9.4","status":"affected"},{"version":">=14.10.0, <14.10.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:N/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.0,"impactScore":4.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-522"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"1.0.2","versionEndExcluding":"14.8.6","matchCriteriaId":"691B1EF3-6066-456D-8477-A0BC9568AD59"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"1.0.2","versionEndExcluding":"14.8.6","matchCriteriaId":"DEF3BA64-879C-4B12-A961-F220A7FCECCE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.4","matchCriteriaId":"BCD83B23-0868-4545-9E4E-98F0DF151924"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.4","matchCriteriaId":"2B4C393E-6B88-4AF8-9071-2C43935A1AEC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.10.0:*:*:*:community:*:*:*","matchCriteriaId":"41411D82-66AE-4AE4-9093-D019F80ED990"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.10.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"9643D908-345C-48F9-BEDE-08F69EC16931"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1413.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/353720","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1413.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/353720","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2022-1416","sourceIdentifier":"cve@gitlab.com","published":"2022-05-19T18:15:09.480","lastModified":"2026-06-17T04:22:24.853","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Missing sanitization of data in Pipeline error messages in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 allows for rendering of attacker controlled HTML tags and CSS styling"},{"lang":"es","value":"Una falta de saneo de datos en los mensajes de error de Pipeline en GitLab CE/EE, afectando a todas las versiones a partir de la 1.0.2 anteriores a 14.8.6, todas las versiones a partir de la 14.9.0 anteriores a 14.9.4 y todas las versiones a partir de la 14.10.0 anteriores a 14.10.1, permite una representación de etiquetas HTML y estilos CSS controlados por el atacante"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=1.0.2, <14.8.6","status":"affected"},{"version":">=14.9.0, <14.9.4","status":"affected"},{"version":">=14.10.0, <14.10.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"1.0.2","versionEndExcluding":"14.8.6","matchCriteriaId":"691B1EF3-6066-456D-8477-A0BC9568AD59"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"1.0.2","versionEndExcluding":"14.8.6","matchCriteriaId":"DEF3BA64-879C-4B12-A961-F220A7FCECCE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.4","matchCriteriaId":"BCD83B23-0868-4545-9E4E-98F0DF151924"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.4","matchCriteriaId":"2B4C393E-6B88-4AF8-9071-2C43935A1AEC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.10.0:*:*:*:community:*:*:*","matchCriteriaId":"41411D82-66AE-4AE4-9093-D019F80ED990"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.10.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"9643D908-345C-48F9-BEDE-08F69EC16931"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1416.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/342988","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking","Technical Description","Third Party Advisory"]},{"url":"https://hackerone.com/reports/1362405","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1416.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/342988","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Technical Description","Third Party Advisory"]},{"url":"https://hackerone.com/reports/1362405","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-1423","sourceIdentifier":"cve@gitlab.com","published":"2022-05-19T18:15:09.530","lastModified":"2026-06-17T04:22:25.600","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Improper access control in the CI/CD cache mechanism in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 allows a malicious actor with Developer privileges to perform cache poisoning leading to arbitrary code execution in protected branches"},{"lang":"es","value":"Un control de acceso inapropiado en el mecanismo de caché CI/CD en GitLab CE/EE afectando a todas las versiones a partir de la 1.0.2 anteriores a 14.8.6, todas las versiones a partir de la 14.9.0 anteriores a 14.9.4 y todas las versiones a partir de la 14.10.0 anteriores a 14.10.1, permite a un actor malicioso con privilegios de desarrollador llevar a cabo un envenenamiento de la caché conllevando a una ejecución de código arbitrario en ramas protegidas"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=1.0.2, <14.8.6","status":"affected"},{"version":">=14.9.0, <14.9.4","status":"affected"},{"version":">=14.10.0, <14.10.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.8,"impactScore":4.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"1.0.2","versionEndExcluding":"14.8.6","matchCriteriaId":"691B1EF3-6066-456D-8477-A0BC9568AD59"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"1.0.2","versionEndExcluding":"14.8.6","matchCriteriaId":"DEF3BA64-879C-4B12-A961-F220A7FCECCE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.4","matchCriteriaId":"BCD83B23-0868-4545-9E4E-98F0DF151924"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"14.9.4","matchCriteriaId":"2B4C393E-6B88-4AF8-9071-2C43935A1AEC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.10.0:*:*:*:community:*:*:*","matchCriteriaId":"41411D82-66AE-4AE4-9093-D019F80ED990"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:14.10.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"9643D908-345C-48F9-BEDE-08F69EC16931"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1423.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/330047","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1182375","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1423.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/330047","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1182375","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-1783","sourceIdentifier":"cve@gitlab.com","published":"2022-06-06T17:15:10.543","lastModified":"2026-06-17T04:23:06.300","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.3 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1. It may be possible for malicious group maintainers to add new members to a project within their group, through the REST API, even after their group owner enabled a setting to prevent members from being added to projects within that group."},{"lang":"es","value":"Se ha detectado un problema en GitLab CE/EE afectando a todas las versiones a partir de 14.3 anteriores a 14.9.5, todas las versiones a partir de 14.10 anteriores a 14.10.4, todas las versiones a partir de 15.0 anteriores a 15.0.1. Es posible a mantenedores de grupos maliciosos añadir nuevos miembros a un proyecto dentro de su grupo, mediante la API REST, incluso después de que el propietario de su grupo haya habilitado una configuración para evitar que se añadan miembros a los proyectos dentro de ese grupo"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=15.0.0, <15.0.1","status":"affected"},{"version":">=14.10.0, <14.10.4","status":"affected"},{"version":">=14.3, <14.9.5","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N","baseScore":2.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N","baseScore":2.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.3.0","versionEndExcluding":"14.9.5","matchCriteriaId":"51B378B5-906F-4CE2-9C91-53F9F9F5DAD3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.3.0","versionEndExcluding":"14.9.5","matchCriteriaId":"2B8B95B6-6915-4DF1-ADBE-707119C9968F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.10.0","versionEndExcluding":"14.10.4","matchCriteriaId":"5E69F4A1-5B3A-4FF5-95EC-62DCEB7DCE5F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.10.0","versionEndExcluding":"14.10.4","matchCriteriaId":"4E6B5E02-4670-4E74-A3EA-DF81659861E1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.0.0:*:*:*:community:*:*:*","matchCriteriaId":"00FDE831-EC28-4124-AC9F-A1C089D5BBFA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"E8953D9B-56DF-4AA2-BFDC-B28CF4F31CB5"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1783.json","source":"cve@gitlab.com","tags":["Patch","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/353121","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1472109","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1783.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/353121","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1472109","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2022-1821","sourceIdentifier":"cve@gitlab.com","published":"2022-06-06T17:15:10.610","lastModified":"2026-06-17T04:23:10.540","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.8 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1. It may be possible for a subgroup member to access the members list of their parent group."},{"lang":"es","value":"Se ha detectado un problema en GitLab CE/EE afectando todas las versiones a partir de 10.8 anteriores a 14.9.5, todas las versiones a partir de la 14.10 anteriores a 14.10.4, todas las versiones a partir de la 15.0 anteriores a 15.0.1. Es posible que un miembro de un subgrupo pueda acceder a la lista de miembros de su grupo padre"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=15.0.0, <15.0.1","status":"affected"},{"version":">=14.10.0, <14.10.4","status":"affected"},{"version":">=10.8, <14.9.5","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.8.0","versionEndExcluding":"14.9.5","matchCriteriaId":"90E0ACB3-7C7B-4544-BA1C-7CA720D39F03"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.8.0","versionEndExcluding":"14.9.5","matchCriteriaId":"31D8ECD8-4123-406D-8A57-C64B2568D0F0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.10.0","versionEndExcluding":"14.10.4","matchCriteriaId":"5E69F4A1-5B3A-4FF5-95EC-62DCEB7DCE5F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.10.0","versionEndExcluding":"14.10.4","matchCriteriaId":"4E6B5E02-4670-4E74-A3EA-DF81659861E1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.0.0:*:*:*:community:*:*:*","matchCriteriaId":"00FDE831-EC28-4124-AC9F-A1C089D5BBFA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"E8953D9B-56DF-4AA2-BFDC-B28CF4F31CB5"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1821.json","source":"cve@gitlab.com","tags":["Exploit","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/353730","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1821.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/353730","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2022-1935","sourceIdentifier":"cve@gitlab.com","published":"2022-06-06T17:15:10.673","lastModified":"2026-06-17T04:23:23.013","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1 allowed an attacker already in possession of a valid Project Trigger Token to misuse it from any location even when IP address restrictions were configured"},{"lang":"es","value":"Una autorización incorrecta en GitLab EE afectando todas las versiones a partir de 12.0 anteriores a 14.9.5, todas las versiones a partir de la 14.10 anteriores a 14.10.4, todas las versiones a partir de la 15.0 anteriores a 15.0.1, permitía a un atacante que ya estuviera en posesión de un Token de Despliegue de Proyecto válido hacer un uso no debido del mismo desde cualquier ubicación incluso cuando se hubieran configurado restricciones de dirección IP"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=15.0.0, <15.0.1","status":"affected"},{"version":">=14.10.0, <14.10.4","status":"affected"},{"version":">=12.0.0, <14.9.5","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.0.0","versionEndExcluding":"14.9.5","matchCriteriaId":"8032FDD5-A274-48C6-A528-F99CCA42338C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.10.0","versionEndExcluding":"14.10.4","matchCriteriaId":"4E6B5E02-4670-4E74-A3EA-DF81659861E1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"E8953D9B-56DF-4AA2-BFDC-B28CF4F31CB5"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1935.json","source":"cve@gitlab.com","tags":["Patch","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/363650","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1935.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/363650","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2022-1936","sourceIdentifier":"cve@gitlab.com","published":"2022-06-06T17:15:10.737","lastModified":"2026-06-17T04:23:23.120","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1 allowed an attacker already in possession of a valid Project Deploy Token to misuse it from any location even when IP address restrictions were configured"},{"lang":"es","value":"Una autorización incorrecta en GitLab EE, afectando todas las versiones a partir de 12.0 anteriores a 14.9.5, todas las versiones a partir de 14.10 anteriores a 14.10.4 y todas las versiones a partir de 15.0 anteriores a 15.0.1, permitía que un atacante que ya estuviera en posesión de un token de despliegue de proyecto válido lo usara inapropiadamente desde cualquier ubicación, incluso cuando hubieran sido configuradas restricciones de dirección IP"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=15.0.0, <15.0.1","status":"affected"},{"version":">=14.10.0, <14.10.4","status":"affected"},{"version":">=12.0.0, <14.9.5","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.0.0","versionEndExcluding":"14.9.5","matchCriteriaId":"8032FDD5-A274-48C6-A528-F99CCA42338C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.10.0","versionEndExcluding":"14.10.4","matchCriteriaId":"4E6B5E02-4670-4E74-A3EA-DF81659861E1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"E8953D9B-56DF-4AA2-BFDC-B28CF4F31CB5"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1936.json","source":"cve@gitlab.com","tags":["Patch","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/363638","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1936.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/363638","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2022-1940","sourceIdentifier":"cve@gitlab.com","published":"2022-06-06T17:15:10.803","lastModified":"2026-06-17T04:23:23.520","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A Stored Cross-Site Scripting vulnerability in Jira integration in GitLab EE affecting all versions from 13.11 prior to 14.9.5, 14.10 prior to 14.10.4, and 15.0 prior to 15.0.1 allows an attacker to execute arbitrary JavaScript code in GitLab on a victim's behalf via specially crafted Jira Issues"},{"lang":"es","value":"Una vulnerabilidad de tipo almacenado en la integración de Jira en GitLab EE afectando a todas las versiones desde la 13.11 anteriores a 14.9.5, 14.10 anteriores a 14.10.4 y 15.0 anteriores a 15.0.1, permite a un atacante ejecutar código JavaScript arbitrario en GitLab en nombre de la víctima por medio de ediciones de Jira especialmente diseñadas"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.11, <14.9.5","status":"affected"},{"version":">=14.10, <14.10.4","status":"affected"},{"version":">=15.0, <15.0.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":7.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.3,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.11.0","versionEndExcluding":"14.9.5","matchCriteriaId":"B5D8AC23-4760-4977-AE95-A8D879520110"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.10.0","versionEndExcluding":"14.10.4","matchCriteriaId":"4E6B5E02-4670-4E74-A3EA-DF81659861E1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"E8953D9B-56DF-4AA2-BFDC-B28CF4F31CB5"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1940.json","source":"cve@gitlab.com","tags":["Patch","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/359142","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1533976","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1940.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/359142","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1533976","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2022-1944","sourceIdentifier":"cve@gitlab.com","published":"2022-06-06T17:15:10.867","lastModified":"2026-06-17T04:23:24.043","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"When the feature is configured, improper authorization in the Interactive Web Terminal in GitLab CE/EE affecting all versions from 11.3 prior to 14.9.5, 14.10 prior to 14.10.4, and 15.0 prior to 15.0.1 allows users with the Developer role to open terminals on other Developers' running jobs"},{"lang":"es","value":"Cuando la función está configurada, una autorización inapropiada en el Terminal Web Interactivo en GitLab CE/EE que afectando a todas las versiones desde la 11.3 anteriores a 14.9.5, 14.10 anteriores a 14.10.4, y 15.0 anteriores a 15.0.1, permite a usuarios con el rol de Desarrollador abrir terminales en los trabajos en ejecución de otros Desarrolladores"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=11.3, <14.9.5","status":"affected"},{"version":">=14.10, <14.10.4","status":"affected"},{"version":">=15.0, <15.0.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":4.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":4.2}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:P/I:P/A:N","baseScore":4.9,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":6.8,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"14.9.5","matchCriteriaId":"68C8C8D5-E965-4291-9825-DD7A9AE0EB5F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"14.9.5","matchCriteriaId":"15F617DB-515D-46A9-BE58-CA3128108FD2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.10.0","versionEndExcluding":"14.10.4","matchCriteriaId":"5E69F4A1-5B3A-4FF5-95EC-62DCEB7DCE5F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.10.0","versionEndExcluding":"14.10.4","matchCriteriaId":"4E6B5E02-4670-4E74-A3EA-DF81659861E1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.0.0:*:*:*:community:*:*:*","matchCriteriaId":"00FDE831-EC28-4124-AC9F-A1C089D5BBFA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"E8953D9B-56DF-4AA2-BFDC-B28CF4F31CB5"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1944.json","source":"cve@gitlab.com","tags":["Patch","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/349750","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1944.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/349750","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2022-1680","sourceIdentifier":"cve@gitlab.com","published":"2022-06-06T18:15:08.417","lastModified":"2026-06-17T04:22:54.837","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An account takeover issue has been discovered in GitLab EE affecting all versions starting from 11.10 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1. When group SAML SSO is configured, the SCIM feature (available only on Premium+ subscriptions) may allow any owner of a Premium group to invite arbitrary users through their username and email, then change those users' email addresses via SCIM to an attacker controlled email address and thus - in the absence of 2FA - take over those accounts. It is also possible for the attacker to change the display name and username of the targeted account."},{"lang":"es","value":"Se ha detectado un problema de toma de posesión de cuentas en GitLab EE afectando a todas las versiones a partir de 11.10 anteriores a 14.9.5, todas las versiones a partir de 14.10 anteriores a 14.10.4 y todas las versiones a partir de 15.0 anteriores a 15.0.1. Cuando es configurado el SAML SSO de grupo, la función SCIM (disponible sólo en las suscripciones Premium+) puede permitir a cualquier propietario de un grupo Premium invitar a usuarios arbitrarios mediante su nombre de usuario y su correo electrónico, y luego cambiar las direcciones de correo electrónico de esos usuarios por medio de SCIM a una dirección de correo electrónico controlada por el atacante y así -en ausencia de 2FA- una toma de control de esas cuentas. También es posible que el atacante cambie el nombre de pantalla y el nombre de usuario de la cuenta objetivo"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=15.0.0, <15.0.1","status":"affected"},{"version":">=14.10.0, <14.10.4","status":"affected"},{"version":">=11.0, <14.9.5","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":9.9,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.1,"impactScore":6.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.10.0","versionEndExcluding":"14.9.5","matchCriteriaId":"788937EC-1DA9-4F08-91E4-41B79F91BCB9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.10.0","versionEndExcluding":"14.10.4","matchCriteriaId":"4E6B5E02-4670-4E74-A3EA-DF81659861E1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"E8953D9B-56DF-4AA2-BFDC-B28CF4F31CB5"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1680.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/363058","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1680.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/363058","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2022-1983","sourceIdentifier":"cve@gitlab.com","published":"2022-07-01T16:15:08.007","lastModified":"2026-06-17T04:23:28.027","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Incorrect authorization in GitLab EE affecting all versions from 10.7 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allowed an attacker already in possession of a valid Deploy Key or a Deploy Token to misuse it from any location to access Container Registries even when IP address restrictions were configured."},{"lang":"es","value":"Una autorización incorrecta en GitLab EE afectando a todas las versiones desde la 10.7 anteriores a 14.10.5, 15.0 anteriores a 15.0.4 y 15.1 anteriores a 15.1.1, permitía a un atacante que ya estuviera en posesión de una clave de despliegue válida o de un token de despliegue hacer un uso no debido de la misma desde cualquier lugar para acceder a los registros de contenedores, incluso cuando habían sido configuradas restricciones de direcciones IP"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=10.7, <14.10.5","status":"affected"},{"version":">=15.0, <15.0.4","status":"affected"},{"version":">=15.1, <15.1.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.7.0","versionEndExcluding":"14.10.5","matchCriteriaId":"EF025481-C2DD-4B86-B65D-E72CFCB60D9F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.0.0","versionEndExcluding":"15.0.4","matchCriteriaId":"18F6B2F9-8BDA-41C7-8152-70D61CCCC0B8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"E07D39FA-8428-4585-9A4C-55D2A1799F9E"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1983.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/363651","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1983.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/363651","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2022-2185","sourceIdentifier":"cve@gitlab.com","published":"2022-07-01T16:15:08.093","lastModified":"2026-06-17T04:41:27.597","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A critical issue has been discovered in GitLab affecting all versions starting from 14.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 where an authenticated user authorized to import projects could import a maliciously crafted project leading to remote code execution."},{"lang":"es","value":"Se ha descubierto un problema crítico en GitLab que afecta a todas las versiones a partir de la 14.0 anterior a la 14.10.5, la 15.0 anterior a la 15.0.4 y la 15.1 anterior a la 15.1.1, en el que un usuario autenticado y autorizado a importar proyectos podría importar un proyecto malicioso que condujera a la ejecución remota de código"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=14.0, <14.10.5","status":"affected"},{"version":">=15.0, <15.0.4","status":"affected"},{"version":">=15.1, <15.1.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":9.9,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.1,"impactScore":6.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-78"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.10.5","matchCriteriaId":"D4B25A15-8656-43DE-B0DF-3493BB2F8FE8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.10.5","matchCriteriaId":"53A77E6E-918F-402B-8F8D-D3843794E45B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.0.0","versionEndExcluding":"15.0.4","matchCriteriaId":"59BC7D90-71FE-4551-BC55-2CBDD7F037C3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.0.0","versionEndExcluding":"15.0.4","matchCriteriaId":"18F6B2F9-8BDA-41C7-8152-70D61CCCC0B8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.1.0:*:*:*:community:*:*:*","matchCriteriaId":"0CE56232-8EF7-428C-90F2-85803A66B664"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"E07D39FA-8428-4585-9A4C-55D2A1799F9E"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2185.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/366088","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1609965","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2185.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/366088","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1609965","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-2227","sourceIdentifier":"cve@gitlab.com","published":"2022-07-01T16:15:08.163","lastModified":"2026-06-17T04:41:31.453","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Improper access control in the runner jobs API in GitLab CE/EE affecting all versions prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows a previous maintainer of a project with a specific runner to access job and project meta data under certain conditions"},{"lang":"es","value":"Un control de acceso inapropiado en la API de trabajos del corredor en GitLab CE/EE afectando a todas las versiones anteriores a 14.10.5, 15.0 anteriores a 15.0.4, y 15.1 anteriores a 15.1.1, permite a un mantenedor anterior de un proyecto con un corredor específico acceder a los metadatos del trabajo y del proyecto bajo determinadas condiciones"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":"<14.10.5","status":"affected"},{"version":">=15.0, <15.0.4","status":"affected"},{"version":">=15.1, <15.1.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":3.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:P/I:N/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-732"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"14.10.5","matchCriteriaId":"E2C31BC5-AA93-42FD-9B94-FBE04BB721CE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"14.10.5","matchCriteriaId":"448992A9-00E1-4900-9BC1-7FE73970EBBE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.0.0","versionEndExcluding":"15.0.4","matchCriteriaId":"59BC7D90-71FE-4551-BC55-2CBDD7F037C3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.0.0","versionEndExcluding":"15.0.4","matchCriteriaId":"18F6B2F9-8BDA-41C7-8152-70D61CCCC0B8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.1.0:*:*:*:community:*:*:*","matchCriteriaId":"0CE56232-8EF7-428C-90F2-85803A66B664"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"E07D39FA-8428-4585-9A4C-55D2A1799F9E"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2227.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/300842","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1092199","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2227.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/300842","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1092199","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-2230","sourceIdentifier":"cve@gitlab.com","published":"2022-07-01T16:15:08.227","lastModified":"2026-06-17T04:41:31.780","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A Stored Cross-Site Scripting vulnerability in the project settings page in GitLab CE/EE affecting all versions from 14.4 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows an attacker to execute arbitrary JavaScript code in GitLab on a victim's behalf."},{"lang":"es","value":"Una vulnerabilidad de tipo Cross-Site Scripting almacenada en la página de configuración del proyecto en GitLab CE/EE afectando a todas las versiones desde 14.4 anteriores a 14.10.5, 15.0 anteriores a 15.0.4, y 15.1 anteriores a 15.1.1, permite a un atacante ejecutar código JavaScript arbitrario en GitLab en nombre de una víctima"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=14.4, <14.10.5","status":"affected"},{"version":">=15.0, <15.0.4","status":"affected"},{"version":">=15.1, <15.1.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.7,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N","baseScore":4.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.7,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.4.0","versionEndExcluding":"14.10.5","matchCriteriaId":"A4B917FC-56DF-40BB-8FEA-225E0C28EC2A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.4.0","versionEndExcluding":"14.10.5","matchCriteriaId":"D8F9AA9A-CC21-4FEE-8FD2-4FC03624CBC1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.0.0","versionEndExcluding":"15.0.4","matchCriteriaId":"59BC7D90-71FE-4551-BC55-2CBDD7F037C3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.0.0","versionEndExcluding":"15.0.4","matchCriteriaId":"18F6B2F9-8BDA-41C7-8152-70D61CCCC0B8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.1.0:*:*:*:community:*:*:*","matchCriteriaId":"0CE56232-8EF7-428C-90F2-85803A66B664"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"E07D39FA-8428-4585-9A4C-55D2A1799F9E"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2230.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/364164","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1588732","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2230.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/364164","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1588732","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-2235","sourceIdentifier":"cve@gitlab.com","published":"2022-07-01T16:15:08.300","lastModified":"2026-06-17T04:41:32.360","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Insufficient sanitization in GitLab EE's external issue tracker affecting all versions from 14.5 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to perform cross-site scripting when a victim clicks on a maliciously crafted ZenTao link"},{"lang":"es","value":"Un saneamiento insuficiente en el rastreador de problemas externo de GitLab EE afectando a todas las versiones desde la 14.5 anteriores a 14.10.5, la 15.0 anteriores a 15.0.4, y la 15.1 anteriores a 15.1.1 permite a un atacante llevar a cabo ataques de tipo cross-site scripting cruzados cuando una víctima hace clic en un enlace ZenTao maliciosamente diseñado"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=14.5, <14.10.5","status":"affected"},{"version":">=15.0, <15.0.4","status":"affected"},{"version":">=15.1, <15.1.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.10.5","matchCriteriaId":"027057E4-66F1-43FC-88B3-8288872EE194"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.0.0","versionEndExcluding":"15.0.4","matchCriteriaId":"18F6B2F9-8BDA-41C7-8152-70D61CCCC0B8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"E07D39FA-8428-4585-9A4C-55D2A1799F9E"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2235.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/360540","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1542510","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2235.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/360540","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1542510","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-2243","sourceIdentifier":"cve@gitlab.com","published":"2022-07-01T16:15:08.367","lastModified":"2026-06-17T04:41:33.103","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An access control vulnerability in GitLab EE/CE affecting all versions from 14.8 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows authenticated users to enumerate issues in non-linked sentry projects."},{"lang":"es","value":""}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=14.8, <14.10.5","status":"affected"},{"version":">=15.0, <15.0.4","status":"affected"},{"version":">=15.1, <15.1.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N","baseScore":5.0,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-639"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.8.0","versionEndExcluding":"14.10.5","matchCriteriaId":"BFD478CB-C2CF-4F7C-A51F-4CF1853E38BB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.8.0","versionEndExcluding":"14.10.5","matchCriteriaId":"7BD6FC32-3B01-44E6-9CF2-BE2D57F5684E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.0.0","versionEndExcluding":"15.0.4","matchCriteriaId":"59BC7D90-71FE-4551-BC55-2CBDD7F037C3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.0.0","versionEndExcluding":"15.0.4","matchCriteriaId":"18F6B2F9-8BDA-41C7-8152-70D61CCCC0B8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.1.0:*:*:*:community:*:*:*","matchCriteriaId":"0CE56232-8EF7-428C-90F2-85803A66B664"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"E07D39FA-8428-4585-9A4C-55D2A1799F9E"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2243.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/360666","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1546138","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2243.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/360666","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1546138","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-2244","sourceIdentifier":"cve@gitlab.com","published":"2022-07-01T16:15:08.437","lastModified":"2026-06-17T04:41:33.217","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An improper authorization vulnerability in GitLab EE/CE affecting all versions from 14.8 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows project memebers with reporter role to manage issues in project's error tracking feature."},{"lang":"es","value":"Una vulnerabilidad de autorización inapropiada en GitLab EE/CE afectando a todas las versiones desde la 14.8 anteriores a 14.10.5, la 15.0 anteriores a 15.0.4 y la 15.1 anteriores a 15.1.1, permite a miembros del proyecto con rol de reportero administrar problemas en la funcionalidad project's error tracking"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=14.8, <14.10.5","status":"affected"},{"version":">=15.0, <15.0.4","status":"affected"},{"version":">=15.1, <15.1.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.8.0","versionEndExcluding":"14.10.5","matchCriteriaId":"BFD478CB-C2CF-4F7C-A51F-4CF1853E38BB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.8.0","versionEndExcluding":"14.10.5","matchCriteriaId":"7BD6FC32-3B01-44E6-9CF2-BE2D57F5684E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.0.0","versionEndExcluding":"15.0.4","matchCriteriaId":"59BC7D90-71FE-4551-BC55-2CBDD7F037C3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.0.0","versionEndExcluding":"15.0.4","matchCriteriaId":"18F6B2F9-8BDA-41C7-8152-70D61CCCC0B8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.1.0:*:*:*:community:*:*:*","matchCriteriaId":"0CE56232-8EF7-428C-90F2-85803A66B664"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"E07D39FA-8428-4585-9A4C-55D2A1799F9E"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2244.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/360666","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1619583","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2244.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/360666","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1619583","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-2250","sourceIdentifier":"cve@gitlab.com","published":"2022-07-01T16:15:08.503","lastModified":"2026-06-17T04:41:33.557","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An open redirect vulnerability in GitLab EE/CE affecting all versions from 11.1 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows an attacker to redirect users to an arbitrary location if they trust the URL."},{"lang":"es","value":"Una vulnerabilidad de redireccionamiento abierto en GitLab EE/CE afectando a todas las versiones desde la 11.1 anteriores a 14.10.5, la 15.0 anteriores a 15.0.4 y la 15.1 anteriores a 15.1.1, permite a un atacante redirigir a usuarios a una ubicación arbitraria si confían en la URL"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=11.1, <14.10.5","status":"affected"},{"version":">=15.0, <15.0.4","status":"affected"},{"version":">=15.1, <15.1.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N","baseScore":4.7,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:N","baseScore":5.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-601"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.1.0","versionEndExcluding":"14.0.5","matchCriteriaId":"B0D39771-B059-4E58-8A0E-DF98631BD96E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.1.0","versionEndExcluding":"14.10.5","matchCriteriaId":"60536CF4-C35F-4126-8E64-8F448FC31EB3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.0.0","versionEndExcluding":"15.0.4","matchCriteriaId":"59BC7D90-71FE-4551-BC55-2CBDD7F037C3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.0.0","versionEndExcluding":"15.0.4","matchCriteriaId":"18F6B2F9-8BDA-41C7-8152-70D61CCCC0B8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.1.0:*:*:*:community:*:*:*","matchCriteriaId":"0CE56232-8EF7-428C-90F2-85803A66B664"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"E07D39FA-8428-4585-9A4C-55D2A1799F9E"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2250.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/355509","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1506126","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2250.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/355509","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1506126","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-2281","sourceIdentifier":"cve@gitlab.com","published":"2022-07-01T16:15:08.647","lastModified":"2026-06-17T04:41:37.147","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An information disclosure vulnerability in GitLab EE affecting all versions from 12.5 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows disclosure of release titles if group milestones are associated with any project releases."},{"lang":"es","value":"Una vulnerabilidad de divulgación de información en GitLab EE afectando a todas las versiones a partir de la 12.5 anteriores a 14.10.5, la 15.0 anteriores a 15.0.4 y la 15.1 anteriores a 15.1.1, permite una divulgación de los títulos de las versiones si los hitos del grupo están asociados a alguna versión del proyecto"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.5, <14.10.5","status":"affected"},{"version":">=15.0, <15.0.4","status":"affected"},{"version":">=15.1, <15.1.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N","baseScore":2.6,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.5.0","versionEndExcluding":"14.10.5","matchCriteriaId":"BE6C04FB-0D3C-4AAD-A81E-D80F37CA9DF9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.0.0","versionEndExcluding":"15.0.4","matchCriteriaId":"18F6B2F9-8BDA-41C7-8152-70D61CCCC0B8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"E07D39FA-8428-4585-9A4C-55D2A1799F9E"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2281.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/271172","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1012659","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2281.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/271172","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1012659","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-1963","sourceIdentifier":"cve@gitlab.com","published":"2022-07-01T17:15:07.143","lastModified":"2026-06-17T04:23:26.207","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 14.10.5, all versions starting from 15.0 before 15.0.4, all versions starting from 15.1 before 15.1.1. GitLab reveals if a user has enabled two-factor authentication on their account in the HTML source, to unauthenticated users."},{"lang":"es","value":"Se ha detectado un problema en GitLab CE/EE afectando a todas las versiones a partir de la 13.4 anteriores a 14.10.5, a todas las versiones a partir de la 15.0 anteriores a 15.0.4, a todas las versiones a partir de la 15.1 anteriores a 15.1.1. GitLab revela si un usuario ha habilitado la autenticación de dos factores en su cuenta en la fuente HTML, a usuarios no autenticados"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.4, <14.10.5","status":"affected"},{"version":">=15.0, <15.0.4","status":"affected"},{"version":">=15.1, <15.1.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.4.0","versionEndExcluding":"14.10.5","matchCriteriaId":"89307AF3-269D-4F29-A945-3D69369FFC2E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.4.0","versionEndExcluding":"14.10.5","matchCriteriaId":"E2C8845B-1CE5-4B93-BE4F-3943E08AF61C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.0.0","versionEndExcluding":"15.0.4","matchCriteriaId":"59BC7D90-71FE-4551-BC55-2CBDD7F037C3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.0.0","versionEndExcluding":"15.0.4","matchCriteriaId":"18F6B2F9-8BDA-41C7-8152-70D61CCCC0B8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.1.0:*:*:*:community:*:*:*","matchCriteriaId":"0CE56232-8EF7-428C-90F2-85803A66B664"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"E07D39FA-8428-4585-9A4C-55D2A1799F9E"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1963.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/352210","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1470023","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1963.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/352210","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1470023","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-1981","sourceIdentifier":"cve@gitlab.com","published":"2022-07-01T17:15:07.217","lastModified":"2026-06-17T04:23:27.793","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions starting from 12.2 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1. In GitLab, if a group enables the setting to restrict access to users belonging to specific domains, that allow-list may be bypassed if a Maintainer uses the 'Invite a group' feature to invite a group that has members that don't comply with domain allow-list."},{"lang":"es","value":"Se ha detectado un problema en GitLab EE afectando a todas las versiones a partir de la 12.2 anteriores a 14.10.5, la 15.0 anteriores a 15.0.4 y la 15.1 anteriores a 15.1.1. En GitLab, si un grupo habilita la configuración para restringir el acceso a usuarios que pertenecen a dominios específicos, esa lista permitida puede omitirse si un mantenedor usa la función \"Invite a group\" para invitar a un grupo que presenta miembros que no cumplen con la lista permitida del dominio"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.2, <14.10.5","status":"affected"},{"version":">=15.0, <15.0.4","status":"affected"},{"version":">=15.1, <15.1.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N","baseScore":2.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N","baseScore":2.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"14.10.5","matchCriteriaId":"C086FCC8-528B-4FDE-922C-35A7AD8B17EA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.0.0","versionEndExcluding":"15.0.4","matchCriteriaId":"18F6B2F9-8BDA-41C7-8152-70D61CCCC0B8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"E07D39FA-8428-4585-9A4C-55D2A1799F9E"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1981.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/354791","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1501733","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1981.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/354791","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1501733","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-1999","sourceIdentifier":"cve@gitlab.com","published":"2022-07-01T17:15:07.283","lastModified":"2026-06-17T04:23:29.727","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 8.13 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1. Under certain conditions, using the REST API an unprivileged user was able to change labels description."},{"lang":"es","value":"Se ha detectado un problema en GitLab CE/EE afectando a todas las versiones desde la 8.13 anteriores a 14.10.5, la 15.0 anteriores a 15.0.4 y la 15.1 anteriores a 15.1.1. Bajo determinadas condiciones, usando la API REST un usuario no privilegiado podía cambiar la descripción de las etiquetas"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=8.13, <14.10.5","status":"affected"},{"version":">=15.0, <15.0.4","status":"affected"},{"version":">=15.1, <15.1.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N","baseScore":3.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.13.0","versionEndExcluding":"14.10.5","matchCriteriaId":"E50D4514-ED7E-42A3-A99E-4F03D651F7B1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.13.0","versionEndExcluding":"14.10.5","matchCriteriaId":"BDCBE009-B48B-4B42-B0C5-789FCB1B7116"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.0.0","versionEndExcluding":"15.0.4","matchCriteriaId":"59BC7D90-71FE-4551-BC55-2CBDD7F037C3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.0.0","versionEndExcluding":"15.0.4","matchCriteriaId":"18F6B2F9-8BDA-41C7-8152-70D61CCCC0B8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.1.0:*:*:*:community:*:*:*","matchCriteriaId":"0CE56232-8EF7-428C-90F2-85803A66B664"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"E07D39FA-8428-4585-9A4C-55D2A1799F9E"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1999.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/357963","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1999.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/357963","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2022-2228","sourceIdentifier":"cve@gitlab.com","published":"2022-07-01T17:15:07.437","lastModified":"2026-06-17T04:41:31.563","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Information exposure in GitLab EE affecting all versions from 12.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker with the appropriate access tokens to obtain CI variables in a group with using IP-based access restrictions even if the GitLab Runner is calling from outside the allowed IP range"},{"lang":"es","value":"Una exposición de información en GitLab EE afectando a todas las versiones desde la 12.0 anteriores a 14.10.5, la 15.0 anteriores a 15.0.4 y la 15.1 anteriores a 15.1.1 permite a un atacante con los tokens de acceso apropiados obtener variables de CI en un grupo con el uso de restricciones de acceso basadas en IP, incluso si el GitLab Runner está llamando desde fuera del rango de IP permitido"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.0, <14.10.5","status":"affected"},{"version":">=15.0, <15.0.4","status":"affected"},{"version":">=15.1, <15.1.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.0.0","versionEndExcluding":"14.10.5","matchCriteriaId":"1BC6759B-67CB-457D-9E3A-87D9CFA1D370"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.0.0","versionEndExcluding":"15.0.4","matchCriteriaId":"18F6B2F9-8BDA-41C7-8152-70D61CCCC0B8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"E07D39FA-8428-4585-9A4C-55D2A1799F9E"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2228.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/security/gitlab/-/issues/682","source":"cve@gitlab.com","tags":["Permissions Required","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2228.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/security/gitlab/-/issues/682","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2022-2229","sourceIdentifier":"cve@gitlab.com","published":"2022-07-01T17:15:07.487","lastModified":"2026-06-17T04:41:31.670","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An improper authorization issue in GitLab CE/EE affecting all versions from 13.7 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to extract the value of an unprotected variable they know the name of in public projects or private projects they're a member of."},{"lang":"es","value":"Un problema de autorización inapropiada en GitLab CE/EE afectando a todas las versiones desde la 13.7 anteriores a 14.10.5, la 15.0 anteriores a 15.0.4 y la 15.1 anteriores a 15.1.1 permite a un atacante extraer el valor de una variable no protegida de la que conoce el nombre en proyectos públicos o privados de los que es miembro"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.7, <14.10.5","status":"affected"},{"version":">=15.0, <15.0.4","status":"affected"},{"version":">=15.1, <15.1.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"14.10.5","matchCriteriaId":"C64C3F26-2B71-4E0A-A2F0-67FBF1EB57FF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"14.10.5","matchCriteriaId":"5B47F70F-B2A0-4C62-9B90-FB43E986A9A4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.0.0","versionEndExcluding":"15.0.4","matchCriteriaId":"59BC7D90-71FE-4551-BC55-2CBDD7F037C3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.0.0","versionEndExcluding":"15.0.4","matchCriteriaId":"18F6B2F9-8BDA-41C7-8152-70D61CCCC0B8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.1.0:*:*:*:community:*:*:*","matchCriteriaId":"0CE56232-8EF7-428C-90F2-85803A66B664"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"E07D39FA-8428-4585-9A4C-55D2A1799F9E"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2229.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/355738","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1511133","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2229.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/355738","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1511133","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-2270","sourceIdentifier":"cve@gitlab.com","published":"2022-07-01T17:15:07.550","lastModified":"2026-06-17T04:41:35.953","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 12.4 before 14.10.5, all versions starting from 15.0 before 15.0.4, all versions starting from 15.1 before 15.1.1. GitLab was leaking Conan packages names due to incorrect permissions verification."},{"lang":"es","value":"Se ha detectado un problema en GitLab afectando a todas las versiones a partir de la 12.4 anteriores a 14.10.5, todas las versiones a partir de la 15.0 anteriores a 15.0.4, todas las versiones a partir de la 15.1 anteriores a 15.1.1. GitLab estaba filtrando los nombres de los paquetes de Conan debido a una verificación incorrecta de los permisos"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.4, <14.10.5","status":"affected"},{"version":">=15.0, <15.0.4","status":"affected"},{"version":">=15.1, <15.1.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N","baseScore":3.5,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-276"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.4.0","versionEndExcluding":"14.10.5","matchCriteriaId":"F20B9579-DA68-4FBE-8C6E-E6A2AACAB698"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.4.0","versionEndExcluding":"14.10.5","matchCriteriaId":"22A3673F-FB49-4800-B477-49C0F0267A56"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.0.0","versionEndExcluding":"15.0.4","matchCriteriaId":"59BC7D90-71FE-4551-BC55-2CBDD7F037C3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.0.0","versionEndExcluding":"15.0.4","matchCriteriaId":"18F6B2F9-8BDA-41C7-8152-70D61CCCC0B8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.1.0:*:*:*:community:*:*:*","matchCriteriaId":"0CE56232-8EF7-428C-90F2-85803A66B664"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"E07D39FA-8428-4585-9A4C-55D2A1799F9E"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2270.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/223074","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/901473","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2270.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/223074","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/901473","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-0167","sourceIdentifier":"cve@gitlab.com","published":"2022-07-01T18:15:08.517","lastModified":"2026-06-17T04:20:05.140","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 14.0 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was not disabling the Autocomplete attribute of fields related to sensitive information making it possible to be retrieved under certain conditions."},{"lang":"es","value":"Se ha detectado un problema en GitLab afectando a todas las versiones a partir de la 14.0 anteriores a 14.4.5, todas las versiones a partir de la 14.5.0 anteriores a 14.5.3, todas las versiones a partir de la 14.6.0 anteriores a 14.6.2. GitLab no deshabilitaba el atributo Autocompletar de los campos relacionados con información confidencial, haciendo posible su recuperación en determinadas condiciones"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=14.0, <14.4.5","status":"affected"},{"version":">=14.5.0, <14.5.3","status":"affected"},{"version":">=14.6.0, <14.6.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:N","baseScore":3.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":0.5,"impactScore":2.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.4.5","matchCriteriaId":"EF09679A-7EA4-42A6-9276-6185FF3785E2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.4.5","matchCriteriaId":"4D2FE61A-40FA-4896-82ED-0ACFA0648620"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.3","matchCriteriaId":"F4792D58-0D9A-43E6-879B-8DC10289BBED"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.3","matchCriteriaId":"2E89DBD2-9B16-4842-B103-B2B4096C046F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.6.0","versionEndExcluding":"14.6.2","matchCriteriaId":"3881FF6F-04B1-4780-A445-8FD3C5E70211"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.6.0","versionEndExcluding":"14.6.2","matchCriteriaId":"404671C6-4722-446A-B0B3-BA551FEAA4FC"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0167.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/339146","source":"cve@gitlab.com","tags":["Exploit","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0167.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/339146","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2022-1954","sourceIdentifier":"cve@gitlab.com","published":"2022-07-01T18:15:08.570","lastModified":"2026-06-17T04:23:25.167","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A Regular Expression Denial of Service vulnerability in GitLab CE/EE affecting all versions from 1.0.2 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to make a GitLab instance inaccessible via specially crafted web server response headers"},{"lang":"es","value":"Una vulnerabilidad de Denegación de Servicio por Expresiones Regulares en GitLab CE/EE que afecta a todas las versiones desde la 1.0.2 anteriores a 14.10.5, la 15.0 anteriores a 15.0.4 y la 15.1 anteriores a 15.1.1, permite a un atacante hacer inaccesible una instancia de GitLab por medio de encabezados de respuesta del servidor web especialmente diseñadas"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=1.0.2, <14.10.5","status":"affected"},{"version":">=15.0, <15.0.4","status":"affected"},{"version":">=15.1, <15.1.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-1333"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"1.0.2","versionEndExcluding":"14.10.5","matchCriteriaId":"333553F3-B222-4B31-939E-0A753F181E1D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"1.0.2","versionEndExcluding":"14.10.5","matchCriteriaId":"9DC186FA-BBBB-441D-B33D-A827D71BDFCD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.0.0","versionEndExcluding":"15.0.4","matchCriteriaId":"59BC7D90-71FE-4551-BC55-2CBDD7F037C3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.0.0","versionEndExcluding":"15.0.4","matchCriteriaId":"18F6B2F9-8BDA-41C7-8152-70D61CCCC0B8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.1.0:*:*:*:community:*:*:*","matchCriteriaId":"0CE56232-8EF7-428C-90F2-85803A66B664"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"E07D39FA-8428-4585-9A4C-55D2A1799F9E"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1954.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/358160","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1531958","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1954.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/358160","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1531958","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-1948","sourceIdentifier":"cve@gitlab.com","published":"2022-07-28T15:15:07.600","lastModified":"2026-06-17T04:23:24.567","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 15.0 before 15.0.1. Missing validation of input used in quick actions allowed an attacker to exploit XSS by injecting HTML in contact details."},{"lang":"es","value":"Se ha detectado un problema en GitLab afectando a todas las versiones desde 15.0 hasta 15.0.1. Una falta de comprobación de la entrada usada en las acciones rápidas permitía a un atacante explotar una vulnerabilidad de tipo XSS al inyectar HTML en los datos de contacto"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=15.0.0, <15.0.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.0.0:*:*:*:community:*:*:*","matchCriteriaId":"00FDE831-EC28-4124-AC9F-A1C089D5BBFA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"E8953D9B-56DF-4AA2-BFDC-B28CF4F31CB5"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1948.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/security/gitlab/-/issues/673","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://hackerone.com/reports/1578400","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1948.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/security/gitlab/-/issues/673","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]},{"url":"https://hackerone.com/reports/1578400","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2022-2095","sourceIdentifier":"cve@gitlab.com","published":"2022-08-05T16:15:11.617","lastModified":"2026-06-17T04:41:16.407","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An improper access control check in GitLab CE/EE affecting all versions starting from 13.7 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1 allows a malicious authenticated user to view a public project's Deploy Key's public fingerprint and name when that key has write permission. Note that GitLab never asks for nor stores the private key."},{"lang":"es","value":"Una comprobación de control de acceso inapropiada en GitLab CE/EE afectando a todas las versiones a partir de 13.7 anteriores a 15.0.5, a todas las versiones a partir de 15.1 anteriores a 15.1.4, a todas las versiones a partir de 15.2 anteriores a 15.2.1, permite a un usuario autenticado malicioso visualizar la huella digital pública y el nombre de la clave de despliegue de un proyecto público cuando dicha clave presenta permiso de escritura. Ten en cuenta que GitLab nunca pide ni almacena la clave privada"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.7, <15.0.5","status":"affected"},{"version":">=15.1, <15.1.4","status":"affected"},{"version":">=15.2, <15.2.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"15.0.5","matchCriteriaId":"69ADBFF9-BCC0-4B08-87E0-B25880525093"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.1.0","versionEndExcluding":"15.1.4","matchCriteriaId":"B835154E-74C9-40CC-9CB1-D0644E8FB5AB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"4ECA8C34-F6D0-4ED7-8278-041D709296BC"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"15.0.5","matchCriteriaId":"EC404E6B-ED77-470B-A5AA-7AC8A570D9B8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.1.0","versionEndExcluding":"15.1.4","matchCriteriaId":"6EB37BE7-C89E-4366-9735-AFD4B5B63984"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.2:*:*:*:community:*:*:*","matchCriteriaId":"B5EFE8DA-DD79-4CED-A75E-8240DAA9A143"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2095.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/365415","source":"cve@gitlab.com","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1600325","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2095.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/365415","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1600325","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-2303","sourceIdentifier":"cve@gitlab.com","published":"2022-08-05T16:15:11.677","lastModified":"2026-06-17T04:41:39.583","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible for group members to bypass 2FA enforcement enabled at the group level by using Resource Owner Password Credentials grant to obtain an access token without using 2FA."},{"lang":"es","value":"Se ha detectado un problema en GitLab CE/EE afectando a todas las versiones anteriores a la 15.0.5, a todas las versiones a partir de 15.1 anteriores a 15.1.4 y a todas las versiones a partir de 15.2 anteriores a 15.2.1. Puede ser posible a los miembros del grupo omitir la aplicación de 2FA habilitada a nivel de grupo al usar la concesión de credenciales de contraseña de propietario de recursos para obtener un token de acceso sin usar 2FA"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=15.2, <15.2.1","status":"affected"},{"version":">=15.1, <15.1.4","status":"affected"},{"version":">=0.0, <15.0.5","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-287"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"15.0.5","matchCriteriaId":"9C4B3F61-B368-4253-AAAF-61A11FD7EACA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.1.0","versionEndExcluding":"15.1.4","matchCriteriaId":"B835154E-74C9-40CC-9CB1-D0644E8FB5AB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"4ECA8C34-F6D0-4ED7-8278-041D709296BC"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"15.0.5","matchCriteriaId":"D6E61178-D0CC-4A09-8059-E25D6CD137B5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.1.0","versionEndExcluding":"15.1.4","matchCriteriaId":"6EB37BE7-C89E-4366-9735-AFD4B5B63984"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.2:*:*:*:community:*:*:*","matchCriteriaId":"B5EFE8DA-DD79-4CED-A75E-8240DAA9A143"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2303.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/355028","source":"cve@gitlab.com","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1498133","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2303.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/355028","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1498133","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-2307","sourceIdentifier":"cve@gitlab.com","published":"2022-08-05T16:15:11.730","lastModified":"2026-06-17T04:41:40.017","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A lack of cascading deletes in GitLab CE/EE affecting all versions starting from 13.0 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1 allows a malicious Group Owner to retain a usable Group Access Token even after the Group is deleted, though the APIs usable by that token are limited."},{"lang":"es","value":"Una falta de borrado en cascada en GitLab CE/EE afectando a todas las versiones a partir de 13.0 anteriores a 15.0.5, a todas las versiones a partir de 15.1 anteriores a 15.1.4, a todas las versiones a partir de 15.2 anteriores a 15.2.1, permite que un propietario de grupo malicioso conserve un token de acceso al grupo usable incluso después de que se haya eliminado el grupo, aunque las API usables por ese token son limitadas"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.0, <15.0.5","status":"affected"},{"version":">=15.1, <15.1.4","status":"affected"},{"version":">=15.2, <15.2.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N","baseScore":3.5,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":0.9,"impactScore":2.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N","baseScore":3.8,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":2.5}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-459"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.0.0","versionEndExcluding":"15.0.5","matchCriteriaId":"CA7CDB62-8D97-43F2-B928-27526E08375D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.1.0","versionEndExcluding":"15.1.4","matchCriteriaId":"B835154E-74C9-40CC-9CB1-D0644E8FB5AB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"4ECA8C34-F6D0-4ED7-8278-041D709296BC"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.0.0","versionEndExcluding":"15.0.5","matchCriteriaId":"E6FF812F-1C4F-47AE-B980-433F332602E3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.1.0","versionEndExcluding":"15.1.4","matchCriteriaId":"6EB37BE7-C89E-4366-9735-AFD4B5B63984"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.2:*:*:*:community:*:*:*","matchCriteriaId":"B5EFE8DA-DD79-4CED-A75E-8240DAA9A143"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2307.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/360025","source":"cve@gitlab.com","tags":["Broken Link","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2307.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/360025","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2022-2326","sourceIdentifier":"cve@gitlab.com","published":"2022-08-05T16:15:11.787","lastModified":"2026-06-17T04:41:41.990","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible to gain access to a private project through an email invite by using other user's email address as an unverified secondary email."},{"lang":"es","value":"Se ha detectado un problema en GitLab CE/EE afectando a todas las versiones anteriores a la 15.0.5, a todas las versiones a partir de 15.1 anteriores a 15.1.4 y a todas las versiones a partir de 15.2 anteriores a 15.2.1. Puede ser posible obtener acceso a un proyecto privado mediante una invitación por correo electrónico usando la dirección de correo electrónico de otro usuario como un correo electrónico secundario no verificado"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=0.0, <15.0.5","status":"affected"},{"version":">=15.1, <15.1.4","status":"affected"},{"version":">=15.2, <15.2.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":5.2}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"15.0.5","matchCriteriaId":"9C4B3F61-B368-4253-AAAF-61A11FD7EACA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.1.0","versionEndExcluding":"15.1.4","matchCriteriaId":"B835154E-74C9-40CC-9CB1-D0644E8FB5AB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"4ECA8C34-F6D0-4ED7-8278-041D709296BC"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"15.0.5","matchCriteriaId":"D6E61178-D0CC-4A09-8059-E25D6CD137B5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.1.0","versionEndExcluding":"15.1.4","matchCriteriaId":"6EB37BE7-C89E-4366-9735-AFD4B5B63984"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"4ECA8C34-F6D0-4ED7-8278-041D709296BC"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2326.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/356665","source":"cve@gitlab.com","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1517554","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2326.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/356665","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1517554","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-2417","sourceIdentifier":"cve@gitlab.com","published":"2022-08-05T16:15:11.860","lastModified":"2026-06-17T04:41:51.480","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Insufficient validation in GitLab CE/EE affecting all versions from 12.10 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 allows an authenticated and authorised user to import a project that includes branch names which are 40 hexadecimal characters, which could be abused in supply chain attacks where a victim pinned to a specific Git commit of the project."},{"lang":"es","value":"Una comprobación insuficiente en GitLab CE/EE afectando a todas las versiones a partir de 12.10 anteriores a 15.0.5, la 15.1 anteriores a 15.1.4 y la 15.2 anteriores a 15.2.1 permite a un usuario autenticado y autorizado importar un proyecto que incluya nombres de rama que tengan 40 caracteres hexadecimales, lo que podría ser objeto de abuso en ataques a una cadena de suministro en los que una víctima es fijado en un commit Git específico del proyecto"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.10, <15.0.5","status":"affected"},{"version":">=15.1, <15.1.4","status":"affected"},{"version":">=15.2, <15.2.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:N","baseScore":6.2,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.7,"impactScore":4.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N","baseScore":4.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":0.9,"impactScore":3.6}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-20"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.10.0","versionEndExcluding":"15.0.5","matchCriteriaId":"722750F6-836C-4A7E-9114-7279BE652181"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.1.0","versionEndExcluding":"15.1.4","matchCriteriaId":"B835154E-74C9-40CC-9CB1-D0644E8FB5AB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"4ECA8C34-F6D0-4ED7-8278-041D709296BC"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.10.0","versionEndExcluding":"15.0.5","matchCriteriaId":"E5AB715D-FB7D-4F88-B01C-A2C3B6EA7D58"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.1.0","versionEndExcluding":"15.1.4","matchCriteriaId":"6EB37BE7-C89E-4366-9735-AFD4B5B63984"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.2:*:*:*:community:*:*:*","matchCriteriaId":"B5EFE8DA-DD79-4CED-A75E-8240DAA9A143"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2417.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/361179","source":"cve@gitlab.com","tags":["Broken Link","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2417.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/361179","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2022-2456","sourceIdentifier":"cve@gitlab.com","published":"2022-08-05T16:15:11.930","lastModified":"2026-06-17T04:41:55.673","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible for malicious group or project maintainers to change their corresponding group or project visibility by crafting a malicious POST request."},{"lang":"es","value":"Se ha detectado un problema en GitLab CE/EE afectando a todas las versiones anteriores a la 15.0.5, a todas las versiones a partir de 15.1 anteriores a 15.1.4 y a todas las versiones a partir de 15.2 anteriores a 15.2.1. Es posible que mantenedores de grupos o proyectos maliciosos cambien la visibilidad de su grupo o proyecto correspondiente al diseñar una petición POST maliciosa"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=15.2, <15.2.1","status":"affected"},{"version":">=15.1, <15.1.4","status":"affected"},{"version":">=0.0, <15.0.5","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N","baseScore":2.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":1.4}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"15.0.5","matchCriteriaId":"9C4B3F61-B368-4253-AAAF-61A11FD7EACA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.1.0","versionEndExcluding":"15.1.4","matchCriteriaId":"B835154E-74C9-40CC-9CB1-D0644E8FB5AB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"4ECA8C34-F6D0-4ED7-8278-041D709296BC"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"15.0.5","matchCriteriaId":"D6E61178-D0CC-4A09-8059-E25D6CD137B5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.1.0","versionEndExcluding":"15.1.4","matchCriteriaId":"6EB37BE7-C89E-4366-9735-AFD4B5B63984"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.2:*:*:*:community:*:*:*","matchCriteriaId":"B5EFE8DA-DD79-4CED-A75E-8240DAA9A143"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2456.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/359910","source":"cve@gitlab.com","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1536559","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2456.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/359910","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1536559","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-2459","sourceIdentifier":"cve@gitlab.com","published":"2022-08-05T16:15:11.993","lastModified":"2026-06-17T04:41:56.040","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible for email invited members to join a project even after the Group Owner has enabled the setting to prevent members from being added to projects in a group, if the invite was sent before the setting was enabled."},{"lang":"es","value":"Se ha detectado un problema en GitLab EE afectando a todas las versiones anteriores a la 15.0.5, a todas las versiones a partir de 15.1 anteriores a 15.1.4 y a todas las versiones a partir de 15.2 anteriores a 15.2.1. Es posible que miembros invitados por correo electrónico sean unidas a un proyecto incluso después de que el propietario del grupo haya habilitado la configuración para evitar que los miembros sean añadidas a proyectos de un grupo, si la invitación es enviada antes de que sea habilitada la configuración"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=15.2, <15.2.1","status":"affected"},{"version":">=15.1, <15.1.4","status":"affected"},{"version":">=0.0, <15.0.5","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N","baseScore":2.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N","baseScore":2.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":1.4}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"15.0.5","matchCriteriaId":"9C4B3F61-B368-4253-AAAF-61A11FD7EACA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.1.0","versionEndExcluding":"15.1.4","matchCriteriaId":"B835154E-74C9-40CC-9CB1-D0644E8FB5AB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"4ECA8C34-F6D0-4ED7-8278-041D709296BC"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"15.0.5","matchCriteriaId":"D6E61178-D0CC-4A09-8059-E25D6CD137B5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.1.0","versionEndExcluding":"15.1.4","matchCriteriaId":"6EB37BE7-C89E-4366-9735-AFD4B5B63984"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.2:*:*:*:community:*:*:*","matchCriteriaId":"B5EFE8DA-DD79-4CED-A75E-8240DAA9A143"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2459.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/336169","source":"cve@gitlab.com","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1256967","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2459.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/336169","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1256967","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-2497","sourceIdentifier":"cve@gitlab.com","published":"2022-08-05T16:15:12.067","lastModified":"2026-06-17T04:42:00.353","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. A malicious developer could exfiltrate an integration's access token by modifying the integration URL such that authenticated requests are sent to an attacker controlled server."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones a partir de la 12.6 antes de la 15.0.5, todas las versiones a partir de la 15.1 antes de la 15.1.4, todas las versiones a partir de la 15.2 antes de la 15.2.1. Un desarrollador malintencionado podría exfiltrar el token de acceso de una integración modificando la URL de la integración de forma que las peticiones autenticadas se envíen a un servidor controlado por el atacante"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.6, <15.0.5","status":"affected"},{"version":">=15.1, <15.1.4","status":"affected"},{"version":">=15.2, <15.2.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N","baseScore":8.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":4.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.6.0","versionEndExcluding":"15.0.5","matchCriteriaId":"0FD7184D-167C-478B-8EE5-1C8E021B4A74"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.1.0","versionEndExcluding":"15.1.4","matchCriteriaId":"B835154E-74C9-40CC-9CB1-D0644E8FB5AB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"4ECA8C34-F6D0-4ED7-8278-041D709296BC"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.6.0","versionEndExcluding":"15.0.5","matchCriteriaId":"B8983233-E8DA-4D3B-B215-6E091021932F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.1.0","versionEndExcluding":"15.1.4","matchCriteriaId":"6EB37BE7-C89E-4366-9735-AFD4B5B63984"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.2:*:*:*:community:*:*:*","matchCriteriaId":"B5EFE8DA-DD79-4CED-A75E-8240DAA9A143"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2497.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/362671","source":"cve@gitlab.com","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1557992","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2497.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/362671","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1557992","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-2498","sourceIdentifier":"cve@gitlab.com","published":"2022-08-05T16:15:12.137","lastModified":"2026-06-17T04:42:00.470","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue in pipeline subscriptions in GitLab EE affecting all versions from 12.8 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 triggered new pipelines with the person who created the tag as the pipeline creator instead of the subscription's author."},{"lang":"es","value":"Un problema en las suscripciones a pipelines en GitLab EE afectando a todas las versiones desde la 12.8 anteriores a 15.0.5, la 15.1 anteriores a 15.1.4 y la 15.2 anteriores a 15.2.1, desencadena nuevos pipelines con la persona que creó la etiqueta como creador de tubería en lugar del autor de la suscripción"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.8, <15.0.5","status":"affected"},{"version":">=15.1, <15.1.4","status":"affected"},{"version":">=15.2, <15.2.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-269"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.8.0","versionEndExcluding":"15.0.5","matchCriteriaId":"2803CE66-92D2-41EF-9CB1-FCB133732CF6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.1.0","versionEndExcluding":"15.1.4","matchCriteriaId":"B835154E-74C9-40CC-9CB1-D0644E8FB5AB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"4ECA8C34-F6D0-4ED7-8278-041D709296BC"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2498.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/243703","source":"cve@gitlab.com","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/966824","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2498.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/243703","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/966824","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-2499","sourceIdentifier":"cve@gitlab.com","published":"2022-08-05T16:15:12.200","lastModified":"2026-06-17T04:42:00.587","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions starting from 13.10 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. GitLab's Jira integration has an insecure direct object reference vulnerability that may be exploited by an attacker to leak Jira issues."},{"lang":"es","value":"Se ha detectado un problema en GitLab EE afectando a todas las versiones a partir de 13.10 anteriores a 15.0.5, a todas las versiones a partir de 15.1 anteriores a 15.1.4, a todas las versiones a partir de 15.2 anteriores a 15.2.1. La integración con Jira de GitLab presenta una vulnerabilidad de referencia directa a objetos insegura que puede ser aprovechada por un atacante para filtrar las incidencias de Jira"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.10, <15.0.5","status":"affected"},{"version":">=15.1, <15.1.4","status":"affected"},{"version":">=15.2, <15.2.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N","baseScore":3.5,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-639"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.10.0","versionEndExcluding":"15.0.5","matchCriteriaId":"406D181D-067D-4023-8617-B7817B44456C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.1.0","versionEndExcluding":"15.1.4","matchCriteriaId":"B835154E-74C9-40CC-9CB1-D0644E8FB5AB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"4ECA8C34-F6D0-4ED7-8278-041D709296BC"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2499.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/360800","source":"cve@gitlab.com","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1538068","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2499.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/360800","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1538068","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-2500","sourceIdentifier":"cve@gitlab.com","published":"2022-08-05T16:15:12.267","lastModified":"2026-06-17T04:42:00.700","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1. A stored XSS flaw in job error messages allows attackers to perform arbitrary actions on behalf of victims at client side."},{"lang":"es","value":"Se ha detectado un problema de tipo cross-site scripting en GitLab CE/EE afectando a todas las versiones anteriores a 15.0.5, a 15.1 anterior a 15.1.4 y  15.2 anteriores a 15.2.1. Un fallo de tipo XSS almacenado en los mensajes de error de los trabajos permite a atacantes llevar a cabo acciones arbitrarias en nombre de las víctimas en el lado del cliente"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=0.0, <15.0.5","status":"affected"},{"version":">=15.1, <15.1.4","status":"affected"},{"version":">=15.2, <15.2.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":4.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.3,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"15.0.5","matchCriteriaId":"9C4B3F61-B368-4253-AAAF-61A11FD7EACA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.1.0","versionEndExcluding":"15.1.4","matchCriteriaId":"B835154E-74C9-40CC-9CB1-D0644E8FB5AB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"4ECA8C34-F6D0-4ED7-8278-041D709296BC"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"15.0.5","matchCriteriaId":"D6E61178-D0CC-4A09-8059-E25D6CD137B5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.1.0","versionEndExcluding":"15.1.4","matchCriteriaId":"6EB37BE7-C89E-4366-9735-AFD4B5B63984"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.2:*:*:*:community:*:*:*","matchCriteriaId":"B5EFE8DA-DD79-4CED-A75E-8240DAA9A143"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2500.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/363725","source":"cve@gitlab.com","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1579645","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2500.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/363725","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1579645","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-2501","sourceIdentifier":"cve@gitlab.com","published":"2022-08-05T16:15:12.327","lastModified":"2026-06-17T04:42:00.817","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An improper access control issue in GitLab EE affecting all versions from 12.0 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 allows an attacker to bypass IP allow-listing and download artifacts. This attack only bypasses IP allow-listing, proper permissions are still required."},{"lang":"es","value":"Un problema de control de acceso inapropiado en GitLab EE afectando a todas las versiones desde la 12.0 anteriores a 15.0.5, la 15.1 anteriores a 15.1.4 y la 15.2 anteriores a 15.2.1 permite a un atacante omitir la lista de IPs permitidas y descargar artefactos. Este ataque sólo evita la lista de IPs permitidas, los permisos apropiados siguen siendo necesarios"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.0, <15.0.5","status":"affected"},{"version":">=15.1, <15.1.4","status":"affected"},{"version":">=15.2, <15.2.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.0.0","versionEndExcluding":"15.0.5","matchCriteriaId":"28664DAF-CB65-4C8C-B26A-CC2192A0447D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.1.0","versionEndExcluding":"15.1.4","matchCriteriaId":"B835154E-74C9-40CC-9CB1-D0644E8FB5AB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"4ECA8C34-F6D0-4ED7-8278-041D709296BC"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2501.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/364822","source":"cve@gitlab.com","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1591412","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2501.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/364822","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1591412","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-2512","sourceIdentifier":"cve@gitlab.com","published":"2022-08-05T16:15:12.383","lastModified":"2026-06-17T04:42:02.107","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.0 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. Membership changes are not reflected in TODO for confidential notes, allowing a former project members to read updates via TODOs."},{"lang":"es","value":"Se ha detectado un problema en GitLab CE/EE afectando a todas las versiones a partir de 15.0 anteriores a 15.0.5, todas las versiones a partir de 15.1 anteriores a 15.1.4, todas las versiones a partir de 15.2 anteriores a 15.2.1. Los cambios de los miembros no son reflejados en los TODO de las notas confidenciales, lo que permite a antiguos miembros del proyecto leer las actualizaciones por medio de los TODO"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=15.2, <15.2.1","status":"affected"},{"version":">=15.1, <15.1.4","status":"affected"},{"version":">=15.0, <15.0.5","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.0.0","versionEndExcluding":"15.0.5","matchCriteriaId":"D050B123-5443-4056-A991-1CF6CFD07D9A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.1.0","versionEndExcluding":"15.1.4","matchCriteriaId":"B835154E-74C9-40CC-9CB1-D0644E8FB5AB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"4ECA8C34-F6D0-4ED7-8278-041D709296BC"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.0.0","versionEndExcluding":"15.0.5","matchCriteriaId":"81853305-D2DB-4FC0-8A3E-95BC68E3D3C0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.1.0","versionEndExcluding":"15.1.4","matchCriteriaId":"6EB37BE7-C89E-4366-9735-AFD4B5B63984"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.2:*:*:*:community:*:*:*","matchCriteriaId":"B5EFE8DA-DD79-4CED-A75E-8240DAA9A143"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2512.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/365742","source":"cve@gitlab.com","tags":["Broken Link","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2512.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/365742","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2022-2531","sourceIdentifier":"cve@gitlab.com","published":"2022-08-05T16:15:12.433","lastModified":"2026-06-17T04:42:04.167","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions starting from 12.5 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. GitLab was not performing correct authentication on Grafana API under specific conditions allowing unauthenticated users to perform queries through a path traversal vulnerability."},{"lang":"es","value":"Se ha detectado un problema en GitLab EE afectando a todas las versiones a partir de 12.5 anteriores a 15.0.5, todas las versiones a partir de 15.1 anteriores a 15.1.4, todas las versiones a partir de 15.2 anteriores a 15.2.1. GitLab no estaba llevando a cabo una autenticación correcta en la API de Grafana bajo condiciones específicas que permitían a usuarios no autenticados llevar a cabo consultas mediante una vulnerabilidad de salto de ruta"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.5, <15.0.5","status":"affected"},{"version":">=15.1, <15.1.4","status":"affected"},{"version":">=15.2, <15.2.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-22"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.5.0","versionEndExcluding":"15.0.5","matchCriteriaId":"2B96516E-90F7-4BBF-A6CA-19E2839D1EA7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.1.0","versionEndExcluding":"15.1.4","matchCriteriaId":"B835154E-74C9-40CC-9CB1-D0644E8FB5AB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"4ECA8C34-F6D0-4ED7-8278-041D709296BC"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2531.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/364252","source":"cve@gitlab.com","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1566306","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2531.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/364252","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1566306","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-2534","sourceIdentifier":"cve@gitlab.com","published":"2022-08-05T16:15:12.490","lastModified":"2026-06-17T04:42:04.493","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 9.3 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. GitLab was returning contributor emails due to improper data handling in the Datadog integration."},{"lang":"es","value":"Se ha detectado un problema en GitLab CE/EE afectando a todas las versiones a partir de 9.3 anteriores a 15.0.5, a todas las versiones a partir de 15.1 anteriores a 15.1.4 y a todas las versiones a partir de 15.2 anteriores a 15.2.1. GitLab devolvía los correos electrónicos de los colaboradores debido a un manejo inapropiado de los datos en la integración con Datadog"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=9.3, <15.0.5","status":"affected"},{"version":">=15.1, <15.1.4","status":"affected"},{"version":">=15.2, <15.2.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N","baseScore":2.2,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":0.7,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"9.3.0","versionEndExcluding":"15.0.5","matchCriteriaId":"3C66E87A-6C4A-4930-8F55-9299C03BFDF2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.1.0","versionEndExcluding":"15.1.4","matchCriteriaId":"B835154E-74C9-40CC-9CB1-D0644E8FB5AB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"4ECA8C34-F6D0-4ED7-8278-041D709296BC"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"9.3.0","versionEndExcluding":"15.0.5","matchCriteriaId":"33B49790-BC4A-4344-B867-373C75A2B166"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.1.0","versionEndExcluding":"15.1.4","matchCriteriaId":"6EB37BE7-C89E-4366-9735-AFD4B5B63984"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.2:*:*:*:community:*:*:*","matchCriteriaId":"B5EFE8DA-DD79-4CED-A75E-8240DAA9A143"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2534.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/361654","source":"cve@gitlab.com","tags":["Broken Link","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2534.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/361654","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2022-2539","sourceIdentifier":"cve@gitlab.com","published":"2022-08-05T16:15:12.547","lastModified":"2026-06-17T04:42:05.130","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.6 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1, allowed a project member to filter issues by contact and organization."},{"lang":"es","value":"Se ha detectado un problema en GitLab CE/EE afectando a todas las versiones a partir de 14.6 anterior a la 15.0.5, la 15.1 anterior a la 15.1.4 y la 15.2 anterior a la 15.2.1, que permitía a un miembro del proyecto filtrar las incidencias por contacto y organización"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=14.6, <15.0.5","status":"affected"},{"version":">=15.1, <15.1.4","status":"affected"},{"version":">=15.2, <15.2.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.6.0","versionEndExcluding":"15.0.5","matchCriteriaId":"D9BAC6B6-C6B4-4A8F-8539-7EDEF8735E25"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.1.0","versionEndExcluding":"15.1.4","matchCriteriaId":"B835154E-74C9-40CC-9CB1-D0644E8FB5AB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"4ECA8C34-F6D0-4ED7-8278-041D709296BC"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.6.0","versionEndExcluding":"15.0.5","matchCriteriaId":"7918DA09-A434-465A-9261-531647CB419A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.1.0","versionEndExcluding":"15.1.4","matchCriteriaId":"6EB37BE7-C89E-4366-9735-AFD4B5B63984"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.2:*:*:*:community:*:*:*","matchCriteriaId":"B5EFE8DA-DD79-4CED-A75E-8240DAA9A143"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2539.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/364315","source":"cve@gitlab.com","tags":["Broken Link","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2539.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/364315","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2022-2428","sourceIdentifier":"cve@gitlab.com","published":"2022-10-17T16:15:20.990","lastModified":"2026-06-17T04:41:52.570","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A crafted tag in the Jupyter Notebook viewer in GitLab EE/CE affecting all versions before 15.1.6, 15.2 to 15.2.4, and 15.3 to 15.3.2 allows an attacker to issue arbitrary HTTP requests"},{"lang":"es","value":"Una etiqueta diseñada en Jupyter Notebook viewer in GitLab EE/CE que afectando a todas las versiones anteriores a 15.1.6, 15.2 a 15.2.4, y 15.3 a 15.3.2 permite a un atacante emitir peticiones HTTP arbitrarias"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=15.0, <15.1.6","status":"affected"},{"version":">=15.2, <15.2.4","status":"affected"},{"version":">=15.3, <15.3.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-13T19:48:19.706801Z","id":"CVE-2022-2428","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"15.1.6","matchCriteriaId":"4AD3082E-EC31-4A5E-BADB-23D9AA1C64E1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"15.1.6","matchCriteriaId":"F398204C-DEBD-4A66-A404-FD350D454738"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.2","versionEndExcluding":"15.2.4","matchCriteriaId":"3D749C09-7157-4B87-9232-8E32F05C6655"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.2","versionEndExcluding":"15.2.4","matchCriteriaId":"B81CEDFB-EDCD-4298-8AEF-80C16422AE12"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.3","versionEndExcluding":"15.3.2","matchCriteriaId":"72FB7E61-B73F-4BBA-A1B4-FAFC9F351858"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.3","versionEndExcluding":"15.3.2","matchCriteriaId":"7D17D848-4F93-4E17-98E7-10DC30A5CCFE"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2428.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/362272","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://hackerone.com/reports/1563379","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2428.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/362272","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://hackerone.com/reports/1563379","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/362272","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-2455","sourceIdentifier":"cve@gitlab.com","published":"2022-10-17T16:15:21.060","lastModified":"2026-06-17T04:41:55.557","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A business logic issue in the handling of large repositories in all versions of GitLab CE/EE from 10.0 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2 allowed an authenticated and authorized user to exhaust server resources by importing a malicious project."},{"lang":"es","value":"Un problema de lógica de negocio en el manejo de repositorios grandes en todas las versiones de GitLab CE/EE desde la 10.0 anteriores a 15.1.6, todas las versiones a partir de 15.2 anteriores a 15.2.4, todas las versiones a partir de 15.3 anteriores a 15.3.2, permitía a un usuario autenticado y autorizado agotar los recursos del servidor importando un proyecto malicioso"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=10.0, <15.1.6","status":"affected"},{"version":">=15.2, <15.2.4","status":"affected"},{"version":">=15.3, <15.3.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-13T19:41:15.605298Z","id":"CVE-2022-2455","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-400"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-400"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.0.0","versionEndExcluding":"15.1.6","matchCriteriaId":"DFCA9940-AB41-4FEC-9E73-4CD45424B7DD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.0.0","versionEndExcluding":"15.1.6","matchCriteriaId":"7A0F024F-E32F-437D-AE54-F630126F2CE1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.2","versionEndExcluding":"15.2.4","matchCriteriaId":"3D749C09-7157-4B87-9232-8E32F05C6655"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.2","versionEndExcluding":"15.2.4","matchCriteriaId":"B81CEDFB-EDCD-4298-8AEF-80C16422AE12"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.3","versionEndExcluding":"15.3.2","matchCriteriaId":"72FB7E61-B73F-4BBA-A1B4-FAFC9F351858"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.3","versionEndExcluding":"15.3.2","matchCriteriaId":"7D17D848-4F93-4E17-98E7-10DC30A5CCFE"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2455.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/359964","source":"cve@gitlab.com","tags":["Broken Link","Third Party Advisory"]},{"url":"https://hackerone.com/reports/1542230","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2455.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/359964","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory"]},{"url":"https://hackerone.com/reports/1542230","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-2527","sourceIdentifier":"cve@gitlab.com","published":"2022-10-17T16:15:21.133","lastModified":"2026-06-17T04:42:03.813","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue in Incident Timelines has been discovered in GitLab CE/EE affecting all versions starting from 14.9 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2.which allowed an authenticated attacker to inject arbitrary content. A victim interacting with this content could lead to arbitrary requests."},{"lang":"es","value":"Se ha detectado un problema en las líneas de tiempo de incidentes en GitLab CE/EE afectando a todas las versiones a partir de 14.9 anteriores a 15.1.6, a todas las versiones a partir de 15.2 anteriores a 15.2.4, a todas las versiones a partir de 15.3 anteriores a 15.3.2.que permitía a un atacante autenticado inyectar contenido arbitrario. Una víctima que interactuara con este contenido podría conllevar a peticiones arbitrarias"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=15.3, <15.3.2","status":"affected"},{"version":">=15.2, <15.2.4","status":"affected"},{"version":">=14.9, <15.1.6","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","baseScore":8.0,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.1,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-13T19:34:31.428767Z","id":"CVE-2022-2527","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"15.1.6","matchCriteriaId":"25B4AA56-7411-4E45-A319-504E7CD4B745"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"15.1.6","matchCriteriaId":"A8276955-1F00-4D1A-A0E5-29A7D37A4CE3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.2","versionEndExcluding":"15.2.4","matchCriteriaId":"3D749C09-7157-4B87-9232-8E32F05C6655"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.2","versionEndExcluding":"15.2.4","matchCriteriaId":"B81CEDFB-EDCD-4298-8AEF-80C16422AE12"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.3","versionEndExcluding":"15.3.2","matchCriteriaId":"72FB7E61-B73F-4BBA-A1B4-FAFC9F351858"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.3","versionEndExcluding":"15.3.2","matchCriteriaId":"7D17D848-4F93-4E17-98E7-10DC30A5CCFE"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2527.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/368676","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://hackerone.com/reports/1647446","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2527.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/368676","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://hackerone.com/reports/1647446","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/368676","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-2533","sourceIdentifier":"cve@gitlab.com","published":"2022-10-17T16:15:21.203","lastModified":"2026-06-17T04:42:04.377","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 12.10 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. GitLab was not performing correct authentication with some Package Registries when IP address restrictions were configured, allowing an attacker already in possession of a valid Deploy Token to misuse it from any location."},{"lang":"es","value":"Se ha detectado un problema en GitLab afectando a todas las versiones a partir de 12.10 anteriores a 15.1.6, todas las versiones a partir de 15.2 anteriores a 15.2.4, todas las versiones a partir de 15.3 anteriores a 15.3.2. GitLab no llevaba a cabo una autenticación correcta con algunos Registros de Paquetes cuando eran configurados restricciones de direcciones IP, lo que permitía que un atacante que ya estuviera en posesión de un Token de Despliegue válido lo usara inapropiadamente desde cualquier lugar"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.10, <15.1.6","status":"affected"},{"version":">=15.2, <15.2.4","status":"affected"},{"version":">=15.3, <15.3.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","baseScore":7.4,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-13T19:31:57.701214Z","id":"CVE-2022-2533","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-287"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-287"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.10","versionEndExcluding":"15.1.6","matchCriteriaId":"BEAC3B50-A63C-41B6-9B8D-47D19C946777"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.10","versionEndExcluding":"15.1.6","matchCriteriaId":"554E3EC7-C042-4321-A86E-C68658E0A104"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.2","versionEndExcluding":"15.2.4","matchCriteriaId":"3D749C09-7157-4B87-9232-8E32F05C6655"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.2","versionEndExcluding":"15.2.4","matchCriteriaId":"B81CEDFB-EDCD-4298-8AEF-80C16422AE12"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.3","versionEndExcluding":"15.3.2","matchCriteriaId":"72FB7E61-B73F-4BBA-A1B4-FAFC9F351858"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.3","versionEndExcluding":"15.3.2","matchCriteriaId":"7D17D848-4F93-4E17-98E7-10DC30A5CCFE"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2533.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/363863","source":"cve@gitlab.com","tags":["Broken Link","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2533.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/363863","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-2592","sourceIdentifier":"cve@gitlab.com","published":"2022-10-17T16:15:21.263","lastModified":"2026-06-17T04:42:10.710","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A lack of length validation in Snippet descriptions in GitLab CE/EE affecting all versions prior to 15.1.6, 15.2 prior to 15.2.4 and 15.3 prior to 15.3.2 allows an authenticated attacker to create a maliciously large Snippet which when requested with or without authentication places excessive load on the server, potential leading to Denial of Service."},{"lang":"es","value":"Una falta de comprobación de la longitud en las descripciones de Snippet en GitLab CE/EE afectando a todas las versiones anteriores a 15.1.6, 15.2 anteriores a 15.2.4 y 15.3 anteriores a 15.3.2, permite a un atacante autenticado crear un Snippet maliciosamente grande que cuando son solicitados con o sin autenticación pone una carga excesiva en el servidor, lo que puede conllevar a una denegación de servicio"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.9.8, <15.1.6","status":"affected"},{"version":">=15.2, <15.2.4","status":"affected"},{"version":">=15.3, <15.3.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-13T19:16:23.870258Z","id":"CVE-2022-2592","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-1284"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-1284"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"15.1.6","matchCriteriaId":"4AD3082E-EC31-4A5E-BADB-23D9AA1C64E1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"15.1.6","matchCriteriaId":"F398204C-DEBD-4A66-A404-FD350D454738"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.2","versionEndExcluding":"15.2.4","matchCriteriaId":"3D749C09-7157-4B87-9232-8E32F05C6655"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.2","versionEndExcluding":"15.2.4","matchCriteriaId":"B81CEDFB-EDCD-4298-8AEF-80C16422AE12"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.3","versionEndExcluding":"15.3.2","matchCriteriaId":"72FB7E61-B73F-4BBA-A1B4-FAFC9F351858"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.3","versionEndExcluding":"15.3.2","matchCriteriaId":"7D17D848-4F93-4E17-98E7-10DC30A5CCFE"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2592.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/362566","source":"cve@gitlab.com","tags":["Broken Link","Third Party Advisory"]},{"url":"https://hackerone.com/reports/1544507","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2592.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/362566","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory"]},{"url":"https://hackerone.com/reports/1544507","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-2630","sourceIdentifier":"cve@gitlab.com","published":"2022-10-17T16:15:21.323","lastModified":"2026-06-17T04:42:14.777","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An improper access control issue in GitLab CE/EE affecting all versions starting from 15.2 before 15.2.4, all versions from 15.3 before 15.3.2 allows disclosure of confidential information via the Incident timeline events."},{"lang":"es","value":"Se ha detectado que EOS versión v2.1.0, contenía un desbordamiento del búfer de la pila por medio de la función txn_test_gen_plugin"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=15.2, <15.2.4","status":"affected"},{"version":">=15.3, <15.3.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-13T19:12:41.096945Z","id":"CVE-2022-2630","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.2","versionEndExcluding":"15.2.4","matchCriteriaId":"3D749C09-7157-4B87-9232-8E32F05C6655"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.2","versionEndExcluding":"15.2.4","matchCriteriaId":"B81CEDFB-EDCD-4298-8AEF-80C16422AE12"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.3","versionEndExcluding":"15.3.2","matchCriteriaId":"72FB7E61-B73F-4BBA-A1B4-FAFC9F351858"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.3","versionEndExcluding":"15.3.2","matchCriteriaId":"7D17D848-4F93-4E17-98E7-10DC30A5CCFE"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2630.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/369429","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://hackerone.com/reports/1652853","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2630.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/369429","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://hackerone.com/reports/1652853","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-2865","sourceIdentifier":"cve@gitlab.com","published":"2022-10-17T16:15:21.387","lastModified":"2026-06-17T04:42:44.113","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions before 15.1.6, 15.2 to 15.2.4 and 15.3 prior to 15.3.2. It was possible to exploit a vulnerability in setting the labels colour feature which could lead to a stored XSS that allowed attackers to perform arbitrary actions on behalf of victims at client side."},{"lang":"es","value":"Se ha detectado un problema de tipo cross-site scripting en GitLab CE/EE afectando a todas las versiones anteriores a 15.1.6, 15.2 a 15.2.4 y 15.3 anteriores a 15.3.2. Era posible explotar una vulnerabilidad en la configuración de la función de color de las etiquetas que podía conllevar a un ataque de tipo XSS almacenado que permitía a atacantes llevar a cabo acciones arbitrarias en nombre de las víctimas en el lado del cliente"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=9.0, <15.1.6","status":"affected"},{"version":">=15.2, <15.2.4","status":"affected"},{"version":">=15.3, <15.3.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:N","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.0,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N","baseScore":4.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.7,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-14T13:56:48.463701Z","id":"CVE-2022-2865","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"9.0.0","versionEndExcluding":"15.1.6","matchCriteriaId":"5A9F96AE-0B08-4A0E-A60C-CCBA691A38CB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"9.0.0","versionEndExcluding":"15.1.6","matchCriteriaId":"E729D58B-8660-41D2-B667-5D664CA4E92D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.2","versionEndExcluding":"15.2.4","matchCriteriaId":"3D749C09-7157-4B87-9232-8E32F05C6655"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.2","versionEndExcluding":"15.2.4","matchCriteriaId":"B81CEDFB-EDCD-4298-8AEF-80C16422AE12"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.3","versionEndExcluding":"15.3.2","matchCriteriaId":"72FB7E61-B73F-4BBA-A1B4-FAFC9F351858"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2865.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/370873","source":"cve@gitlab.com","tags":["Broken Link","Third Party Advisory"]},{"url":"https://hackerone.com/reports/1665658","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2865.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/370873","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory"]},{"url":"https://hackerone.com/reports/1665658","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-2884","sourceIdentifier":"cve@gitlab.com","published":"2022-10-17T16:15:21.453","lastModified":"2026-06-17T04:42:46.173","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an authenticated user to achieve remote code execution via the Import from GitHub API endpoint"},{"lang":"es","value":"Una vulnerabilidad en GitLab CE/EE afectando a todas las versiones desde la 11.3.4 anteriores a 15.1.5, desde la 15.2 a 15.2.3, desde la 15.3 a 15.3.1, permite a un usuario autenticado lograr una ejecución de código remota por medio del endpoint de la API Import from GitHub"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=11.3.4, <15.1.5","status":"affected"},{"version":">=15.2, <15.2.3","status":"affected"},{"version":">=15.3, <15.3.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":9.9,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.1,"impactScore":6.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":9.9,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.1,"impactScore":6.0}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-14T14:23:51.849841Z","id":"CVE-2022-2884","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-78"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-78"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.3.4","versionEndExcluding":"15.1.5","matchCriteriaId":"18FB513A-106E-4F22-AE3C-925910B73974"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.3.4","versionEndExcluding":"15.1.5","matchCriteriaId":"0650671A-D69C-4BA8-B127-2187953A981A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.2","versionEndExcluding":"15.2.3","matchCriteriaId":"76941E90-BEA1-4F0E-96F3-330C1496708F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.2","versionEndExcluding":"15.2.3","matchCriteriaId":"C09289D8-65AA-40EB-859A-723345B6162C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.3","versionEndExcluding":"15.3.1","matchCriteriaId":"110D4A9A-CEFA-412F-B117-E2BC03F268FA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.3","versionEndExcluding":"15.3.1","matchCriteriaId":"FED2BA5A-129B-4943-9E8C-464C6A6A1162"}]}]}],"references":[{"url":"http://packetstormsecurity.com/files/171628/GitLab-15.3-Remote-Code-Execution.html","source":"cve@gitlab.com"},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2884.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/371098","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://hackerone.com/reports/1672388","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"http://packetstormsecurity.com/files/171628/GitLab-15.3-Remote-Code-Execution.html","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2884.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/371098","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://hackerone.com/reports/1672388","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-2908","sourceIdentifier":"cve@gitlab.com","published":"2022-10-17T16:15:21.517","lastModified":"2026-06-17T04:42:48.710","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A potential DoS vulnerability was discovered in Gitlab CE/EE versions starting from 10.7 before 15.1.5, all versions starting from 15.2 before 15.2.3, all versions starting from 15.3 before 15.3.1 allowed an attacker to trigger high CPU usage via a special crafted input added in the Commit message field."},{"lang":"es","value":"Se ha detectado una potencial vulnerabilidad DoS en Gitlab CE/EE versiones a partir de 10.7 anteriores a 15.1.5, todas las versiones a partir de 15.2 anteriores a 15.2.3, todas las versiones a partir de 15.3 anteriores a 15.3.1, que permitía a un atacante desencadenar un alto uso de la CPU por medio de una entrada especialmente diseñada añadida en el campo de mensaje Commit"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=10.7, <15.1.5","status":"affected"},{"version":">=15.2, <15.2.3","status":"affected"},{"version":">=15.3, <15.3.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-13T19:10:50.957904Z","id":"CVE-2022-2908","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-1333"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-1333"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.7.0","versionEndExcluding":"15.1.5","matchCriteriaId":"B3603DDC-AF75-4674-888C-CBDB6C940F0C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.7.0","versionEndExcluding":"15.1.5","matchCriteriaId":"0A85E97A-C795-46D8-8977-4439281DA00F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.2","versionEndExcluding":"15.2.3","matchCriteriaId":"76941E90-BEA1-4F0E-96F3-330C1496708F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.2","versionEndExcluding":"15.2.3","matchCriteriaId":"C09289D8-65AA-40EB-859A-723345B6162C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.3","versionEndExcluding":"15.3.1","matchCriteriaId":"110D4A9A-CEFA-412F-B117-E2BC03F268FA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.3","versionEndExcluding":"15.3.1","matchCriteriaId":"FED2BA5A-129B-4943-9E8C-464C6A6A1162"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2908.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/363734","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://hackerone.com/reports/1584156","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2908.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/363734","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://hackerone.com/reports/1584156","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/363734","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-2931","sourceIdentifier":"cve@gitlab.com","published":"2022-10-17T16:15:21.580","lastModified":"2026-06-17T04:42:50.537","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. Malformed content added to the issue description could have been used to trigger high CPU usage."},{"lang":"es","value":"Se ha detectado una posible vulnerabilidad de DOS en GitLab CE/EE afectando todas las versiones anteriores a 15.1.6, todas las versiones a partir de 15.2 anteriores a 15.2.4 y a todas las versiones a partir de 15.3 anteriores a 15.3.2. El contenido malformado añadido a la descripción del problema podría haber sido usado para desencadenar un alto uso de la CPU"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":" <15.1.6","status":"affected"},{"version":">=15.2, <15.2.4","status":"affected"},{"version":">=15.3, <15.3.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-13T16:25:23.390059Z","id":"CVE-2022-2931","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-400"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"15.1.6","matchCriteriaId":"4AD3082E-EC31-4A5E-BADB-23D9AA1C64E1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"15.1.6","matchCriteriaId":"F398204C-DEBD-4A66-A404-FD350D454738"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.2","versionEndExcluding":"15.2.4","matchCriteriaId":"3D749C09-7157-4B87-9232-8E32F05C6655"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.2","versionEndExcluding":"15.2.4","matchCriteriaId":"B81CEDFB-EDCD-4298-8AEF-80C16422AE12"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.3","versionEndExcluding":"15.3.2","matchCriteriaId":"72FB7E61-B73F-4BBA-A1B4-FAFC9F351858"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.3","versionEndExcluding":"15.3.2","matchCriteriaId":"7D17D848-4F93-4E17-98E7-10DC30A5CCFE"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2931.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/361982","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://hackerone.com/reports/1543718","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2931.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/361982","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://hackerone.com/reports/1543718","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/361982","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-2992","sourceIdentifier":"cve@gitlab.com","published":"2022-10-17T16:15:21.640","lastModified":"2026-06-17T04:42:56.830","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated user to achieve remote code execution via the Import from GitHub API endpoint."},{"lang":"es","value":"Una vulnerabilidad en GitLab CE/EE afectando a todas las versiones desde la 11.10 anteriores a 15.1.6, desde la 15.2 hasta la 15.2.4, desde la 15.3 hasta la 15.3.2 permite a un usuario autenticado lograr la ejecución de código remota por medio del endpoint de la API Import from GitHub"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=11.10, <15.1.6","status":"affected"},{"version":">=15.2, <15.2.4","status":"affected"},{"version":">=15.3, <15.3.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":9.9,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.1,"impactScore":6.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":9.9,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.1,"impactScore":6.0}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-14T14:27:07.346076Z","id":"CVE-2022-2992","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-74"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-74"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.10","versionEndExcluding":"15.1.6","matchCriteriaId":"B3F9B079-6508-4B15-B42D-21D85FBA8FB2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.10","versionEndExcluding":"15.1.6","matchCriteriaId":"E58D36E5-D356-4286-A5A3-CB99D9464D33"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.2","versionEndExcluding":"15.2.4","matchCriteriaId":"3D749C09-7157-4B87-9232-8E32F05C6655"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.2","versionEndExcluding":"15.2.4","matchCriteriaId":"B81CEDFB-EDCD-4298-8AEF-80C16422AE12"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.3","versionEndExcluding":"15.3.2","matchCriteriaId":"72FB7E61-B73F-4BBA-A1B4-FAFC9F351858"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.3","versionEndExcluding":"15.3.2","matchCriteriaId":"7D17D848-4F93-4E17-98E7-10DC30A5CCFE"}]}]}],"references":[{"url":"http://packetstormsecurity.com/files/171008/GitLab-GitHub-Repo-Import-Deserialization-Remote-Code-Execution.html","source":"cve@gitlab.com"},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2992.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/371884","source":"cve@gitlab.com","tags":["Broken Link","Third Party Advisory"]},{"url":"https://hackerone.com/reports/1679624","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"http://packetstormsecurity.com/files/171008/GitLab-GitHub-Repo-Import-Deserialization-Remote-Code-Execution.html","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2992.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/371884","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory"]},{"url":"https://hackerone.com/reports/1679624","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-3030","sourceIdentifier":"cve@gitlab.com","published":"2022-10-17T16:15:21.947","lastModified":"2026-06-17T04:58:40.263","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An improper access control issue in GitLab CE/EE affecting all versions starting before 15.1.6, all versions from 15.2 before 15.2.4, all versions from 15.3 before 15.3.2 allows disclosure of pipeline status to unauthorized users."},{"lang":"es","value":"Un problema de control de acceso inapropiado en GitLab CE/EE afectando a todas las versiones a partir de 15.1.6, a todas las versiones a partir de 15.2 anteriores a 15.2.4, a todas las versiones a partir de 15.3 anteriores a 15.3.2 permite revelar el estado de las tuberías a usuarios no autorizados"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":"<15.1.6","status":"affected"},{"version":">=15.2, <15.2.4","status":"affected"},{"version":">=15.3, <15.3.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-13T16:21:36.682852Z","id":"CVE-2022-3030","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"15.1.6","matchCriteriaId":"4AD3082E-EC31-4A5E-BADB-23D9AA1C64E1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"15.1.6","matchCriteriaId":"F398204C-DEBD-4A66-A404-FD350D454738"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.2","versionEndExcluding":"15.2.4","matchCriteriaId":"3D749C09-7157-4B87-9232-8E32F05C6655"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.2","versionEndExcluding":"15.2.4","matchCriteriaId":"B81CEDFB-EDCD-4298-8AEF-80C16422AE12"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.3","versionEndExcluding":"15.3.2","matchCriteriaId":"72FB7E61-B73F-4BBA-A1B4-FAFC9F351858"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.3","versionEndExcluding":"15.3.2","matchCriteriaId":"7D17D848-4F93-4E17-98E7-10DC30A5CCFE"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3030.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/37959","source":"cve@gitlab.com","tags":["Broken Link","Third Party Advisory"]},{"url":"https://hackerone.com/reports/749882","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3030.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/37959","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory"]},{"url":"https://hackerone.com/reports/749882","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-3031","sourceIdentifier":"cve@gitlab.com","published":"2022-10-17T16:15:22.007","lastModified":"2026-06-17T04:58:40.380","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. It may be possible for an attacker to guess a user's password by brute force by sending crafted requests to a specific endpoint, even if the victim user has 2FA enabled on their account."},{"lang":"es","value":"Se ha detectado un problema en GitLab CE/EE afectando a todas las versiones anteriores a 15.1.6, a todas las versiones a partir de 15.2 anteriores a 15.2.4 y a todas las versiones a partir de 15.3 anteriores a 15.3.2. Es posible que un atacante adivine la contraseña de un usuario por fuerza bruta mediante el envío de peticiones diseñadas a un endpoint específico, incluso si el usuario víctima presenta 2FA habilitado en su cuenta"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=15.3, <15.3.2","status":"affected"},{"version":">=15.2, <15.2.4","status":"affected"},{"version":">=0.0, <15.1.6","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":3.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-13T16:20:40.064676Z","id":"CVE-2022-3031","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-307"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"15.1.6","matchCriteriaId":"4AD3082E-EC31-4A5E-BADB-23D9AA1C64E1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"15.1.6","matchCriteriaId":"F398204C-DEBD-4A66-A404-FD350D454738"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.2","versionEndExcluding":"15.2.4","matchCriteriaId":"3D749C09-7157-4B87-9232-8E32F05C6655"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.2","versionEndExcluding":"15.2.4","matchCriteriaId":"B81CEDFB-EDCD-4298-8AEF-80C16422AE12"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.3","versionEndExcluding":"15.3.2","matchCriteriaId":"72FB7E61-B73F-4BBA-A1B4-FAFC9F351858"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.3","versionEndExcluding":"15.3.2","matchCriteriaId":"7D17D848-4F93-4E17-98E7-10DC30A5CCFE"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3031.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/340395","source":"cve@gitlab.com","tags":["Broken Link","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3031.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/340395","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-3060","sourceIdentifier":"cve@gitlab.com","published":"2022-10-17T16:15:22.073","lastModified":"2026-06-17T04:58:44.800","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Improper control of a resource identifier in Error Tracking in GitLab CE/EE affecting all versions from 12.7 allows an authenticated attacker to generate content which could cause a victim to make unintended arbitrary requests"},{"lang":"es","value":"Un control inapropiado de un identificador de recurso en el seguimiento de errores en GitLab CE/EE, afectando a todas las versiones a partir de 12.7, permite que un atacante autenticado genere contenido que podría causar que una víctima realice peticiones arbitrarias no deseadas"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=15.4, <15.4.1","status":"affected"},{"version":">=15.3, <15.3.4","status":"affected"},{"version":">=12.7, <15.2.5","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-13T16:19:48.539119Z","id":"CVE-2022-3060","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-22"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-22"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndIncluding":"12.7.0","matchCriteriaId":"99A3A546-59D4-4C25-9FA4-0DE2798858B0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndIncluding":"12.7.0","matchCriteriaId":"8E7CDD55-EDE1-4F9C-80BC-08CF6E9A9460"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3060.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/365427","source":"cve@gitlab.com","tags":["Broken Link","Third Party Advisory"]},{"url":"https://hackerone.com/reports/1600343","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3060.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/365427","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory"]},{"url":"https://hackerone.com/reports/1600343","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-3066","sourceIdentifier":"cve@gitlab.com","published":"2022-10-17T16:15:22.137","lastModified":"2026-06-17T04:58:45.447","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 10.0 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. It was possible for an unauthorised user to create issues in a project."},{"lang":"es","value":"Se ha detectado un problema en GitLab afectando a todas las versiones a partir de 10.0 anteriores a 15.2.5, todas las versiones a partir de 15.3 anteriores a 15.3.4, todas las versiones a partir de 15.4 anteriores a 15.4.1. Era posible que un usuario no autorizado creara problemas en un proyecto"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=15.4, <15.4.1","status":"affected"},{"version":">=15.3, <15.3.4","status":"affected"},{"version":">=10.0, <15.2.5","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-13T16:18:30.291729Z","id":"CVE-2022-3066","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.0.0","versionEndExcluding":"15.2.5","matchCriteriaId":"C6380DF5-A56C-40CF-AD09-C09857436223"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.3","versionEndExcluding":"15.3.4","matchCriteriaId":"3A4CDDAE-AEDA-40D8-9D36-11535172233D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.4","versionEndExcluding":"15.4.1","matchCriteriaId":"1605D4DC-D7EA-42BC-B006-8A79C32781CE"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3066.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/372149","source":"cve@gitlab.com","tags":["Broken Link","Third Party Advisory"]},{"url":"https://hackerone.com/reports/1685105","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3066.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/372149","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory"]},{"url":"https://hackerone.com/reports/1685105","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-3067","sourceIdentifier":"cve@gitlab.com","published":"2022-10-17T16:15:22.200","lastModified":"2026-06-17T04:58:45.567","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in the Import functionality of GitLab CE/EE affecting all versions starting from 14.4 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. It was possible for an authenticated user to read arbitrary projects' content given the project's ID."},{"lang":"es","value":"Se ha detectado un problema en la funcionalidad de importación de GitLab CE/EE afectando a todas las versiones a partir de 14.4 anteriores a 15.2.5, a todas las versiones a partir de 15.3 anteriores a 15.3.4, a todas las versiones a partir de 15.4 anteriores a 15.4.1. Era posible que un usuario autenticado leyera el contenido de proyectos arbitrarios dado el ID del proyecto"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=15.4, <15.4.1","status":"affected"},{"version":">=15.3, <15.3.4","status":"affected"},{"version":">=14.4, <15.2.5","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-13T16:05:38.961847Z","id":"CVE-2022-3067","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.4","versionEndExcluding":"15.2.5","matchCriteriaId":"E052E9D4-A124-4C8D-B231-23824C54378C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.4","versionEndExcluding":"15.2.5","matchCriteriaId":"10D5A5C4-401E-496A-AACC-19B6A621E221"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.3","versionEndExcluding":"15.3.4","matchCriteriaId":"FA378384-D683-47B4-9AB2-28C565A954CB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.3","versionEndExcluding":"15.3.4","matchCriteriaId":"3A4CDDAE-AEDA-40D8-9D36-11535172233D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.4","versionEndExcluding":"15.4.1","matchCriteriaId":"71CE99C3-F315-4071-A1B2-FEACE6A3F049"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.4","versionEndExcluding":"15.4.1","matchCriteriaId":"1605D4DC-D7EA-42BC-B006-8A79C32781CE"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3067.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/372165","source":"cve@gitlab.com","tags":["Broken Link","Third Party Advisory"]},{"url":"https://hackerone.com/reports/1685822","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3067.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/372165","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory"]},{"url":"https://hackerone.com/reports/1685822","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://hackerone.com/reports/1685822","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-3279","sourceIdentifier":"cve@gitlab.com","published":"2022-10-17T16:15:22.330","lastModified":"2026-06-17T04:59:12.983","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An unhandled exception in job log parsing in GitLab CE/EE affecting all versions prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an attacker to prevent access to job logs"},{"lang":"es","value":"Una excepción no manejada en el análisis del registro de trabajos en GitLab CE/EE afectando a todas las versiones anteriores a 15.2.5, a la 15.3 anteriores a 15.3.4 y a la 15.4 anteriores a 15.4.1 permite a un atacante impedir el acceso a los registros de trabajos"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":"<15.2.5","status":"affected"},{"version":">=15.3, <15.3.4","status":"affected"},{"version":">=15.4, <15.4.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L","baseScore":2.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":1.2,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-13T15:49:59.670461Z","id":"CVE-2022-3279","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-755"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-755"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"15.2.5","matchCriteriaId":"D5D2A977-BB2E-406A-8EF4-A21C271678F3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"15.2.5","matchCriteriaId":"C3662260-5645-41E0-AA03-7FD57F06C617"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.3","versionEndExcluding":"15.3.4","matchCriteriaId":"FA378384-D683-47B4-9AB2-28C565A954CB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.3","versionEndExcluding":"15.3.4","matchCriteriaId":"3A4CDDAE-AEDA-40D8-9D36-11535172233D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.4","versionEndExcluding":"15.4.1","matchCriteriaId":"71CE99C3-F315-4071-A1B2-FEACE6A3F049"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.4","versionEndExcluding":"15.4.1","matchCriteriaId":"1605D4DC-D7EA-42BC-B006-8A79C32781CE"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3279.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/364249","source":"cve@gitlab.com","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1587261","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3279.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/364249","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1587261","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/364249","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Broken Link","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2022-3283","sourceIdentifier":"cve@gitlab.com","published":"2022-10-17T16:15:22.390","lastModified":"2026-06-17T04:59:13.560","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions before before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1 While cloning an issue with special crafted content added to the description could have been used to trigger high CPU usage."},{"lang":"es","value":"Se ha detectado una potencial vulnerabilidad de DOS en GitLab CE/EE afectando a todas las versiones anteriores a 15.2.5, a todas las versiones a partir de 15.3 anteriores a 15.3.4, a todas las versiones a partir de 15.4 anteriores a 15.4.1 Mientras era clonado un problema con contenido especialmente diseñado añadido a la descripción podría haberse usado para desencadenar un alto uso de la CPU"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=15.4, <15.4.1","status":"affected"},{"version":">=15.3, <15.3.4","status":"affected"},{"version":"<15.2.5","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-13T15:45:58.265219Z","id":"CVE-2022-3283","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-400"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-400"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"15.2.5","matchCriteriaId":"D5D2A977-BB2E-406A-8EF4-A21C271678F3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"15.2.5","matchCriteriaId":"C3662260-5645-41E0-AA03-7FD57F06C617"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.3","versionEndExcluding":"15.3.4","matchCriteriaId":"FA378384-D683-47B4-9AB2-28C565A954CB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.3","versionEndExcluding":"15.3.4","matchCriteriaId":"3A4CDDAE-AEDA-40D8-9D36-11535172233D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.4","versionEndExcluding":"15.4.1","matchCriteriaId":"71CE99C3-F315-4071-A1B2-FEACE6A3F049"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.4","versionEndExcluding":"15.4.1","matchCriteriaId":"1605D4DC-D7EA-42BC-B006-8A79C32781CE"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3283.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/361982","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1543718","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3283.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/361982","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1543718","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-3286","sourceIdentifier":"cve@gitlab.com","published":"2022-10-17T16:15:22.447","lastModified":"2026-06-17T04:59:13.900","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Lack of IP address checking in GitLab EE affecting all versions from 14.2 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows a group member to bypass IP restrictions when using a deploy token"},{"lang":"es","value":"Una falta de comprobación de la dirección IP en GitLab EE, afectando a todas las versiones desde la 14.2 anteriores a 15.2.5, la 15.3 anteriores a 15.3.4 y la 15.4 anteriores a 15.4.1, permite a un miembro del grupo omitir las restricciones de IP cuando usa un token de despliegue"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=14.2, <15.2.5","status":"affected"},{"version":">=15.3, <15.3.4","status":"affected"},{"version":">=15.4, <15.4.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-13T15:45:05.237283Z","id":"CVE-2022-3286","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.2","versionEndExcluding":"15.2.5","matchCriteriaId":"2F071B0A-EB4F-448A-8DDD-86D5D3188659"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.3","versionEndExcluding":"15.3.4","matchCriteriaId":"3A4CDDAE-AEDA-40D8-9D36-11535172233D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.4","versionEndExcluding":"15.4.1","matchCriteriaId":"1605D4DC-D7EA-42BC-B006-8A79C32781CE"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3286.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/363827","source":"cve@gitlab.com","tags":["Broken Link","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3286.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/363827","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/363827","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Broken Link","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2022-3288","sourceIdentifier":"cve@gitlab.com","published":"2022-10-17T16:15:22.507","lastModified":"2026-06-17T04:59:14.160","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A branch/tag name confusion in GitLab CE/EE affecting all versions prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an attacker to manipulate pages where the content of the default branch would be expected."},{"lang":"es","value":"Una confusión de nombre de rama/etiqueta en GitLab CE/EE afectando a todas las versiones anteriores a 15.2.5, a la 15.3 anteriores a 15.3.4 y a la 15.4 anteriores a 15.4.1 permite a un atacante manipular páginas donde era esperado el contenido de la rama por defecto"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":"<15.2.5","status":"affected"},{"version":">=15.3, <15.3.4","status":"affected"},{"version":">=15.4, <15.4.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N","baseScore":3.5,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-13T15:43:30.626369Z","id":"CVE-2022-3288","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-471"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"15.2.5","matchCriteriaId":"D5D2A977-BB2E-406A-8EF4-A21C271678F3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"15.2.5","matchCriteriaId":"C3662260-5645-41E0-AA03-7FD57F06C617"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.3","versionEndExcluding":"15.3.4","matchCriteriaId":"FA378384-D683-47B4-9AB2-28C565A954CB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.3","versionEndExcluding":"15.3.4","matchCriteriaId":"3A4CDDAE-AEDA-40D8-9D36-11535172233D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.4","versionEndExcluding":"15.4.1","matchCriteriaId":"71CE99C3-F315-4071-A1B2-FEACE6A3F049"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.4","versionEndExcluding":"15.4.1","matchCriteriaId":"1605D4DC-D7EA-42BC-B006-8A79C32781CE"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3288.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/354948","source":"cve@gitlab.com","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1498354","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3288.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/354948","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1498354","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/354948","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Broken Link","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2022-3291","sourceIdentifier":"cve@gitlab.com","published":"2022-10-17T16:15:22.567","lastModified":"2026-06-17T04:59:14.393","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Serialization of sensitive data in GitLab EE affecting all versions from 14.9 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 can leak sensitive information via cache"},{"lang":"es","value":"Una serialización de datos confidenciales en GitLab EE afectando a todas las versiones desde la 14.9 anteriores a 15.2.5, la 15.3 anteriores a 15.3.4 y la 15.4 anteriores a 15.4.1 puede filtrar información confidencial por medio de la caché"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=14.9, <15.2.5","status":"affected"},{"version":">=15.3, <15.3.4","status":"affected"},{"version":">=15.4, <15.4.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-13T15:42:20.537942Z","id":"CVE-2022-3291","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-502"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-502"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.9","versionEndExcluding":"15.2.5","matchCriteriaId":"0E1D81D0-5DF4-4FB0-88F9-CCDBD1168CC4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.3","versionEndExcluding":"15.3.4","matchCriteriaId":"3A4CDDAE-AEDA-40D8-9D36-11535172233D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.4","versionEndExcluding":"15.4.1","matchCriteriaId":"1605D4DC-D7EA-42BC-B006-8A79C32781CE"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3291.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/354299","source":"cve@gitlab.com","tags":["Broken Link","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3291.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/354299","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2022-3293","sourceIdentifier":"cve@gitlab.com","published":"2022-10-17T16:15:22.627","lastModified":"2026-06-17T04:59:14.627","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Email addresses were leaked in WebHook logs in GitLab EE affecting all versions from 9.3 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1"},{"lang":"es","value":"Fueron filtrados direcciones de correo electrónico en los registros de WebHook en GitLab EE afectando a todas las versiones desde la 9.3 anteriores a 15.2.5, la 15.3 anteriores a 15.3.4 y la 15.4 anteriores a 15.4.1"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=9.3, <15.2.5","status":"affected"},{"version":">=15.3, <15.3.4","status":"affected"},{"version":">=15.4, <15.4.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N","baseScore":3.5,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-13T15:39:21.081015Z","id":"CVE-2022-3293","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-532"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-532"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"9.3","versionEndExcluding":"15.2.5","matchCriteriaId":"CD4BFD4D-A7FD-4673-99F8-B82C74CAFDB4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.3","versionEndExcluding":"15.3.4","matchCriteriaId":"3A4CDDAE-AEDA-40D8-9D36-11535172233D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.4","versionEndExcluding":"15.4.1","matchCriteriaId":"1605D4DC-D7EA-42BC-B006-8A79C32781CE"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3293.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/369008","source":"cve@gitlab.com","tags":["Broken Link","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3293.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/369008","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/369008","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Broken Link","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2022-3325","sourceIdentifier":"cve@gitlab.com","published":"2022-10-17T16:15:22.687","lastModified":"2026-06-17T04:59:18.597","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Improper access control in the GitLab CE/EE API affecting all versions starting from 12.8 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. Allowed for editing the approval rules via the API by an unauthorised user."},{"lang":"es","value":"Control de acceso inapropiado en la API de GitLab CE/EE afectando a todas las versiones a partir de 12.8 anteriores a 15.2.5, a todas las versiones a partir de 15.3 anteriores a 15.3.4, a todas las versiones a partir de 15.4 anteriores a 15.4.1. Permitido editar las reglas de aprobación por medio de la API por un usuario no autorizado"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=15.4, <15.4.1","status":"affected"},{"version":">=15.3, <15.3.4","status":"affected"},{"version":">=12.8, <15.2.5","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N","baseScore":2.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-13T15:36:08.270836Z","id":"CVE-2022-3325","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.8.0","versionEndExcluding":"15.2.5","matchCriteriaId":"24686DBA-D8BB-436A-8B59-F12915465FAB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.8.0","versionEndExcluding":"15.2.5","matchCriteriaId":"8BD8CE89-5C71-4ACC-994E-0A06B9A9A208"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.3","versionEndExcluding":"15.3.4","matchCriteriaId":"FA378384-D683-47B4-9AB2-28C565A954CB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.3","versionEndExcluding":"15.3.4","matchCriteriaId":"3A4CDDAE-AEDA-40D8-9D36-11535172233D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.4","versionEndExcluding":"15.4.1","matchCriteriaId":"71CE99C3-F315-4071-A1B2-FEACE6A3F049"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.4","versionEndExcluding":"15.4.1","matchCriteriaId":"1605D4DC-D7EA-42BC-B006-8A79C32781CE"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3325.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/360819","source":"cve@gitlab.com","tags":["Broken Link","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3325.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/360819","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/360819","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Broken Link","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2022-3330","sourceIdentifier":"cve@gitlab.com","published":"2022-10-17T16:15:22.757","lastModified":"2026-06-17T04:59:19.053","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"It was possible for a guest user to read a todo targeting an inaccessible note in Gitlab CE/EE affecting all versions from 15.0 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1."},{"lang":"es","value":"Era posible que un usuario invitado leyera una tarea dirigida a una nota inaccesible en Gitlab CE/EE, lo que afectaba a todas las versiones desde la 15.0 hasta la 15.2.5, la 15.3 hasta la 15.3.4 y la 15.4 hasta la 15.4.1"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=15.0, <15.2.5","status":"affected"},{"version":">=15.3, <15.3.4","status":"affected"},{"version":">=15.4, <15.4.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-14T20:17:40.285279Z","id":"CVE-2022-3330","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.0.0","versionEndExcluding":"15.2.5","matchCriteriaId":"8D70F069-31A1-4BE1-AC8B-71DDD647F567"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.0.0","versionEndExcluding":"15.2.5","matchCriteriaId":"8BA9224F-66EE-4733-A60C-B07CF0ABF610"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.3","versionEndExcluding":"15.3.4","matchCriteriaId":"FA378384-D683-47B4-9AB2-28C565A954CB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.3","versionEndExcluding":"15.3.4","matchCriteriaId":"3A4CDDAE-AEDA-40D8-9D36-11535172233D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.4","versionEndExcluding":"15.4.1","matchCriteriaId":"71CE99C3-F315-4071-A1B2-FEACE6A3F049"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.4","versionEndExcluding":"15.4.1","matchCriteriaId":"1605D4DC-D7EA-42BC-B006-8A79C32781CE"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3330.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/365827","source":"cve@gitlab.com","tags":["Broken Link","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3330.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/365827","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2022-3331","sourceIdentifier":"cve@gitlab.com","published":"2022-10-17T16:15:22.827","lastModified":"2026-06-17T04:59:19.163","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions starting from 14.5 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. GitLab's Zentao integration has an insecure direct object reference vulnerability that may be exploited by an attacker to leak Zentao project issues."},{"lang":"es","value":"Se ha detectado un problema en GitLab EE afectando a todas las versiones a partir de 14.5 anteriores a 15.1.6, todas las versiones a partir de 15.2 anteriores a 15.2.4, todas las versiones a partir de 15.3 anteriores a 15.3.2. La integración con Zentao de GitLab presenta una vulnerabilidad de referencia directa a objetos no segura que puede ser explotada por un atacante para filtrar los problemas de los proyectos de Zentao"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=14.5, <15.1.6","status":"affected"},{"version":">=15.2, <15.2.4","status":"affected"},{"version":">=15.3, <15.3.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N","baseScore":3.5,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-14T20:18:42.403947Z","id":"CVE-2022-3331","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-639"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-639"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.5","versionEndExcluding":"15.1.6","matchCriteriaId":"7495D743-6CB7-4908-B247-2EF5170004C6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.2","versionEndExcluding":"15.2.4","matchCriteriaId":"B81CEDFB-EDCD-4298-8AEF-80C16422AE12"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.3","versionEndExcluding":"15.3.2","matchCriteriaId":"7D17D848-4F93-4E17-98E7-10DC30A5CCFE"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3331.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/360372","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1542834","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3331.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/360372","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1542834","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-3351","sourceIdentifier":"cve@gitlab.com","published":"2022-10-17T16:15:22.900","lastModified":"2026-06-17T04:59:21.680","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions starting from 13.7 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. A user's primary email may be disclosed to an attacker through group member events webhooks."},{"lang":"es","value":"Se ha detectado un problema en GitLab EE afectando a todas las versiones a partir de 13.7 anteriores a 15.2.5, a todas las versiones a partir de 15.3 anteriores a 15.3.4, a todas las versiones a partir de 15.4 anteriores a 15.4.1. El correo electrónico principal de un usuario puede ser divulgado a un atacante mediante los webhooks de eventos de miembros del grupo"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=15.4, <15.4.1","status":"affected"},{"version":">=15.3, <15.3.4","status":"affected"},{"version":">=13.7, <15.2.5","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-14T20:22:29.268837Z","id":"CVE-2022-3351","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"15.2.5","matchCriteriaId":"3073D046-63A0-4514-8398-93E0DF38CBFF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.3","versionEndExcluding":"15.3.4","matchCriteriaId":"3A4CDDAE-AEDA-40D8-9D36-11535172233D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.4","versionEndExcluding":"15.4.1","matchCriteriaId":"1605D4DC-D7EA-42BC-B006-8A79C32781CE"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3351.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/364266","source":"cve@gitlab.com","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1446022","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3351.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/364266","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1446022","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-3639","sourceIdentifier":"cve@gitlab.com","published":"2022-10-21T16:15:11.253","lastModified":"2026-06-17T04:59:55.930","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 10.8 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. Improper data handling on branch creation could have been used to trigger high CPU usage."},{"lang":"es","value":"Se ha detectado una potencial vulnerabilidad de DOS en GitLab CE/EE que afecta a todas las versiones desde la 10.8 anteriores a 15.1.6, a todas las versiones desde la 15.2 anteriores a 15.2.4, a todas las versiones desde la 15.3 anteriores a 15.3.2. Un manejo inapropiado de los datos en la creación de la rama podría haber sido usado para desencadenar un alto uso de la CPU"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=10.8, <15.1.6","status":"affected"},{"version":">=15.2, <15.2.4","status":"affected"},{"version":">=15.3, <15.3.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-07T14:52:53.522601Z","id":"CVE-2022-3639","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-400"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-400"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"10.8.0","versionEndExcluding":"15.1.6","matchCriteriaId":"DBE8F371-4F0B-4297-B371-B1F9EBD9CE84"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"15.2","versionEndExcluding":"15.2.4","matchCriteriaId":"6A8BAF85-89E6-4076-BC77-68B373A55131"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"15.3","versionEndExcluding":"15.3.2","matchCriteriaId":"AA27BF5F-F6D1-4844-9B0A-05B899611DF7"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3639.json","source":"cve@gitlab.com","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/366876","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3639.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/366876","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2022-2882","sourceIdentifier":"cve@gitlab.com","published":"2022-10-28T15:15:15.467","lastModified":"2026-06-17T04:42:45.767","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. A malicious maintainer could exfiltrate a GitHub integration's access token by modifying the integration URL such that authenticated requests are sent to an attacker controlled server."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde 12.6 anteriores a 15.2.5, todas las versiones desde 15.3 anteriores a 15.3.4, todas las versiones desde 15.4 anteriores a 15.4.1. Un mantenedor malicioso podría filtrar el token de acceso de una integración de GitHub modificando la URL de la integración de modo que las solicitudes autenticadas se envíen a un servidor controlado por el atacante."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.6, <15.2.5","status":"affected"},{"version":">=15.3, <15.3.4","status":"affected"},{"version":">=15.4, <15.4.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-07T15:08:33.246411Z","id":"CVE-2022-2882","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-668"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-668"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.6.0","versionEndExcluding":"15.2.5","matchCriteriaId":"ADA33F4D-ECC9-4E02-856D-4907DB5B80AD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.6.0","versionEndExcluding":"15.2.5","matchCriteriaId":"2D7332D2-8652-4F29-BB39-97D8B4E99607"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.3","versionEndExcluding":"15.3.4","matchCriteriaId":"FA378384-D683-47B4-9AB2-28C565A954CB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.3","versionEndExcluding":"15.3.4","matchCriteriaId":"3A4CDDAE-AEDA-40D8-9D36-11535172233D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.4","versionEndExcluding":"15.4.1","matchCriteriaId":"71CE99C3-F315-4071-A1B2-FEACE6A3F049"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.4","versionEndExcluding":"15.4.1","matchCriteriaId":"1605D4DC-D7EA-42BC-B006-8A79C32781CE"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2882.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/371082","source":"cve@gitlab.com","tags":["Broken Link","Third Party Advisory"]},{"url":"https://hackerone.com/reports/1656722","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2882.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/371082","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory"]},{"url":"https://hackerone.com/reports/1656722","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/371082","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Broken Link","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-3018","sourceIdentifier":"cve@gitlab.com","published":"2022-10-28T15:15:15.787","lastModified":"2026-06-17T04:58:39.080","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An information disclosure vulnerability in GitLab CE/EE affecting all versions starting from 9.3 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1 allows a project maintainer to access the DataDog integration API key from webhook logs."},{"lang":"es","value":"Una vulnerabilidad de divulgación de información en GitLab CE/EE que afecta a todas las versiones desde 9.3 anteriores a 15.2.5, todas las versiones desde 15.3 anteriores a 15.3.4, todas las versiones desde 15.4 anteriores a 15.4.1 permite que un mantenedor de proyecto acceda a la clave API de integración de DataDog de los registros de webhook."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=15.4, <15.4.1","status":"affected"},{"version":">=15.3, <15.3.4","status":"affected"},{"version":">=9.3, <15.2.5","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N","baseScore":6.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":4.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-07T14:36:05.502768Z","id":"CVE-2022-3018","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-532"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-532"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"9.3.0","versionEndExcluding":"15.2.5","matchCriteriaId":"50C59C5F-ED0F-451C-9FEA-245972F7DC9C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"9.3.0","versionEndExcluding":"15.2.5","matchCriteriaId":"01341B49-92F7-48EC-A6BB-9C2E7DF5BA7F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.3","versionEndExcluding":"15.3.4","matchCriteriaId":"FA378384-D683-47B4-9AB2-28C565A954CB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.3","versionEndExcluding":"15.3.4","matchCriteriaId":"3A4CDDAE-AEDA-40D8-9D36-11535172233D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.4","versionEndExcluding":"15.4.1","matchCriteriaId":"71CE99C3-F315-4071-A1B2-FEACE6A3F049"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.4","versionEndExcluding":"15.4.1","matchCriteriaId":"1605D4DC-D7EA-42BC-B006-8A79C32781CE"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3018.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/360938","source":"cve@gitlab.com","tags":["Broken Link","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3018.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/360938","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-2826","sourceIdentifier":"cve@gitlab.com","published":"2022-10-28T22:15:09.963","lastModified":"2026-06-17T04:42:39.327","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 10.0 before 12.9.8, all versions starting from 12.10 before 12.10.7, all versions starting from 13.0 before 13.0.1. TODO"},{"lang":"es","value":"Se ha descubierto un problema en GitLab que afecta a todas las versiones desde 10.0 anteriores a 12.9.8, todas las versiones desde 12.10 anteriores a 12.10.7, todas las versiones desde 13.0 anteriores a 13.0.1. TODO\n"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=10.0, <12.9.8","status":"affected"},{"version":">=12.10, <12.10.7","status":"affected"},{"version":">=13.0, <13.0.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N","baseScore":2.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-07T15:23:50.306955Z","id":"CVE-2022-2826","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.0.0","versionEndExcluding":"12.9.8","matchCriteriaId":"EE874257-7013-4DD6-A65C-4FF8BB42A130"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.10.0","versionEndExcluding":"12.10.7","matchCriteriaId":"846CD4C7-BFCB-4DFC-901E-46CCA8ADA56A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:13.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"F6CA871C-BEFF-4951-AC88-ACA603C25CE1"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2826.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/370790","source":"cve@gitlab.com","tags":["Broken Link","Third Party Advisory"]},{"url":"https://hackerone.com/reports/1646633","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2826.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/370790","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory"]},{"url":"https://hackerone.com/reports/1646633","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-2904","sourceIdentifier":"cve@gitlab.com","published":"2022-11-02T20:15:09.950","lastModified":"2026-06-17T04:42:48.217","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions starting from 15.2 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1 It was possible to exploit a vulnerability in the external status checks feature which could lead to a stored XSS that allowed attackers to perform arbitrary actions on behalf of victims at client side."},{"lang":"es","value":"Se descubrió un problema de Cross-Site Scripting (XSS) en GitLab CE/EE que afecta a todas las versiones desde 15.2 anteriores a 15.2.5, todas las versiones desde 15.3 anteriores a 15.3.4, todas las versiones desde 15.4 anteriores a 15.4.1. Fue posible explotar una vulnerabilidad en la función de verificación de estado externa que podría conducir a un XSS almacenado que permitiera a los atacantes realizar acciones arbitrarias en nombre de las víctimas en el lado del cliente."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=15.4, <15.4.1","status":"affected"},{"version":">=15.3, <15.3.4","status":"affected"},{"version":">=15.2, <15.2.5","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:N","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.0,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-02T18:46:43.996354Z","id":"CVE-2022-2904","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.2","versionEndExcluding":"15.2.5","matchCriteriaId":"67DD8B25-B5C8-4DBC-9921-7F951090910D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.2","versionEndIncluding":"15.2.5","matchCriteriaId":"80BE5142-0A0C-48A5-B3D7-B83B15C7AEC8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.3","versionEndExcluding":"15.3.4","matchCriteriaId":"FA378384-D683-47B4-9AB2-28C565A954CB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.3","versionEndIncluding":"15.3.4","matchCriteriaId":"DC8DDF7C-4E81-47A4-AA91-EAA5FD1E563A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.4:*:*:*:community:*:*:*","matchCriteriaId":"3B0C3B60-C9AA-49C8-9B62-491FC2335D40"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.4:*:*:*:enterprise:*:*:*","matchCriteriaId":"8AB37811-871C-4488-B051-AAB138BC4ED4"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2904.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/367408","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1628009","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2904.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/367408","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1628009","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-2761","sourceIdentifier":"cve@gitlab.com","published":"2022-11-09T23:15:09.920","lastModified":"2026-06-17T04:42:31.957","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An information disclosure issue in GitLab CE/EE affecting all versions from 14.4 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to use GitLab Flavored Markdown (GFM) references in a Jira issue to disclose the names of resources they don't have access to."},{"lang":"es","value":"Un problema de divulgación de información en GitLab CE/EE que afecta a todas las versiones desde 14.4 anterior a 15.3.5, 15.4 anterior a 15.4.4 y 15.5 anterior a 15.5.2 permite a un atacante utilizar referencias de GitLab Flavored Markdown (GFM) en un problema en una edición de Jira para revelar los nombres de los recursos a los que no tienen acceso."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.9, <15.3.5","status":"affected"},{"version":">=15.4, <15.4.4","status":"affected"},{"version":">=15.5, <15.5.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-01T19:35:28.843532Z","id":"CVE-2022-2761","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.9.0","versionEndExcluding":"15.3.5","matchCriteriaId":"D42B2A89-803F-446D-A1CD-0D963BF09DA1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.9.0","versionEndExcluding":"15.3.5","matchCriteriaId":"7C5E2E54-7829-4393-ACFC-C867E4AA2248"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.4.0","versionEndExcluding":"15.4.4","matchCriteriaId":"ABE6E41B-B7AD-4081-99BC-5DD7A1280014"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.4.0","versionEndExcluding":"15.4.4","matchCriteriaId":"2FBFF5F6-6C42-4E64-8177-1BED65D38B00"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.5.0","versionEndExcluding":"15.5.2","matchCriteriaId":"127C9D37-25F3-479F-980C-9F5B6E818523"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.5.0","versionEndExcluding":"15.5.2","matchCriteriaId":"CE5ABA53-66D4-4BDE-BE64-AB45EFDADE24"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2761.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/370458","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1653149","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2761.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/370458","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1653149","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-3265","sourceIdentifier":"cve@gitlab.com","published":"2022-11-09T23:15:13.187","lastModified":"2026-06-17T04:59:11.190","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. It was possible to exploit a vulnerability in setting the labels colour feature which could lead to a stored XSS that allowed attackers to perform arbitrary actions on behalf of victims at client side."},{"lang":"es","value":"Se descubrió un problema de Cross-Site Scripting (XSS) en GitLab CE/EE que afecta a todas las versiones anteriores a 15.3.5, 15.4 anteriores a 15.4.4 y 15.5 anteriores a 15.5.2. Fue posible explotar una vulnerabilidad al configurar la función de color de las etiquetas, lo que podría conducir a un XSS almacenado que permitiera a los atacantes realizar acciones arbitrarias en nombre de las víctimas en el lado del cliente."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":"<15.3.5","status":"affected"},{"version":">=15.4, <15.4.4","status":"affected"},{"version":">=15.5, <15.5.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:N","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.0,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-01T19:25:51.228831Z","id":"CVE-2022-3265","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"15.3.5","matchCriteriaId":"129FF0B7-CB2A-42DD-A089-33D1AD8E31ED"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"15.3.5","matchCriteriaId":"E6F25E37-3A83-49C5-8388-F7E35933D9BD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.4.0","versionEndExcluding":"15.4.4","matchCriteriaId":"ABE6E41B-B7AD-4081-99BC-5DD7A1280014"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.4.0","versionEndExcluding":"15.4.4","matchCriteriaId":"2FBFF5F6-6C42-4E64-8177-1BED65D38B00"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.5.0","versionEndExcluding":"15.5.2","matchCriteriaId":"127C9D37-25F3-479F-980C-9F5B6E818523"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.5.0","versionEndExcluding":"15.5.2","matchCriteriaId":"CE5ABA53-66D4-4BDE-BE64-AB45EFDADE24"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3265.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/374976","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1693150","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3265.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/374976","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1693150","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-3280","sourceIdentifier":"cve@gitlab.com","published":"2022-11-09T23:15:13.613","lastModified":"2026-06-17T04:59:13.117","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An open redirect in GitLab CE/EE affecting all versions from 10.1 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to trick users into visiting a trustworthy URL and being redirected to arbitrary content."},{"lang":"es","value":"Una redirección abierta en GitLab CE/EE que afecta a todas las versiones desde 10.1 anterior a 15.3.5, 15.4 anterior a 15.4.4 y 15.5 anterior a 15.5.2 permite a un atacante engañar a los usuarios para que visiten una URL confiable y sean redirigidos a contenido arbitrario."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=10.1, <15.3.5","status":"affected"},{"version":">=15.4, <15.4.4","status":"affected"},{"version":">=15.5, <15.5.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N","baseScore":3.5,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-01T19:25:07.752906Z","id":"CVE-2022-3280","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-601"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-601"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.1.0","versionEndExcluding":"15.3.5","matchCriteriaId":"A53292F8-BB34-4900-A830-B7510B18ABD1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.1.0","versionEndExcluding":"15.3.5","matchCriteriaId":"B18120C3-219F-4FE6-8D90-57B5609FF24D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.4.0","versionEndExcluding":"15.4.4","matchCriteriaId":"ABE6E41B-B7AD-4081-99BC-5DD7A1280014"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.4.0","versionEndExcluding":"15.4.4","matchCriteriaId":"2FBFF5F6-6C42-4E64-8177-1BED65D38B00"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.5.0","versionEndExcluding":"15.5.2","matchCriteriaId":"127C9D37-25F3-479F-980C-9F5B6E818523"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.5.0","versionEndExcluding":"15.5.2","matchCriteriaId":"CE5ABA53-66D4-4BDE-BE64-AB45EFDADE24"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3280.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/352611","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1475686","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3280.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/352611","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1475686","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-3285","sourceIdentifier":"cve@gitlab.com","published":"2022-11-09T23:15:14.013","lastModified":"2026-06-17T04:59:13.790","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Bypass of healthcheck endpoint allow list affecting all versions from 12.0 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an unauthorized attacker to prevent access to GitLab"},{"lang":"es","value":"Omitir la lista de permitidos del endpoint de Healthcheck que afecta a todas las versiones desde 12.0 anterior a 15.2.5, 15.3 anterior a 15.3.4 y 15.4 anterior a 15.4.1 permite a un atacante no autorizado impedir el acceso a GitLab"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.0, <15.2.5","status":"affected"},{"version":">=15.3, <15.3.4","status":"affected"},{"version":">=15.4, <15.4.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-01T19:24:24.537646Z","id":"CVE-2022-3285","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.0.0","versionEndExcluding":"15.2.5","matchCriteriaId":"9D716D44-EF29-4B26-A9E0-14321CB1B68A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.0.0","versionEndExcluding":"15.2.5","matchCriteriaId":"2AB1CA1A-7F59-4959-9EB8-698FA698BCF7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.3.0","versionEndExcluding":"15.3.4","matchCriteriaId":"B61A660E-9E09-4C01-96BC-7F3329F725B7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.3.0","versionEndExcluding":"15.3.4","matchCriteriaId":"591A49FA-92CD-4820-9D16-B44B7EAE1804"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.4.0:*:*:*:community:*:*:*","matchCriteriaId":"2BEA307F-4230-423F-AD7D-9325E717BDA8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.4.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"781CCE7B-E9AD-46B8-8A4E-33C610B63111"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3285.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/security/omnibus-gitlab/-/issues/64","source":"cve@gitlab.com","tags":["Permissions Required","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3285.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/security/omnibus-gitlab/-/issues/64","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2022-3483","sourceIdentifier":"cve@gitlab.com","published":"2022-11-09T23:15:14.413","lastModified":"2026-06-17T04:59:36.857","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.1 before 15.3.5, all versions starting from 15.4 before 15.4.4, all versions starting from 15.5 before 15.5.2. A malicious maintainer could exfiltrate a Datadog integration's access token by modifying the integration URL such that authenticated requests are sent to an attacker controlled server."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde 12.1 anteriores a 15.3.5, todas las versiones desde 15.4 anteriores a 15.4.4, todas las versiones desde 15.5 anteriores a 15.5.2. Un mantenedor malicioso podría filtrar el token de acceso de una integración de Datadog modificando la URL de integración de manera que las solicitudes autenticadas se envíen a un servidor controlado por el atacante."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.1, <15.3.5","status":"affected"},{"version":">=15.4, <15.4.4","status":"affected"},{"version":">=15.5, <15.5.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-01T19:28:33.299343Z","id":"CVE-2022-3483","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"15.3.5","matchCriteriaId":"C7885BCA-BA0B-4205-B633-B11D9CBDBFB5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"15.3.5","matchCriteriaId":"23A33565-23F6-4CB0-9B63-B5D8F28C4E66"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.4.0","versionEndExcluding":"15.4.4","matchCriteriaId":"ABE6E41B-B7AD-4081-99BC-5DD7A1280014"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.4.0","versionEndExcluding":"15.4.4","matchCriteriaId":"2FBFF5F6-6C42-4E64-8177-1BED65D38B00"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.5.0","versionEndExcluding":"15.5.2","matchCriteriaId":"127C9D37-25F3-479F-980C-9F5B6E818523"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.5.0","versionEndExcluding":"15.5.2","matchCriteriaId":"CE5ABA53-66D4-4BDE-BE64-AB45EFDADE24"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3483.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/377799","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1724402","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3483.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/377799","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1724402","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-3486","sourceIdentifier":"cve@gitlab.com","published":"2022-11-09T23:15:14.973","lastModified":"2026-06-17T04:59:37.230","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An open redirect vulnerability in GitLab EE/CE affecting all versions from 9.3 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2, allows an attacker to redirect users to an arbitrary location if they trust the URL."},{"lang":"es","value":"Una vulnerabilidad de redireccionamiento abierto en GitLab EE/CE que afecta a todas las versiones desde la 9.3 anterior a la 15.3.5, la 15.4 anterior a la 15.4.4 y la 15.5 anterior a la 15.5.2, permite a un atacante redirigir a los usuarios a una ubicación arbitraria si confían en la URL."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=9.4, <15.3.5","status":"affected"},{"version":">=15.4, <15.4.4","status":"affected"},{"version":">=15.5, <15.5.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N","baseScore":4.7,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-01T19:27:47.619626Z","id":"CVE-2022-3486","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-601"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-601"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"9.4.0","versionEndExcluding":"15.3.5","matchCriteriaId":"5D303FB9-3C72-4236-88FA-64A946E2E18E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"9.4.0","versionEndExcluding":"15.3.5","matchCriteriaId":"9EDB0942-D3D0-447B-B3E7-24DB6CF990A0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.4.0","versionEndExcluding":"15.4.4","matchCriteriaId":"ABE6E41B-B7AD-4081-99BC-5DD7A1280014"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.4.0","versionEndExcluding":"15.4.4","matchCriteriaId":"2FBFF5F6-6C42-4E64-8177-1BED65D38B00"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.5.0","versionEndExcluding":"15.5.2","matchCriteriaId":"127C9D37-25F3-479F-980C-9F5B6E818523"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.5.0","versionEndExcluding":"15.5.2","matchCriteriaId":"CE5ABA53-66D4-4BDE-BE64-AB45EFDADE24"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3486.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/377810","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1725190","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3486.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/377810","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1725190","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-3413","sourceIdentifier":"cve@gitlab.com","published":"2022-11-10T00:15:20.737","lastModified":"2026-06-17T04:59:28.587","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Incorrect authorization during display of Audit Events in GitLab EE affecting all versions from 14.5 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2, allowed Developers to view the project's Audit Events and Developers or Maintainers to view the group's Audit Events. These should have been restricted to Project Maintainers, Group Owners, and above."},{"lang":"es","value":"La autorización incorrecta durante la visualización de eventos de auditoría en GitLab EE que afecta a todas las versiones desde 14.5 anterior a 15.3.5, 15.4 anterior a 15.4.4 y 15.5 anterior a 15.5.2, permitió a los desarrolladores ver los eventos de auditoría del proyecto y a los desarrolladores o mantenedores ver los Eventos de Auditoría del grupo. Estos deberían haber estado restringidos a mantenedores de proyectos, propietarios de grupos y superiores."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=14.5, <15.3.5","status":"affected"},{"version":">=15.4, <15.4.4","status":"affected"},{"version":">=15.5, <15.5.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-01T15:53:11.166508Z","id":"CVE-2022-3413","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-639"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-639"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"15.3.5","matchCriteriaId":"ED059E2E-B69C-4D8C-8FCD-966700E6DC7E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.4.0","versionEndExcluding":"15.4.4","matchCriteriaId":"2FBFF5F6-6C42-4E64-8177-1BED65D38B00"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.5.0","versionEndExcluding":"15.5.2","matchCriteriaId":"CE5ABA53-66D4-4BDE-BE64-AB45EFDADE24"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3413.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/374926","source":"cve@gitlab.com","tags":["Broken Link","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3413.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/374926","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/374926","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Broken Link","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2022-3706","sourceIdentifier":"cve@gitlab.com","published":"2022-11-10T00:15:22.057","lastModified":"2026-06-17T05:00:09.053","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Improper authorization in GitLab CE/EE affecting all versions from 7.14 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows a user retrying a job in a downstream pipeline to take ownership of the retried jobs in the upstream pipeline even if the user doesn't have access to that project."},{"lang":"es","value":"La autorización inadecuada en GitLab CE/EE que afecta a todas las versiones desde 7.14 anterior a 15.3.5, 15.4 anterior a 15.4.4 y 15.5 anterior a 15.5.2 permite a un usuario reintentar un trabajo en una canalización descendente para tomar posesión de los trabajos reintentados en la tubería ascendente incluso si el usuario no tiene acceso a ese proyecto."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=7.14, <15.3.5","status":"affected"},{"version":">=15.4, <15.4.4","status":"affected"},{"version":">=15.5, <15.5.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":3.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-01T19:23:44.165490Z","id":"CVE-2022-3706","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"7.14.0","versionEndExcluding":"15.3.5","matchCriteriaId":"E2C47F1E-62E2-46B2-BA1A-84B1C2955A4D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"7.14.0","versionEndExcluding":"15.3.5","matchCriteriaId":"BB920C0F-5D6D-462D-BF0D-47E45FF085AB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.4.0","versionEndExcluding":"15.4.4","matchCriteriaId":"ABE6E41B-B7AD-4081-99BC-5DD7A1280014"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.4.0","versionEndExcluding":"15.4.4","matchCriteriaId":"2FBFF5F6-6C42-4E64-8177-1BED65D38B00"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.5.0","versionEndExcluding":"15.5.2","matchCriteriaId":"127C9D37-25F3-479F-980C-9F5B6E818523"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.5.0","versionEndExcluding":"15.5.2","matchCriteriaId":"CE5ABA53-66D4-4BDE-BE64-AB45EFDADE24"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3706.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/365532","source":"cve@gitlab.com","tags":["Broken Link","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3706.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/365532","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2022-3726","sourceIdentifier":"cve@gitlab.com","published":"2022-11-10T00:15:22.257","lastModified":"2026-06-17T05:00:11.020","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Lack of sand-boxing of OpenAPI documents in GitLab CE/EE affecting all versions from 12.6 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to trick a user to click on the Swagger OpenAPI viewer and issue HTTP requests that affect the victim's account."},{"lang":"es","value":"La falta de espacio aislado de los documentos OpenAPI en GitLab CE/EE que afecta a todas las versiones desde 12.6 anterior a 15.3.5, 15.4 anterior a 15.4.4 y 15.5 anterior a 15.5.2 permite a un atacante engañar a un usuario para que haga click en Swagger. Visor OpenAPI y emitir solicitudes HTTP que afectan la cuenta de la víctima."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.6, <15.3.5","status":"affected"},{"version":">=15.4, <15.4.4","status":"affected"},{"version":">=15.5, <15.5.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N","baseScore":4.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H","baseScore":9.0,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.3,"impactScore":6.0}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-01T19:22:45.884884Z","id":"CVE-2022-3726","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.6.0","versionEndExcluding":"15.3.5","matchCriteriaId":"9D9BFB8E-58FD-4B24-BE36-0B1BD69810C1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.6.0","versionEndExcluding":"15.3.5","matchCriteriaId":"BD36BAEA-3D1B-47B7-B7A8-BA11E5F4DCCA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.4.0","versionEndExcluding":"15.4.4","matchCriteriaId":"ABE6E41B-B7AD-4081-99BC-5DD7A1280014"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.4.0","versionEndExcluding":"15.4.4","matchCriteriaId":"2FBFF5F6-6C42-4E64-8177-1BED65D38B00"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.5.0","versionEndExcluding":"15.5.2","matchCriteriaId":"127C9D37-25F3-479F-980C-9F5B6E818523"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.5.0","versionEndExcluding":"15.5.2","matchCriteriaId":"CE5ABA53-66D4-4BDE-BE64-AB45EFDADE24"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3726.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/362509","source":"cve@gitlab.com","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1563383","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3726.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/362509","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1563383","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-3793","sourceIdentifier":"cve@gitlab.com","published":"2022-11-10T00:15:22.537","lastModified":"2026-06-17T05:00:18.817","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An improper authorization issue in GitLab CE/EE affecting all versions from 14.4 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to read variables set directly in a GitLab CI/CD configuration file they don't have access to."},{"lang":"es","value":"Un problema de autorización inadecuada en GitLab CE/EE que afecta a todas las versiones desde 14.4 anterior a 15.3.5, 15.4 anterior a 15.4.4 y 15.5 anterior a 15.5.2 permite a un atacante leer variables configuradas directamente en un archivo de configuración de GitLab CI/CD no tienen acceso a."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.6, <15.3.5","status":"affected"},{"version":">=15.4, <15.4.4","status":"affected"},{"version":">=15.5, <15.5.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-01T19:21:55.415972Z","id":"CVE-2022-3793","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.6.0","versionEndExcluding":"15.3.5","matchCriteriaId":"9D9BFB8E-58FD-4B24-BE36-0B1BD69810C1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.6.0","versionEndExcluding":"15.3.5","matchCriteriaId":"BD36BAEA-3D1B-47B7-B7A8-BA11E5F4DCCA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.4.0","versionEndExcluding":"15.4.4","matchCriteriaId":"ABE6E41B-B7AD-4081-99BC-5DD7A1280014"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.4.0","versionEndExcluding":"15.4.4","matchCriteriaId":"2FBFF5F6-6C42-4E64-8177-1BED65D38B00"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.5.0","versionEndExcluding":"15.5.2","matchCriteriaId":"127C9D37-25F3-479F-980C-9F5B6E818523"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.5.0","versionEndExcluding":"15.5.2","matchCriteriaId":"CE5ABA53-66D4-4BDE-BE64-AB45EFDADE24"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3793.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/372120","source":"cve@gitlab.com","tags":["Broken Link","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3793.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/372120","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2022-3818","sourceIdentifier":"cve@gitlab.com","published":"2022-11-10T00:15:22.620","lastModified":"2026-06-17T05:00:21.547","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An uncontrolled resource consumption issue when parsing URLs in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to cause performance issues and potentially a denial of service on the GitLab instance."},{"lang":"es","value":"Un problema de consumo de recursos no controlado al analizar URL en GitLab CE/EE que afecta a todas las versiones anteriores a 15.3.5, 15.4 anterior a 15.4.4 y 15.5 anterior a 15.5.2 permite que un atacante cause problemas de rendimiento y potencialmente una Denegación de Servicio (DoS) en la instancia de GitLab."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":"<15.3.5","status":"affected"},{"version":">=15.4, <15.4.4","status":"affected"},{"version":">=15.5, <15.5.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-01T19:21:10.364245Z","id":"CVE-2022-3818","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-400"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-400"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"15.3.5","matchCriteriaId":"129FF0B7-CB2A-42DD-A089-33D1AD8E31ED"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"15.3.5","matchCriteriaId":"E6F25E37-3A83-49C5-8388-F7E35933D9BD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.4.0","versionEndExcluding":"15.4.4","matchCriteriaId":"ABE6E41B-B7AD-4081-99BC-5DD7A1280014"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.4.0","versionEndExcluding":"15.4.4","matchCriteriaId":"2FBFF5F6-6C42-4E64-8177-1BED65D38B00"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.5.0","versionEndExcluding":"15.5.2","matchCriteriaId":"127C9D37-25F3-479F-980C-9F5B6E818523"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.5.0","versionEndExcluding":"15.5.2","matchCriteriaId":"CE5ABA53-66D4-4BDE-BE64-AB45EFDADE24"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3818.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/358170","source":"cve@gitlab.com","tags":["Broken Link","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3818.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/358170","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2022-3819","sourceIdentifier":"cve@gitlab.com","published":"2022-11-10T00:15:22.710","lastModified":"2026-06-17T05:00:21.660","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An improper authorization issue in GitLab CE/EE affecting all versions from 15.0 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows a malicious users to set emojis on internal notes they don't have access to."},{"lang":"es","value":"Un problema de autorización inadecuada en GitLab CE/EE que afecta a todas las versiones desde 15.0 anterior a 15.3.5, 15.4 anterior a 15.4.4 y 15.5 anterior a 15.5.2 permite a usuarios malintencionados configurar emojis en notas internas a las que no tienen acceso."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=15.0, <15.3.5","status":"affected"},{"version":">=15.4, <15.4.4","status":"affected"},{"version":">=15.5, <15.5.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N","baseScore":3.5,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-01T19:20:26.950002Z","id":"CVE-2022-3819","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.0.0","versionEndExcluding":"15.3.5","matchCriteriaId":"4CECEF8D-18D4-4990-BDAA-C680A365176D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.0.0","versionEndExcluding":"15.3.5","matchCriteriaId":"39B02747-CF6E-46D5-82E5-5F0B8CA137D0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.4.0","versionEndExcluding":"15.4.4","matchCriteriaId":"ABE6E41B-B7AD-4081-99BC-5DD7A1280014"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.4.0","versionEndExcluding":"15.4.4","matchCriteriaId":"2FBFF5F6-6C42-4E64-8177-1BED65D38B00"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.5.0","versionEndExcluding":"15.5.2","matchCriteriaId":"127C9D37-25F3-479F-980C-9F5B6E818523"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.5.0","versionEndExcluding":"15.5.2","matchCriteriaId":"CE5ABA53-66D4-4BDE-BE64-AB45EFDADE24"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3819.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/365847","source":"cve@gitlab.com","tags":["Broken Link","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3819.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/365847","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2022-3514","sourceIdentifier":"cve@gitlab.com","published":"2023-01-12T04:15:08.717","lastModified":"2026-06-17T04:59:40.167","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 6.6 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. An attacker may cause Denial of Service on a GitLab instance by exploiting a regex issue in the submodule URL parser."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde 6.6 anteriores a 15.5.7, todas las versiones desde 15.6 anteriores a 15.6.4, todas las versiones desde 15.7 anteriores a 15.7.2. Un atacante puede provocar una denegación de servicio en una instancia de GitLab explotando un problema de expresiones regulares en el analizador de URL del submódulo."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=6.6, <15.5.7","status":"affected"},{"version":">=15.6, <15.6.4","status":"affected"},{"version":">=15.7, <15.7.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-04-08T15:55:35.262555Z","id":"CVE-2022-3514","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-1333"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-1333"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"6.6.0","versionEndExcluding":"15.5.7","matchCriteriaId":"A49A3761-4A57-43B9-8C60-6077082A5D5C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"6.6.0","versionEndExcluding":"15.5.7","matchCriteriaId":"186336D8-BFE8-4A33-9294-DBCD2C381BAD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.6.0","versionEndExcluding":"15.6.4","matchCriteriaId":"D184F043-F506-415D-BAC5-03E8A7334E78"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.6.0","versionEndExcluding":"15.6.4","matchCriteriaId":"D82CADBB-B082-4757-B16A-48AA5E3CC54E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.7.0","versionEndExcluding":"15.7.2","matchCriteriaId":"5482B6DC-FA6C-49AA-93FD-AA7EE9B3E39B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.7.0","versionEndExcluding":"15.7.2","matchCriteriaId":"B9242DBC-C1C9-4B96-970E-E1ECB2F3B2AA"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3514.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/377978","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1727201","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3514.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/377978","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1727201","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/377978","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2022-3573","sourceIdentifier":"cve@gitlab.com","published":"2023-01-12T04:15:08.803","lastModified":"2026-06-17T04:59:46.260","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. Due to the improper filtering of query parameters in the wiki changes page, an attacker can execute arbitrary JavaScript on the self-hosted instances running without strict CSP."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde 15.4 anteriores a 15.5.7, todas las versiones desde 15.6 anteriores a 15.6.4, todas las versiones desde 15.7 anteriores a 15.7.2. Debido al filtrado inadecuado de los parámetros de consulta en la página de cambios de la wiki, un atacante puede ejecutar JavaScript arbitrario en las instancias autohospedadas que se ejecutan sin un CSP estricto."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=15.4, <15.5.7","status":"affected"},{"version":">=15.6, <15.6.4","status":"affected"},{"version":">=15.7, <15.7.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-04-08T15:15:35.539787Z","id":"CVE-2022-3573","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.4.0","versionEndExcluding":"15.5.7","matchCriteriaId":"BD5B0EDB-9F2D-4D1E-B999-2E230F1DCC84"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.4.0","versionEndExcluding":"15.5.7","matchCriteriaId":"D51BBBEE-D2D2-4B59-A899-36EC8252DB9F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.6.0","versionEndExcluding":"15.6.4","matchCriteriaId":"D184F043-F506-415D-BAC5-03E8A7334E78"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.6.0","versionEndExcluding":"15.6.4","matchCriteriaId":"D82CADBB-B082-4757-B16A-48AA5E3CC54E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.7.0","versionEndExcluding":"15.7.2","matchCriteriaId":"5482B6DC-FA6C-49AA-93FD-AA7EE9B3E39B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.7.0","versionEndExcluding":"15.7.2","matchCriteriaId":"B9242DBC-C1C9-4B96-970E-E1ECB2F3B2AA"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:abb:drive_composer:*:*:*:*:entry:*:*:*","versionEndIncluding":"2.8","matchCriteriaId":"C721DDDA-58E0-4795-89BC-DF06F97005D3"},{"vulnerable":true,"criteria":"cpe:2.3:a:abb:drive_composer:*:*:*:*:pro:*:*:*","versionEndIncluding":"2.8","matchCriteriaId":"0D6BE9E2-8B07-468C-AD56-C347D1811845"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3573.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/378216","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1730461","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3573.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/378216","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1730461","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/378216","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2022-3613","sourceIdentifier":"cve@gitlab.com","published":"2023-01-12T04:15:08.883","lastModified":"2026-06-17T04:59:52.863","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A crafted Prometheus Server query can cause high resource consumption and may lead to Denial of Service."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones anteriores a 15.5.7, todas las versiones desde 15.6 anteriores a 15.6.4, todas las versiones desde 15.7 anteriores a 15.7.2. Una consulta del servidor Prometheus manipulada puede provocar un alto consumo de recursos y provocar una denegación de servicio."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=0.0, <15.5.7","status":"affected"},{"version":">=15.6, <15.6.4","status":"affected"},{"version":">=15.7, <15.7.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L","baseScore":5.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-04-08T15:05:50.442030Z","id":"CVE-2022-3613","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-400"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"15.5.7","matchCriteriaId":"BA61F130-676B-4DC3-BFF1-8A3D23A44B56"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"15.5.7","matchCriteriaId":"AF132188-F508-4E92-93FF-A4CCEB5872D8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.6.0","versionEndExcluding":"15.6.4","matchCriteriaId":"D184F043-F506-415D-BAC5-03E8A7334E78"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.6.0","versionEndExcluding":"15.6.4","matchCriteriaId":"D82CADBB-B082-4757-B16A-48AA5E3CC54E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.7.0","versionEndExcluding":"15.7.2","matchCriteriaId":"5482B6DC-FA6C-49AA-93FD-AA7EE9B3E39B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.7.0","versionEndExcluding":"15.7.2","matchCriteriaId":"B9242DBC-C1C9-4B96-970E-E1ECB2F3B2AA"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3613.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/378456","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1723106","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3613.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/378456","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1723106","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-3870","sourceIdentifier":"cve@gitlab.com","published":"2023-01-12T04:15:08.957","lastModified":"2026-06-17T05:00:28.530","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.0 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. GitLab allows unauthenticated users to download user avatars using the victim's user ID, on private instances that restrict public level visibility."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde 10.0 anteriores a 15.5.7, todas las versiones desde 15.6 anteriores a 15.6.4, todas las versiones desde 15.7 anteriores a 15.7.2. GitLab permite a los usuarios no autenticados descargar avatares de usuario utilizando la identificación de usuario de la víctima, en instancias privadas que restringen la visibilidad a nivel público."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=10.0, <15.5.7","status":"affected"},{"version":">=15.6, <15.6.4","status":"affected"},{"version":">=15.7, <15.7.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-04-09T13:14:38.624594Z","id":"CVE-2022-3870","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-200"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.0.0","versionEndExcluding":"15.5.7","matchCriteriaId":"2CFE1516-B668-43B7-9527-BE9D24ABA916"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.0.0","versionEndExcluding":"15.5.7","matchCriteriaId":"BE2EEF33-375A-46B4-A58A-D33DC8005CD2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.6.0","versionEndExcluding":"15.6.4","matchCriteriaId":"D184F043-F506-415D-BAC5-03E8A7334E78"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.6.0","versionEndExcluding":"15.6.4","matchCriteriaId":"D82CADBB-B082-4757-B16A-48AA5E3CC54E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.7.0","versionEndExcluding":"15.7.2","matchCriteriaId":"5482B6DC-FA6C-49AA-93FD-AA7EE9B3E39B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.7.0","versionEndExcluding":"15.7.2","matchCriteriaId":"B9242DBC-C1C9-4B96-970E-E1ECB2F3B2AA"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3870.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/381647","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1753423","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3870.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/381647","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1753423","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/381647","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2022-4037","sourceIdentifier":"cve@gitlab.com","published":"2023-01-12T04:15:09.910","lastModified":"2026-06-17T05:19:49.057","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A race condition can lead to verified email forgery and takeover of third-party accounts when using GitLab as an OAuth provider."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones anteriores a 15.5.7, todas las versiones desde 15.6 anteriores a 15.6.4, todas las versiones desde 15.7 anteriores a 15.7.2. Una condición de ejecución puede provocar la falsificación de correos electrónicos verificados y la toma de control de cuentas de terceros cuando se utiliza GitLab como proveedor de OAuth."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=0.0, <15.5.7","status":"affected"},{"version":">=15.6, <15.6.4","status":"affected"},{"version":">=15.7, <15.7.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":8.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":6.0}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-04-08T16:21:35.572752Z","id":"CVE-2022-4037","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-362"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-362"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"15.5.7","matchCriteriaId":"BA61F130-676B-4DC3-BFF1-8A3D23A44B56"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"15.5.7","matchCriteriaId":"AF132188-F508-4E92-93FF-A4CCEB5872D8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.6.0","versionEndExcluding":"15.6.4","matchCriteriaId":"D184F043-F506-415D-BAC5-03E8A7334E78"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.6.0","versionEndExcluding":"15.6.4","matchCriteriaId":"D82CADBB-B082-4757-B16A-48AA5E3CC54E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.7.0","versionEndExcluding":"15.7.2","matchCriteriaId":"5482B6DC-FA6C-49AA-93FD-AA7EE9B3E39B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.7.0","versionEndExcluding":"15.7.2","matchCriteriaId":"B9242DBC-C1C9-4B96-970E-E1ECB2F3B2AA"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4037.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/382957","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1772543","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4037.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/382957","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1772543","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-4131","sourceIdentifier":"cve@gitlab.com","published":"2023-01-12T04:15:10.107","lastModified":"2026-06-17T05:20:02.440","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.8 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. An attacker may cause Denial of Service on a GitLab instance by exploiting a regex issue in how the application parses user agents."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde 10.8 anteriores a 15.5.7, todas las versiones desde 15.6 anteriores a 15.6.4, todas las versiones desde 15.7 anteriores a 15.7.2. Un atacante puede provocar una denegación de servicio en una instancia de GitLab explotando un problema de expresiones regulares en la forma en que la aplicación analiza los agentes de usuario."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=10.8, <15.5.7","status":"affected"},{"version":">=15.6, <15.6.4","status":"affected"},{"version":">=15.7, <15.7.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-04-08T16:25:32.019474Z","id":"CVE-2022-4131","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-1333"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-1333"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.8.0","versionEndExcluding":"15.5.7","matchCriteriaId":"33C0CB7F-432B-4518-99DC-485378A140C1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.8.0","versionEndExcluding":"15.5.7","matchCriteriaId":"BE03F9B2-FD0B-4F14-AD76-135DA6C691C7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.6.0","versionEndExcluding":"15.6.4","matchCriteriaId":"D184F043-F506-415D-BAC5-03E8A7334E78"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.6.0","versionEndExcluding":"15.6.4","matchCriteriaId":"D82CADBB-B082-4757-B16A-48AA5E3CC54E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.7.0","versionEndExcluding":"15.7.2","matchCriteriaId":"5482B6DC-FA6C-49AA-93FD-AA7EE9B3E39B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.7.0","versionEndExcluding":"15.7.2","matchCriteriaId":"B9242DBC-C1C9-4B96-970E-E1ECB2F3B2AA"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4131.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/383598","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1772063","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4131.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/383598","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1772063","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-4167","sourceIdentifier":"cve@gitlab.com","published":"2023-01-12T04:15:10.327","lastModified":"2026-06-17T05:20:09.343","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Incorrect Authorization check affecting all versions of GitLab EE from 13.11 prior to 15.5.7, 15.6 prior to 15.6.4, and 15.7 prior to 15.7.2 allows group access tokens to continue working even after the group owner loses the ability to revoke them."},{"lang":"es","value":"La verificación de autorización incorrecta que afecta a todas las versiones de GitLab EE desde la 13.11 anterior a la 15.5.7, la 15.6 anterior a la 15.6.4 y la 15.7 anterior a la 15.7.2 permite que los tokens de acceso al grupo sigan funcionando incluso después de que el propietario del grupo pierda la capacidad de revocarlos."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.11, <15.5.7","status":"affected"},{"version":">=15.6, <15.6.4","status":"affected"},{"version":">=15.7, <15.7.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-04-08T16:28:24.380605Z","id":"CVE-2022-4167","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.11.0","versionEndExcluding":"15.5.7","matchCriteriaId":"FA18C619-7ED0-4149-B325-B9ADB8060337"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.6.0","versionEndExcluding":"15.6.4","matchCriteriaId":"D82CADBB-B082-4757-B16A-48AA5E3CC54E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.7.0","versionEndExcluding":"15.7.2","matchCriteriaId":"B9242DBC-C1C9-4B96-970E-E1ECB2F3B2AA"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4167.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/367740","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4167.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/367740","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2022-4342","sourceIdentifier":"cve@gitlab.com","published":"2023-01-12T04:15:10.547","lastModified":"2026-06-17T05:20:38.227","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.1 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A malicious Maintainer can leak masked webhook secrets by changing target URL of the webhook."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde 15.1 anteriores a 15.5.7, todas las versiones desde 15.6 anteriores a 15.6.4, todas las versiones desde 15.7 anteriores a 15.7.2. Un mantenedor malicioso puede filtrar secretos de webhooks enmascarados cambiando la URL de destino del webhook."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=15.1, <15.5.7","status":"affected"},{"version":">=15.6, <15.6.4","status":"affected"},{"version":">=15.7, <15.7.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N","baseScore":3.8,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-04-08T16:41:54.279253Z","id":"CVE-2022-4342","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.1.0","versionEndExcluding":"15.5.7","matchCriteriaId":"E4640ABA-18FE-4DCC-989B-FFA3D3D7FADC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.1.0","versionEndExcluding":"15.5.7","matchCriteriaId":"C81AC283-8EC6-4C68-BA91-C4068A7B4763"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.6.0","versionEndExcluding":"15.6.4","matchCriteriaId":"D184F043-F506-415D-BAC5-03E8A7334E78"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.6.0","versionEndExcluding":"15.6.4","matchCriteriaId":"D82CADBB-B082-4757-B16A-48AA5E3CC54E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.7.0","versionEndExcluding":"15.7.2","matchCriteriaId":"5482B6DC-FA6C-49AA-93FD-AA7EE9B3E39B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.7.0","versionEndExcluding":"15.7.2","matchCriteriaId":"B9242DBC-C1C9-4B96-970E-E1ECB2F3B2AA"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4342.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/385118","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1791331","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4342.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/385118","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1791331","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-4365","sourceIdentifier":"cve@gitlab.com","published":"2023-01-12T04:15:10.750","lastModified":"2026-06-17T05:20:42.260","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A malicious Maintainer can leak the sentry token by changing the configured URL in the Sentry error tracking settings page."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde 11.8 anteriores a 15.5.7, todas las versiones desde 15.6 anteriores a 15.6.4, todas las versiones desde 15.7 anteriores a 15.7.2. Un mantenedor malicioso puede filtrar el token de centinela cambiando la URL configurada en la página de configuración de seguimiento de errores de Sentry."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=11.8, <15.5.7","status":"affected"},{"version":">=15.6, <15.6.4","status":"affected"},{"version":">=15.7, <15.7.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-04-08T13:49:47.833272Z","id":"CVE-2022-4365","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-732"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"15.5.7","matchCriteriaId":"B085B23E-9BFE-471C-9A53-33D9643CCD29"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"15.5.7","matchCriteriaId":"134A816F-B6D8-448C-925F-829B908216F3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.6.0","versionEndExcluding":"15.6.4","matchCriteriaId":"D184F043-F506-415D-BAC5-03E8A7334E78"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.6.0","versionEndExcluding":"15.6.4","matchCriteriaId":"D82CADBB-B082-4757-B16A-48AA5E3CC54E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.7.0","versionEndExcluding":"15.7.2","matchCriteriaId":"5482B6DC-FA6C-49AA-93FD-AA7EE9B3E39B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.7.0","versionEndExcluding":"15.7.2","matchCriteriaId":"B9242DBC-C1C9-4B96-970E-E1ECB2F3B2AA"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4365.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/385193","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1792626","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4365.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/385193","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1792626","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/385193","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2023-0042","sourceIdentifier":"cve@gitlab.com","published":"2023-01-12T04:15:10.817","lastModified":"2026-06-17T05:24:39.037","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.4 prior to 15.5.7, 15.6 prior to 15.6.4, and 15.7 prior to 15.7.2. GitLab Pages allows redirection to arbitrary protocols."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde 11.4 anterior a 15.5.7, 15.6 anterior a 15.6.4 y 15.7 anterior a 15.7.2. GitLab Pages permite la redirección a protocolos arbitrarios."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=11.4, <15.5.7","status":"affected"},{"version":">=15.6, <15.6.4","status":"affected"},{"version":">=15.7, <15.7.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":4.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-04-08T13:40:59.256122Z","id":"CVE-2023-0042","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-601"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-601"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"15.5.7","matchCriteriaId":"8E790DFB-A4FB-4562-AF86-DEBEE2045015"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"15.5.7","matchCriteriaId":"9E51C640-5A23-4141-AC61-1E0327F5C010"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.6.0","versionEndExcluding":"15.6.4","matchCriteriaId":"D184F043-F506-415D-BAC5-03E8A7334E78"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.6.0","versionEndExcluding":"15.6.4","matchCriteriaId":"D82CADBB-B082-4757-B16A-48AA5E3CC54E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.7.0","versionEndExcluding":"15.7.2","matchCriteriaId":"5482B6DC-FA6C-49AA-93FD-AA7EE9B3E39B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.7.0","versionEndExcluding":"15.7.2","matchCriteriaId":"B9242DBC-C1C9-4B96-970E-E1ECB2F3B2AA"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-0042.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-pages/-/issues/728","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-0042.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-pages/-/issues/728","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/gitlab-pages/-/issues/728","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2022-2907","sourceIdentifier":"cve@gitlab.com","published":"2023-01-17T21:15:12.683","lastModified":"2026-06-17T04:42:48.557","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. It was possible to read repository content by an unauthorised user if a project member used a crafted link."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde 12.9 anteriores a 15.1.6, todas las versiones desde 15.2 anteriores a 15.2.4, todas las versiones desde 15.3 anteriores a 15.3.2. Era posible que un usuario no autorizado leyera el contenido del repositorio si un miembro del proyecto utilizaba un enlace manipulado."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.9, <15.1.6","status":"affected"},{"version":">=15.2, <15.2.4","status":"affected"},{"version":">=15.3, <15.3.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N","baseScore":5.7,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-04-04T17:42:23.086269Z","id":"CVE-2022-2907","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-200"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.9","versionEndExcluding":"15.1.6","matchCriteriaId":"1D98BC3C-5847-4873-A817-E1B8BF64A2B7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.9","versionEndIncluding":"15.1.6","matchCriteriaId":"721CC746-CDB7-4562-A414-A0C9B42DC3B1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.2.0","versionEndExcluding":"15.2.4","matchCriteriaId":"576472E1-87A8-4C4F-A835-B7F944AD3D00"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.2.0","versionEndExcluding":"15.2.4","matchCriteriaId":"25E28537-790A-4134-823A-10CBACC5418E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.3.0","versionEndExcluding":"15.3.2","matchCriteriaId":"93D0BFB1-DF96-4C26-A92D-9046CF51C142"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.3.0","versionEndExcluding":"15.3.2","matchCriteriaId":"5C1E15E7-862D-4751-BF56-4F4CA2D8D3AF"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2907.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/349388","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1417680","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2907.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/349388","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1417680","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-3478","sourceIdentifier":"cve@gitlab.com","published":"2023-01-26T21:15:51.460","lastModified":"2026-06-17T04:59:36.163","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 12.8 before 15.4.6, all versions starting from 15.5 before 15.5.5, all versions starting from 15.6 before 15.6.1. It was possible to trigger a DoS attack by uploading a malicious nuget package."},{"lang":"es","value":"Se ha descubierto un problema en GitLab que afecta a todas las versiones desde 12.8 anteriores a 15.4.6, todas las versiones desde 15.5 anteriores a 15.5.5, todas las versiones desde 15.6 anteriores a 15.6.1. Era posible desencadenar un ataque DoS cargando un paquete nuget malicioso."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.8, <15.4.6","status":"affected"},{"version":">=15.5, <15.5.5","status":"affected"},{"version":">=15.6, <15.6.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-04-02T15:04:38.449469Z","id":"CVE-2022-3478","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-434"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-434"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.8.0","versionEndExcluding":"15.4.6","matchCriteriaId":"70146422-EAAD-40E4-83B4-F4F438B6A512"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.8.0","versionEndExcluding":"15.4.6","matchCriteriaId":"3B09958F-CF8B-496E-AF31-93BD4A3BDEA5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.5.0","versionEndExcluding":"15.5.5","matchCriteriaId":"C2CF4BFC-D5A9-49F5-AC0E-A5978B8D8CFD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.5.0","versionEndExcluding":"15.5.5","matchCriteriaId":"C734804C-B835-493E-8A2B-556547368D9F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.6.0:*:*:*:community:*:*:*","matchCriteriaId":"B5CD27BD-9171-4958-9E31-FA35229B39E7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.6.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"D1DA9696-F8DA-4C34-AB21-7DE509454B82"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3478.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/377788","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1716296","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3478.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/377788","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1716296","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-3482","sourceIdentifier":"cve@gitlab.com","published":"2023-01-26T21:15:51.793","lastModified":"2026-06-17T04:59:36.740","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An improper access control issue in GitLab CE/EE affecting all versions from 11.3 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allowed an unauthorized user to see release names even when releases we set to be restricted to project members only"},{"lang":"es","value":"Un problema de control de acceso inadecuado en GitLab CE/EE que afectó a todas las versiones desde 11.3 anterior a 15.3.5, 15.4 anterior a 15.4.4 y 15.5 anterior a 15.5.2 permitió a un usuario no autorizado ver los nombres de las versiones incluso cuando las versiones configuramos como restringido solo a miembros del proyecto"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=11.3, <15.4.6","status":"affected"},{"version":">=15.5, <15.5.5","status":"affected"},{"version":">=15.6, <15.6.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-04-02T15:04:13.939534Z","id":"CVE-2022-3482","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"15.4.6","matchCriteriaId":"BFD3D2ED-9A77-4CEC-B09B-182CD984DA4B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"15.4.6","matchCriteriaId":"34D21C08-2445-4D1D-8FEF-EF01AF1D9371"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.5.0","versionEndExcluding":"15.5.5","matchCriteriaId":"C2CF4BFC-D5A9-49F5-AC0E-A5978B8D8CFD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.5.0","versionEndExcluding":"15.5.5","matchCriteriaId":"C734804C-B835-493E-8A2B-556547368D9F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.6.0:*:*:*:community:*:*:*","matchCriteriaId":"B5CD27BD-9171-4958-9E31-FA35229B39E7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.6.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"D1DA9696-F8DA-4C34-AB21-7DE509454B82"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3482.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/377802","source":"cve@gitlab.com","tags":["Exploit","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1725841","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3482.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/377802","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1725841","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-3572","sourceIdentifier":"cve@gitlab.com","published":"2023-01-26T21:15:54.547","lastModified":"2026-06-17T04:59:46.140","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions from 13.5 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. It was possible to exploit a vulnerability in setting the Jira Connect integration which could lead to a reflected XSS that allowed attackers to perform arbitrary actions on behalf of victims."},{"lang":"es","value":"Se descubrió un problema de cross site scripting en GitLab CE/EE que afecta a todas las versiones desde 13.5 anterior a 15.3.5, 15.4 anterior a 15.4.4 y 15.5 anterior a 15.5.2. Fue posible explotar una vulnerabilidad al configurar la integración de Jira Connect, lo que podría conducir a un XSS reflejado que permitiera a los atacantes realizar acciones arbitrarias en nombre de las víctimas."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.5, <15.4.6","status":"affected"},{"version":">=15.5, <15.5.5","status":"affected"},{"version":">=15.6, <15.6.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N","baseScore":9.3,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-04-02T15:03:41.823444Z","id":"CVE-2022-3572","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.5.0","versionEndExcluding":"15.4.6","matchCriteriaId":"A69E5EC3-F106-4367-87D6-8A5E6F120854"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.5.0","versionEndExcluding":"15.4.6","matchCriteriaId":"A6B5ECA3-D2D1-442E-A5E7-0A76ADA64D57"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.5.0","versionEndExcluding":"15.5.5","matchCriteriaId":"C2CF4BFC-D5A9-49F5-AC0E-A5978B8D8CFD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.5.0","versionEndExcluding":"15.5.5","matchCriteriaId":"C734804C-B835-493E-8A2B-556547368D9F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.6.0:*:*:*:community:*:*:*","matchCriteriaId":"B5CD27BD-9171-4958-9E31-FA35229B39E7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.6.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"D1DA9696-F8DA-4C34-AB21-7DE509454B82"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3572.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/378214","source":"cve@gitlab.com","tags":["Exploit","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1727985","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3572.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/378214","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1727985","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-3740","sourceIdentifier":"cve@gitlab.com","published":"2023-01-26T21:15:58.303","lastModified":"2026-06-17T05:00:12.643","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. A group owner may be able to bypass External Authorization check, if it is enabled, to access git repositories and package registries by using Deploy tokens or Deploy keys ."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde 12.9 anterior a 15.3.5, 15.4 anterior a 15.4.4 y 15.5 anterior a 15.5.2. El propietario de un grupo puede omitir la verificación de Autorización externa, si está habilitada, para acceder a repositorios git y registros de paquetes mediante el uso de tokens de implementación o claves de implementación."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.9, <15.4.6","status":"affected"},{"version":">=15.5, <15.5.5","status":"affected"},{"version":">=15.6, <15.6.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-04-02T15:03:08.049429Z","id":"CVE-2022-3740","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-285"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.9.0","versionEndExcluding":"15.4.6","matchCriteriaId":"0E4AD907-F198-48E6-9128-6EF8034F13E9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.9.0","versionEndExcluding":"15.4.6","matchCriteriaId":"52AAC56B-FC72-4887-B04D-3DA72D2C6146"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.5.0","versionEndExcluding":"15.5.5","matchCriteriaId":"C2CF4BFC-D5A9-49F5-AC0E-A5978B8D8CFD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.5.0","versionEndExcluding":"15.5.5","matchCriteriaId":"C734804C-B835-493E-8A2B-556547368D9F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.6.0:*:*:*:community:*:*:*","matchCriteriaId":"B5CD27BD-9171-4958-9E31-FA35229B39E7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.6.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"D1DA9696-F8DA-4C34-AB21-7DE509454B82"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3740.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/368416","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1602904","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3740.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/368416","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1602904","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-3820","sourceIdentifier":"cve@gitlab.com","published":"2023-01-26T21:15:58.750","lastModified":"2026-06-17T05:00:21.787","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. GitLab was not performing correct authentication with some Package Registries when IP address restrictions were configured, allowing an attacker already in possession of a valid Deploy Token to misuse it from any location."},{"lang":"es","value":"Se descubrió un problema en GitLab que afecta a todas las versiones desde la 15.4 anterior a la 15.4.4 y la 15.5 anterior a la 15.5.2. GitLab no estaba realizando la autenticación correcta con algunos registros de paquetes cuando se configuraron las restricciones de dirección IP, lo que permitió que un atacante que ya estuviera en posesión de un token de implementación válido lo usara indebidamente desde cualquier ubicación."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=15.4, <15.4.6","status":"affected"},{"version":">=15.5, <15.5.5","status":"affected"},{"version":">=15.6, <15.6.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-04-02T15:02:02.810173Z","id":"CVE-2022-3820","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-290"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.4.0","versionEndExcluding":"15.4.6","matchCriteriaId":"99D007D3-5D61-4297-828B-B2956AF1FB06"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.4.0","versionEndExcluding":"15.4.6","matchCriteriaId":"89C5D451-E2F3-4EE1-BA54-830F572E1076"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.5.0","versionEndExcluding":"15.5.5","matchCriteriaId":"C2CF4BFC-D5A9-49F5-AC0E-A5978B8D8CFD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.5.0","versionEndExcluding":"15.5.5","matchCriteriaId":"C734804C-B835-493E-8A2B-556547368D9F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.6.0:*:*:*:community:*:*:*","matchCriteriaId":"B5CD27BD-9171-4958-9E31-FA35229B39E7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.6.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"D1DA9696-F8DA-4C34-AB21-7DE509454B82"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3820.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/378638","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3820.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/378638","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2022-3902","sourceIdentifier":"cve@gitlab.com","published":"2023-01-26T21:16:02.713","lastModified":"2026-06-17T05:00:32.730","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 9.3 before 15.4.6, all versions starting from 15.5 before 15.5.5, all versions starting from 15.6 before 15.6.1. It was possible for a project maintainer to unmask webhook secret tokens by reviewing the logs after testing webhooks."},{"lang":"es","value":"Se ha descubierto un problema en GitLab que afecta a todas las versiones desde 9.3 anteriores a 15.4.6, todas las versiones desde 15.5 anteriores a 15.5.5, todas las versiones desde 15.6 anteriores a 15.6.1. Un responsable del proyecto pudo desenmascarar los tokens secretos de los webhooks revisando los registros después de probar los webhooks."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=9.3, <15.4.6","status":"affected"},{"version":">=15.5, <15.5.5","status":"affected"},{"version":">=15.6, <15.6.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-04-02T15:00:00.816401Z","id":"CVE-2022-3902","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-532"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"9.3.0","versionEndExcluding":"15.4.6","matchCriteriaId":"9BCEE406-F161-4B72-910E-C5B6D90A72C2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"9.3.0","versionEndExcluding":"15.4.6","matchCriteriaId":"0228CE03-9BB0-4F55-A64E-71EF4BC5D428"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.5.0","versionEndExcluding":"15.5.5","matchCriteriaId":"C2CF4BFC-D5A9-49F5-AC0E-A5978B8D8CFD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.5.0","versionEndExcluding":"15.5.5","matchCriteriaId":"C734804C-B835-493E-8A2B-556547368D9F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.6.0:*:*:*:community:*:*:*","matchCriteriaId":"B5CD27BD-9171-4958-9E31-FA35229B39E7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.6.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"D1DA9696-F8DA-4C34-AB21-7DE509454B82"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3902.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/381895","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1757999","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3902.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/381895","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1757999","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-4054","sourceIdentifier":"cve@gitlab.com","published":"2023-01-26T21:18:06.253","lastModified":"2026-06-17T05:19:51.563","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 9.3 before 15.4.6, all versions starting from 15.5 before 15.5.5, all versions starting from 15.6 before 15.6.1. It was possible for a project maintainer to leak a webhook secret token by changing the webhook URL to an endpoint that allows them to capture request headers."},{"lang":"es","value":"Se ha descubierto un problema en GitLab en el que se ven afectadas todas las versiones de la 9.3 a la 15.4.6, de la 15.5 a la 15.5.5 y de la 15.6 a la 15.6.1. Era posible que un mantenedor de proyecto filtrara un token secreto de webhook cambiando la URL del webhook a un endpoint que les permitiera capturar encabezados de peticiones."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=9.3, <15.4.6","status":"affected"},{"version":">=15.5, <15.5.5","status":"affected"},{"version":">=15.6, <15.6.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-04-02T15:15:23.331686Z","id":"CVE-2022-4054","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-200"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"9.3.0","versionEndExcluding":"15.4.6","matchCriteriaId":"9BCEE406-F161-4B72-910E-C5B6D90A72C2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"9.3.0","versionEndExcluding":"15.4.6","matchCriteriaId":"0228CE03-9BB0-4F55-A64E-71EF4BC5D428"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.5.0","versionEndExcluding":"15.5.5","matchCriteriaId":"C2CF4BFC-D5A9-49F5-AC0E-A5978B8D8CFD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.5.0","versionEndExcluding":"15.5.5","matchCriteriaId":"C734804C-B835-493E-8A2B-556547368D9F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.6.0:*:*:*:community:*:*:*","matchCriteriaId":"B5CD27BD-9171-4958-9E31-FA35229B39E7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.6.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"D1DA9696-F8DA-4C34-AB21-7DE509454B82"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4054.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/382260","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1758126","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4054.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/382260","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1758126","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-4092","sourceIdentifier":"cve@gitlab.com","published":"2023-01-26T21:18:06.410","lastModified":"2026-06-17T05:19:55.917","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions starting from 15.6 before 15.6.1. It was possible to create a malicious README page due to improper neutralisation of user supplied input."},{"lang":"es","value":"Se descubrió un problema en GitLab EE que afecta a todas las versiones desde la 15.6 hasta la 15.6.1. Fue posible crear una página README maliciosa debido a una neutralización inadecuada de la entrada proporcionada por el usuario."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=15.6, <15.6.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N","baseScore":5.7,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","baseScore":8.0,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.1,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-04-01T17:34:17.380011Z","id":"CVE-2022-4092","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.6.0:*:*:*:community:*:*:*","matchCriteriaId":"B5CD27BD-9171-4958-9E31-FA35229B39E7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.6.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"D1DA9696-F8DA-4C34-AB21-7DE509454B82"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4092.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/383208","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1777934","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4092.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/383208","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1777934","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-4335","sourceIdentifier":"cve@gitlab.com","published":"2023-01-27T18:15:16.183","lastModified":"2026-06-17T05:20:37.340","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A blind SSRF vulnerability was identified in all versions of GitLab EE prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 which allows an attacker to connect to a local host."},{"lang":"es","value":"Se identificó una vulnerabilidad blind SSRF en todas las versiones de GitLab EE anteriores a 15.4.6, 15.5 anteriores a 15.5.5 y 15.6 anteriores a 15.6.1 que permite a un atacante conectarse a un host local."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":"<15.4.6","status":"affected"},{"version":">=15.5, <15.5.5","status":"affected"},{"version":">=15.6, <15.6.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-03-28T14:37:07.684202Z","id":"CVE-2022-4335","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"15.4.6","matchCriteriaId":"D52C5E17-2637-470F-ABBC-8F9F4B062050"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.5.0","versionEndExcluding":"15.5.5","matchCriteriaId":"C734804C-B835-493E-8A2B-556547368D9F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.6","versionEndExcluding":"15.6.1","matchCriteriaId":"632F5D27-1D6E-4B5A-B82F-8F472DFF0BB3"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4335.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/353018","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1462437","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4335.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/353018","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1462437","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-4201","sourceIdentifier":"cve@gitlab.com","published":"2023-01-27T22:15:08.913","lastModified":"2026-06-17T05:20:14.170","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A blind SSRF in GitLab CE/EE affecting all from 11.3 prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 allows an attacker to connect to local addresses when configuring a malicious GitLab Runner."},{"lang":"es","value":"Un blind SSRF en GitLab CE/EE que afecta a todas las versiones 11.3 anteriores a 15.4.6, 15.5 anteriores a 15.5.5 y 15.6 anteriores a 15.6.1 permite a un atacante conectarse a direcciones locales al configurar un GitLab Runner malicioso."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=11.3, <15.4.6","status":"affected"},{"version":">=15.5, <15.5.5","status":"affected"},{"version":">=15.6, <15.6.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N","baseScore":3.5,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-03-27T20:20:53.231292Z","id":"CVE-2022-4201","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"15.4.6","matchCriteriaId":"BFD3D2ED-9A77-4CEC-B09B-182CD984DA4B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"15.4.6","matchCriteriaId":"34D21C08-2445-4D1D-8FEF-EF01AF1D9371"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.5.0","versionEndExcluding":"15.5.5","matchCriteriaId":"C2CF4BFC-D5A9-49F5-AC0E-A5978B8D8CFD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.5.0","versionEndExcluding":"15.5.5","matchCriteriaId":"C734804C-B835-493E-8A2B-556547368D9F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.6.0:*:*:*:community:*:*:*","matchCriteriaId":"B5CD27BD-9171-4958-9E31-FA35229B39E7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.6.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"D1DA9696-F8DA-4C34-AB21-7DE509454B82"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4201.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/30376","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4201.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/30376","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2022-4205","sourceIdentifier":"cve@gitlab.com","published":"2023-01-27T22:15:08.997","lastModified":"2026-06-17T05:20:14.793","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In Gitlab EE/CE before 15.6.1, 15.5.5 and 15.4.6 using a branch with a hexadecimal name could override an existing hash."},{"lang":"es","value":"En Gitlab EE/CE anterior a 15.6.1, 15.5.5 y 15.4.6, el uso de una rama con un nombre hexadecimal podía anular un hash existente."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=1.0, <12.9.8","status":"affected"},{"version":">=15.5, <15.5.5","status":"affected"},{"version":">=15.6, <15.6.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:L","baseScore":6.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":2.1,"impactScore":4.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-03-27T20:19:41.160588Z","id":"CVE-2022-4205","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-843"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-843"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"1.0.0","versionEndExcluding":"12.9.8","matchCriteriaId":"77EEFF96-5C9A-4E2A-986E-8908FD271BCC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"1.0.0","versionEndExcluding":"12.9.8","matchCriteriaId":"FC11B9D3-8CF9-4C4C-8322-5434E17F29FD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.5.0","versionEndExcluding":"15.5.5","matchCriteriaId":"C2CF4BFC-D5A9-49F5-AC0E-A5978B8D8CFD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.5.0","versionEndExcluding":"15.5.5","matchCriteriaId":"C734804C-B835-493E-8A2B-556547368D9F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.6.0:*:*:*:community:*:*:*","matchCriteriaId":"B5CD27BD-9171-4958-9E31-FA35229B39E7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.6.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"D1DA9696-F8DA-4C34-AB21-7DE509454B82"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4205.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/374082","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4205.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/374082","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2022-4255","sourceIdentifier":"cve@gitlab.com","published":"2023-01-27T22:15:09.073","lastModified":"2026-06-17T05:20:24.353","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An info leak issue was identified in all versions of GitLab EE from 13.7 prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 which exposes user email id through webhook payload."},{"lang":"es","value":"Se identificó un problema de fuga de información en todas las versiones de GitLab EE desde la 13.7 anterior a la 15.4.6, la 15.5 anterior a la 15.5.5 y la 15.6 anterior a la 15.6.1 que expone la identificación del correo electrónico del usuario a través de el payload del webhook."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.7, <15.4.6","status":"affected"},{"version":">=15.5, <15.5.5","status":"affected"},{"version":">=15.6, <15.6.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-03-27T20:16:57.832954Z","id":"CVE-2022-4255","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"15.4.6","matchCriteriaId":"B928A180-5CB4-4584-94F0-F84122B83BB3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"15.4.6","matchCriteriaId":"2A1EB64C-6BDB-467C-9E51-5D0A5F43B2E8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.5.0","versionEndExcluding":"15.5.5","matchCriteriaId":"C2CF4BFC-D5A9-49F5-AC0E-A5978B8D8CFD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.5.0","versionEndExcluding":"15.5.5","matchCriteriaId":"C734804C-B835-493E-8A2B-556547368D9F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.6.0:*:*:*:community:*:*:*","matchCriteriaId":"B5CD27BD-9171-4958-9E31-FA35229B39E7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.6.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"D1DA9696-F8DA-4C34-AB21-7DE509454B82"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4255.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/373819","source":"cve@gitlab.com","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4255.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/373819","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2022-3411","sourceIdentifier":"cve@gitlab.com","published":"2023-02-13T23:15:10.703","lastModified":"2026-06-17T04:59:28.470","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A lack of length validation in GitLab CE/EE affecting all versions from 12.4 before 15.6.7, 15.7 before 15.7.6, and 15.8 before 15.8.1 allows an authenticated attacker to create a large Issue description via GraphQL which, when repeatedly requested, saturates CPU usage."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.4, <15.6.7","status":"affected"},{"version":">=15.7, <15.7.6","status":"affected"},{"version":">=15.8, <15.8.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-03-21T18:39:12.640803Z","id":"CVE-2022-3411","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-1284"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-400"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.4","versionEndExcluding":"15.6.7","matchCriteriaId":"91EBC993-FF67-46EE-AEE4-C9EE116D5810"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.4","versionEndExcluding":"15.6.7","matchCriteriaId":"D1033402-8E91-4E97-8554-19A39C7ED3B3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.7","versionEndExcluding":"15.7.6","matchCriteriaId":"8005976E-EF1B-4F9D-B0AE-C1723E781FF8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.7","versionEndExcluding":"15.7.6","matchCriteriaId":"6B9DD4F3-3BDE-4B25-A4C2-B5CFD00139A9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.8","versionEndExcluding":"15.8.1","matchCriteriaId":"50EA48DD-AC48-40AE-97FE-BC88267418F4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.8","versionEndExcluding":"15.8.1","matchCriteriaId":"2933E1A4-77CE-4B7D-A612-4A61FD82BFD6"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3411.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/376247","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1685995","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3411.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/376247","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1685995","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2022-3759","sourceIdentifier":"cve@gitlab.com","published":"2023-02-13T23:15:11.357","lastModified":"2026-06-17T05:00:15.227","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.3 before 15.6.7, all versions starting from 15.7 before 15.7.6, all versions starting from 15.8 before 15.8.1. An attacker may upload a crafted CI job artifact zip file in a project that uses dynamic child pipelines and make a sidekiq job allocate a lot of memory. In GitLab instances where Sidekiq is memory-limited, this may cause Denial of Service."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=14.3, <15.6.7","status":"affected"},{"version":">=15.7, <15.7.6","status":"affected"},{"version":">=15.8, <15.8.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-03-21T18:38:20.240685Z","id":"CVE-2022-3759","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-400"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.3","versionEndExcluding":"15.6.7","matchCriteriaId":"2B9A69D4-B129-4B4E-A06C-A61691E9488E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.3","versionEndExcluding":"15.6.7","matchCriteriaId":"4733B387-B692-46AF-8878-124FF3ED7C39"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.7","versionEndExcluding":"15.7.6","matchCriteriaId":"8005976E-EF1B-4F9D-B0AE-C1723E781FF8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.7","versionEndExcluding":"15.7.6","matchCriteriaId":"6B9DD4F3-3BDE-4B25-A4C2-B5CFD00139A9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.8","versionEndExcluding":"15.8.1","matchCriteriaId":"50EA48DD-AC48-40AE-97FE-BC88267418F4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.8","versionEndExcluding":"15.8.1","matchCriteriaId":"2933E1A4-77CE-4B7D-A612-4A61FD82BFD6"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3759.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/379633","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1736230","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3759.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/379633","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1736230","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/379633","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2022-4138","sourceIdentifier":"cve@gitlab.com","published":"2023-02-13T23:15:11.493","lastModified":"2026-06-17T05:20:03.567","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A Cross Site Request Forgery issue has been discovered in GitLab CE/EE affecting all versions before 15.6.7, all versions starting from 15.7 before 15.7.6, and all versions starting from 15.8 before 15.8.1. An attacker could take over a project if an Owner or Maintainer uploads a file to a malicious project."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">= 1.0, <15.6.7","status":"affected"},{"version":">=15.7, <15.7.6","status":"affected"},{"version":">=15.8, <15.8.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-03-21T19:13:06.642797Z","id":"CVE-2022-4138","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-352"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-352"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"15.6.7","matchCriteriaId":"16919490-D6BE-4C77-A005-9EEC85E82241"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"15.6.7","matchCriteriaId":"390A954C-37F1-4E92-8FAC-6862E414EA51"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.7","versionEndExcluding":"15.7.6","matchCriteriaId":"8005976E-EF1B-4F9D-B0AE-C1723E781FF8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.7","versionEndExcluding":"15.7.6","matchCriteriaId":"6B9DD4F3-3BDE-4B25-A4C2-B5CFD00139A9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.8","versionEndExcluding":"15.8.1","matchCriteriaId":"50EA48DD-AC48-40AE-97FE-BC88267418F4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.8","versionEndExcluding":"15.8.1","matchCriteriaId":"2933E1A4-77CE-4B7D-A612-4A61FD82BFD6"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4138.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/383709","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1778009","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4138.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/383709","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1778009","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-0518","sourceIdentifier":"cve@gitlab.com","published":"2023-02-13T23:15:11.617","lastModified":"2026-06-17T05:25:43.880","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0 before 15.6.7, all versions starting from 15.7 before 15.7.6, all versions starting from 15.8 before 15.8.1. It was possible to trigger a DoS attack by uploading a malicious Helm chart."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=14.0, <15.6.7","status":"affected"},{"version":">=15.7, <15.7.6","status":"affected"},{"version":">=15.8, <15.8.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-03-21T19:13:52.747916Z","id":"CVE-2023-0518","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-400"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.0","versionEndExcluding":"15.6.7","matchCriteriaId":"BCF07502-8EFF-4609-926F-33B90E584DC9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.0","versionEndExcluding":"15.6.7","matchCriteriaId":"7E17CE19-D47F-4DD2-BB96-14586ABDA9BB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.7","versionEndExcluding":"15.7.6","matchCriteriaId":"8005976E-EF1B-4F9D-B0AE-C1723E781FF8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.7","versionEndExcluding":"15.7.6","matchCriteriaId":"6B9DD4F3-3BDE-4B25-A4C2-B5CFD00139A9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.8","versionEndExcluding":"15.8.1","matchCriteriaId":"50EA48DD-AC48-40AE-97FE-BC88267418F4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.8","versionEndExcluding":"15.8.1","matchCriteriaId":"2933E1A4-77CE-4B7D-A612-4A61FD82BFD6"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-0518.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/383082","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1766973","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-0518.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/383082","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1766973","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2022-4007","sourceIdentifier":"cve@gitlab.com","published":"2023-03-08T23:15:10.817","lastModified":"2026-06-17T05:19:44.390","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A issue has been discovered in GitLab CE/EE affecting all versions from 15.3 prior to 15.7.8, version 15.8 prior to 15.8.4, and version 15.9 prior to 15.9.2 A cross-site scripting vulnerability was found in the title field of work items that allowed attackers to perform arbitrary actions on behalf of victims at client side."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=15.3, <15.7.8","status":"affected"},{"version":">=15.8, <15.8.4","status":"affected"},{"version":">=15.9, <15.9.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-03-05T15:14:38.886120Z","id":"CVE-2022-4007","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.3","versionEndExcluding":"15.7.8","matchCriteriaId":"F0DAF847-94F0-4F77-B57C-E623839ED146"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.3","versionEndExcluding":"15.7.8","matchCriteriaId":"F7BD4713-D4AE-4B93-B117-099ECF4A1052"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.8.0","versionEndExcluding":"15.8.4","matchCriteriaId":"FE6EB324-C51D-4653-9CD4-6BB5100F0BC1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.8.0","versionEndExcluding":"15.8.4","matchCriteriaId":"DB9FE3DB-595E-413B-BE25-2181038A6B96"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.9.0","versionEndExcluding":"15.9.2","matchCriteriaId":"22AC1EB0-2D0F-4839-934F-847C5265F469"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.9.0","versionEndExcluding":"15.9.2","matchCriteriaId":"3FD1CDF6-AD2F-462B-B9DB-3071F4B61396"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4007.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/382789","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1767745","source":"cve@gitlab.com","tags":["Broken Link","Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4007.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/382789","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1767745","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Permissions Required"]}]}},{"cve":{"id":"CVE-2022-4462","sourceIdentifier":"cve@gitlab.com","published":"2023-03-09T20:15:09.353","lastModified":"2026-06-17T05:20:55.777","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 12.8 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. This vulnerability could allow a user to unmask the Discord Webhook URL through viewing the raw API response."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.8, <15.7.8","status":"affected"},{"version":">=15.8, <15.8.4","status":"affected"},{"version":">=15.9, <15.9.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N","baseScore":5.0,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-28T21:27:03.653036Z","id":"CVE-2022-4462","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.8.0","versionEndExcluding":"15.7.8","matchCriteriaId":"B250D53A-6A92-4C41-8739-919D7595F281"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.8.0","versionEndExcluding":"15.7.8","matchCriteriaId":"42B09CDE-A581-4C8C-801D-189037EDFA6D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.8.0","versionEndExcluding":"15.8.4","matchCriteriaId":"FE6EB324-C51D-4653-9CD4-6BB5100F0BC1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.8.0","versionEndExcluding":"15.8.4","matchCriteriaId":"DB9FE3DB-595E-413B-BE25-2181038A6B96"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.9.0","versionEndExcluding":"15.9.2","matchCriteriaId":"22AC1EB0-2D0F-4839-934F-847C5265F469"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.9.0","versionEndExcluding":"15.9.2","matchCriteriaId":"3FD1CDF6-AD2F-462B-B9DB-3071F4B61396"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4462.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/385669","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1796210","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4462.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/385669","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1796210","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-0483","sourceIdentifier":"cve@gitlab.com","published":"2023-03-09T20:15:09.427","lastModified":"2026-06-17T05:25:39.333","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 12.1 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. It was possible for a project maintainer to extract a Datadog integration API key by modifying the site."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.1, <15.7.8","status":"affected"},{"version":">=15.8, <15.8.4","status":"affected"},{"version":">=15.9, <15.9.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N","baseScore":3.8,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-28T21:31:11.889066Z","id":"CVE-2023-0483","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"15.7.8","matchCriteriaId":"12FB01B7-042A-4EED-A591-04263172A7BC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"15.7.8","matchCriteriaId":"C1CD74A0-FF1D-4904-9BD1-492FF77A70DD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.8.0","versionEndExcluding":"15.8.4","matchCriteriaId":"FE6EB324-C51D-4653-9CD4-6BB5100F0BC1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.8.0","versionEndExcluding":"15.8.4","matchCriteriaId":"DB9FE3DB-595E-413B-BE25-2181038A6B96"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.9.0","versionEndExcluding":"15.9.2","matchCriteriaId":"22AC1EB0-2D0F-4839-934F-847C5265F469"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.9.0","versionEndExcluding":"15.9.2","matchCriteriaId":"3FD1CDF6-AD2F-462B-B9DB-3071F4B61396"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-0483.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/389188","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1836466","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-0483.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/389188","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1836466","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-1084","sourceIdentifier":"cve@gitlab.com","published":"2023-03-09T20:15:09.497","lastModified":"2026-06-17T05:27:04.350","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. A malicious project Maintainer may create a Project Access Token with Owner level privileges using a crafted request."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=0.0, <15.7.8","status":"affected"},{"version":">=15.8, <15.8.4","status":"affected"},{"version":">=15.9, <15.9.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N","baseScore":2.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N","baseScore":2.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-28T21:34:04.704265Z","id":"CVE-2023-1084","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"15.7.8","matchCriteriaId":"AD9730B5-0E23-428F-9338-01B8E8DADCAF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"15.7.8","matchCriteriaId":"8CD22E6C-1ACA-4232-A35E-56010B267778"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.8.0","versionEndExcluding":"15.8.4","matchCriteriaId":"FE6EB324-C51D-4653-9CD4-6BB5100F0BC1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.8.0","versionEndExcluding":"15.8.4","matchCriteriaId":"DB9FE3DB-595E-413B-BE25-2181038A6B96"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.9.0","versionEndExcluding":"15.9.2","matchCriteriaId":"22AC1EB0-2D0F-4839-934F-847C5265F469"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.9.0","versionEndExcluding":"15.9.2","matchCriteriaId":"3FD1CDF6-AD2F-462B-B9DB-3071F4B61396"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1084.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/390696","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1805549","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1084.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/390696","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1805549","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2022-3381","sourceIdentifier":"cve@gitlab.com","published":"2023-03-09T21:15:10.687","lastModified":"2026-06-17T04:59:25.450","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 10.0 to 15.7.8, 15.8 prior to 15.8.4 and 15.9 prior to 15.9.2. A crafted URL could be used to redirect users to arbitrary sites"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=10.0, <15.7.8","status":"affected"},{"version":">=15.8, <15.8.4","status":"affected"},{"version":">=15.9, <15.9.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-28T17:31:28.290570Z","id":"CVE-2022-3381","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-601"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.0.0","versionEndExcluding":"15.7.8","matchCriteriaId":"5E4A6ADC-694B-46C5-B7AD-7D12A6243F06"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.0.0","versionEndExcluding":"15.7.8","matchCriteriaId":"D5C5FDFB-DB61-4E42-9992-09E8A2F6A9BF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.8.0","versionEndExcluding":"15.8.4","matchCriteriaId":"FE6EB324-C51D-4653-9CD4-6BB5100F0BC1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.8.0","versionEndExcluding":"15.8.4","matchCriteriaId":"DB9FE3DB-595E-413B-BE25-2181038A6B96"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.9.0","versionEndExcluding":"15.9.2","matchCriteriaId":"22AC1EB0-2D0F-4839-934F-847C5265F469"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.9.0","versionEndExcluding":"15.9.2","matchCriteriaId":"3FD1CDF6-AD2F-462B-B9DB-3071F4B61396"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3381.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/376046","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1711497","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3381.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/376046","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1711497","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2022-4289","sourceIdentifier":"cve@gitlab.com","published":"2023-03-09T21:15:10.777","lastModified":"2026-06-17T05:20:29.810","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 15.3 before 15.7.8, versions of 15.8 before 15.8.4, and version 15.9 before 15.9.2. Google IAP details in Prometheus integration were not hidden, could be leaked from instance, group, or project settings to other users."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=15.3, <15.7.8","status":"affected"},{"version":">=15.8, <15.8.4","status":"affected"},{"version":">=15.9, <15.9.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.3.0","versionEndExcluding":"15.7.8","matchCriteriaId":"39FEEA34-7A45-4354-A7CD-F3ED9ACFD961"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.3.0","versionEndExcluding":"15.7.8","matchCriteriaId":"DEFE1317-54AD-437B-AD1B-26E4F0FBFDDA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.8.0","versionEndExcluding":"15.8.4","matchCriteriaId":"FE6EB324-C51D-4653-9CD4-6BB5100F0BC1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.8.0","versionEndExcluding":"15.8.4","matchCriteriaId":"DB9FE3DB-595E-413B-BE25-2181038A6B96"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.9.0","versionEndExcluding":"15.9.2","matchCriteriaId":"22AC1EB0-2D0F-4839-934F-847C5265F469"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.9.0","versionEndExcluding":"15.9.2","matchCriteriaId":"3FD1CDF6-AD2F-462B-B9DB-3071F4B61396"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4289.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/384580","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1780770","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://security.netapp.com/advisory/ntap-20240415-0004/","source":"cve@gitlab.com"},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4289.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/384580","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1780770","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]},{"url":"https://security.netapp.com/advisory/ntap-20240415-0004/","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2023-0223","sourceIdentifier":"cve@gitlab.com","published":"2023-03-09T21:15:10.860","lastModified":"2026-06-17T05:25:03.610","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 15.5 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. Non-project members could retrieve release descriptions via the API, even if the release visibility is restricted to project members only in the project settings."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=15.5, <15.7.8","status":"affected"},{"version":">=15.8, <15.8.4","status":"affected"},{"version":">=15.9, <15.9.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-28T21:29:30.352704Z","id":"CVE-2023-0223","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.5.0","versionEndExcluding":"15.7.8","matchCriteriaId":"8C8F9224-14CF-43FF-B0FB-4803FBF05EE8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.5.0","versionEndExcluding":"15.7.8","matchCriteriaId":"FBFE78E3-83FE-401D-B556-B9F6690E3B47"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.8.0","versionEndExcluding":"15.8.4","matchCriteriaId":"FE6EB324-C51D-4653-9CD4-6BB5100F0BC1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.8.0","versionEndExcluding":"15.8.4","matchCriteriaId":"DB9FE3DB-595E-413B-BE25-2181038A6B96"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.9.0","versionEndExcluding":"15.9.2","matchCriteriaId":"22AC1EB0-2D0F-4839-934F-847C5265F469"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.9.0","versionEndExcluding":"15.9.2","matchCriteriaId":"3FD1CDF6-AD2F-462B-B9DB-3071F4B61396"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-0223.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/387870","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1824226","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-0223.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/387870","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1824226","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2022-4331","sourceIdentifier":"cve@gitlab.com","published":"2023-03-09T22:15:51.447","lastModified":"2026-06-17T05:20:36.917","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions starting from 15.1 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. If a group with SAML SSO enabled is transferred to a new namespace as a child group, it's possible previously removed malicious maintainer or owner of the child group can still gain access to the group via SSO or a SCIM token to perform actions on the group."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=15.1, <15.7.8","status":"affected"},{"version":">=15.8, <15.8.4","status":"affected"},{"version":">=15.9, <15.9.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N","baseScore":5.7,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":0.5,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-28T17:24:15.912188Z","id":"CVE-2022-4331","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.1","versionEndExcluding":"15.7.8","matchCriteriaId":"CCE868CE-F7B2-43BC-AC81-C92CE4FA877B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.8","versionEndExcluding":"15.8.4","matchCriteriaId":"124D53C4-ACD0-4C2A-9E95-5E7E7B1BACF6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.9","versionEndExcluding":"15.9.2","matchCriteriaId":"57BB437C-433D-430B-8B1B-3C3B053C9360"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4331.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/385050","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1791518","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4331.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/385050","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1791518","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-0050","sourceIdentifier":"cve@gitlab.com","published":"2023-03-09T22:15:51.523","lastModified":"2026-06-17T05:24:39.957","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 13.7 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. A specially crafted Kroki diagram could lead to a stored XSS on the client side which allows attackers to perform arbitrary actions on behalf of victims."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.7, <15.7.8","status":"affected"},{"version":">=15.8, <15.8.4","status":"affected"},{"version":">=15.9, <15.9.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-28T21:28:22.377964Z","id":"CVE-2023-0050","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.7","versionEndExcluding":"15.7.8","matchCriteriaId":"41C5C799-40FF-443C-9196-ED79CC776A9D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.7","versionEndExcluding":"15.7.8","matchCriteriaId":"01D35134-830D-43A0-923E-EB53FF19984D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.8","versionEndExcluding":"15.8.4","matchCriteriaId":"89B81A26-8FF6-4745-A9F4-3F7A3CFCB943"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.8","versionEndExcluding":"15.8.4","matchCriteriaId":"124D53C4-ACD0-4C2A-9E95-5E7E7B1BACF6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.9","versionEndExcluding":"15.9.2","matchCriteriaId":"3D2A72D7-C712-440D-91F9-D7EBF93EA1F9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.9","versionEndExcluding":"15.9.2","matchCriteriaId":"57BB437C-433D-430B-8B1B-3C3B053C9360"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-0050.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/387023","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1731349","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-0050.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/387023","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1731349","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-1072","sourceIdentifier":"cve@gitlab.com","published":"2023-03-09T22:15:51.810","lastModified":"2026-06-17T05:27:02.403","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 9.0 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. It was possible to trigger a resource depletion attack due to improper filtering for number of requests to read commits details."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=9.0, <15.7.8","status":"affected"},{"version":">=15.8, <15.8.4","status":"affected"},{"version":">=15.9, <15.9.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-28T21:32:50.167068Z","id":"CVE-2023-1072","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-400"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"9.0","versionEndExcluding":"15.7.8","matchCriteriaId":"AD2F3C70-9E35-48BA-917E-4AE3E30114C9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"9.0","versionEndExcluding":"15.7.8","matchCriteriaId":"B860F565-7D1F-4FFC-A5D8-0015807F1DA4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.8","versionEndExcluding":"15.8.4","matchCriteriaId":"89B81A26-8FF6-4745-A9F4-3F7A3CFCB943"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.8","versionEndExcluding":"15.8.4","matchCriteriaId":"124D53C4-ACD0-4C2A-9E95-5E7E7B1BACF6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.9","versionEndExcluding":"15.9.2","matchCriteriaId":"3D2A72D7-C712-440D-91F9-D7EBF93EA1F9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.9","versionEndExcluding":"15.9.2","matchCriteriaId":"57BB437C-433D-430B-8B1B-3C3B053C9360"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1072.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/219619","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1072.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/219619","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2022-3758","sourceIdentifier":"cve@gitlab.com","published":"2023-03-09T23:15:10.753","lastModified":"2026-06-17T05:00:15.107","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 15.5 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. Due to improper permissions checks an unauthorised user was able to read, add or edit a users private snippet."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=15.5, <15.7.8","status":"affected"},{"version":">=15.8, <15.8.4","status":"affected"},{"version":">=15.9, <15.9.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-28T17:30:33.446332Z","id":"CVE-2022-3758","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-276"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.5.0","versionEndExcluding":"15.7.8","matchCriteriaId":"8C8F9224-14CF-43FF-B0FB-4803FBF05EE8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.5.0","versionEndExcluding":"15.7.8","matchCriteriaId":"FBFE78E3-83FE-401D-B556-B9F6690E3B47"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.8.0","versionEndExcluding":"15.8.4","matchCriteriaId":"FE6EB324-C51D-4653-9CD4-6BB5100F0BC1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.8.0","versionEndExcluding":"15.8.4","matchCriteriaId":"DB9FE3DB-595E-413B-BE25-2181038A6B96"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.9.0","versionEndExcluding":"15.9.2","matchCriteriaId":"22AC1EB0-2D0F-4839-934F-847C5265F469"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.9.0","versionEndExcluding":"15.9.2","matchCriteriaId":"3FD1CDF6-AD2F-462B-B9DB-3071F4B61396"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3758.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/379598","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1751258","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3758.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/379598","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1751258","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2022-3375","sourceIdentifier":"cve@gitlab.com","published":"2023-04-05T20:15:07.290","lastModified":"2026-06-17T04:59:24.743","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 11.10 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. It was possible to disclose the branch names when attacker has a fork of a project that was switched to private."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=11.10, <15.8.5","status":"affected"},{"version":">=15.9, <15.9.4","status":"affected"},{"version":">=15.10, <15.10.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":3.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":3.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-10T21:10:57.402815Z","id":"CVE-2022-3375","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-535"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.10.0","versionEndExcluding":"15.8.5","matchCriteriaId":"1B9565EF-8F06-4BAB-A386-0E0190B69C7F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.10.0","versionEndExcluding":"15.8.5","matchCriteriaId":"D6FCCE23-6B2E-4683-A8A2-CE70011BE7B1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.9.0","versionEndExcluding":"15.9.4","matchCriteriaId":"130F61DA-5561-49A8-8024-88D12819F2E1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.9.0","versionEndExcluding":"15.9.4","matchCriteriaId":"E10FDADF-D6E5-402E-8834-F9BD274FBE2D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.10.0:*:*:*:community:*:*:*","matchCriteriaId":"7803BD85-A126-49E0-8DEC-3D0E98A0CAE1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.10.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"7D831DA8-EE49-41A1-AE77-E8B51E8458A4"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3375.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/376041","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1710533","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3375.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/376041","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1710533","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2022-3513","sourceIdentifier":"cve@gitlab.com","published":"2023-04-05T20:15:07.350","lastModified":"2026-06-17T04:59:40.050","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 12.8 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. A specially crafted payload could lead to a reflected XSS on the client side which allows attackers to perform arbitrary actions on behalf of victims on self-hosted instances running without strict CSP."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.8, <15.8.5","status":"affected"},{"version":">=15.9, <15.9.4","status":"affected"},{"version":">=15.10, <15.10.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-11T16:12:22.982852Z","id":"CVE-2022-3513","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.8.0","versionEndExcluding":"15.8.5","matchCriteriaId":"8615F826-D086-4DA8-8B63-9393436B6AD3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.8.0","versionEndExcluding":"15.8.5","matchCriteriaId":"3C14C16A-9694-47AE-AF55-D599A26A40F7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.9.0","versionEndExcluding":"15.9.4","matchCriteriaId":"130F61DA-5561-49A8-8024-88D12819F2E1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.9.0","versionEndExcluding":"15.9.4","matchCriteriaId":"E10FDADF-D6E5-402E-8834-F9BD274FBE2D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.10.0:*:*:*:community:*:*:*","matchCriteriaId":"7803BD85-A126-49E0-8DEC-3D0E98A0CAE1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.10.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"7D831DA8-EE49-41A1-AE77-E8B51E8458A4"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3513.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/377970","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1728015","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3513.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/377970","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1728015","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-0319","sourceIdentifier":"cve@gitlab.com","published":"2023-04-05T20:15:07.403","lastModified":"2026-06-17T05:25:16.620","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 13.6 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1, allowing to read environment names supposed to be restricted to project memebers only."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.6, <15.8.5","status":"affected"},{"version":">=15.9, <15.9.4","status":"affected"},{"version":">=15.10, <15.10.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N","baseScore":5.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-11T16:09:07.621123Z","id":"CVE-2023-0319","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.6.0","versionEndExcluding":"15.8.5","matchCriteriaId":"0E6E5C40-20A6-46DE-BEF9-141EC41D25C9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.6.0","versionEndExcluding":"15.8.5","matchCriteriaId":"E23868FF-759F-4813-8193-01AC30479C0F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.9.0","versionEndExcluding":"15.9.4","matchCriteriaId":"130F61DA-5561-49A8-8024-88D12819F2E1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.9.0","versionEndExcluding":"15.9.4","matchCriteriaId":"E10FDADF-D6E5-402E-8834-F9BD274FBE2D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.10.0:*:*:*:community:*:*:*","matchCriteriaId":"7803BD85-A126-49E0-8DEC-3D0E98A0CAE1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.10.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"7D831DA8-EE49-41A1-AE77-E8B51E8458A4"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-0319.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/388096","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1817586","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-0319.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/388096","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1817586","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-0523","sourceIdentifier":"cve@gitlab.com","published":"2023-04-05T20:15:07.443","lastModified":"2026-06-17T05:25:44.433","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 15.6 before 15.8.5, 15.9 before 15.9.4, and 15.10 before 15.10.1. An XSS was possible via a malicious email address for certain instances."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=15.6, <15.8.5","status":"affected"},{"version":">=15.9, <15.9.4","status":"affected"},{"version":">=15.10, <15.10.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-10T21:09:27.301140Z","id":"CVE-2023-0523","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.6.0","versionEndExcluding":"15.8.5","matchCriteriaId":"482B0E4F-5230-4787-96C7-FB28AC313B7A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.6.0","versionEndIncluding":"15.8.5","matchCriteriaId":"C3DFF460-CB1C-4C61-82DC-DE932FB42484"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.9.0","versionEndExcluding":"15.9.4","matchCriteriaId":"130F61DA-5561-49A8-8024-88D12819F2E1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.9.0","versionEndExcluding":"15.9.4","matchCriteriaId":"E10FDADF-D6E5-402E-8834-F9BD274FBE2D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.10.0:*:*:*:community:*:*:*","matchCriteriaId":"7803BD85-A126-49E0-8DEC-3D0E98A0CAE1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.10.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"7D831DA8-EE49-41A1-AE77-E8B51E8458A4"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-0523.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/389487","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1842867","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-0523.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/389487","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1842867","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-1098","sourceIdentifier":"cve@gitlab.com","published":"2023-04-05T20:15:07.623","lastModified":"2026-06-17T05:27:06.593","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An information disclosure vulnerability has been discovered in GitLab EE/CE affecting all versions starting from 11.5 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1 will allow an admin to leak password from repository mirror configuration."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=11.5, <15.8.5","status":"affected"},{"version":">=15.9, <15.9.4","status":"affected"},{"version":">=15.10, <15.10.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N","baseScore":5.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.3,"impactScore":4.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-10T20:57:56.837476Z","id":"CVE-2023-1098","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-535"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"15.8.5","matchCriteriaId":"13C36E7B-CBC2-449D-B035-1F956BDFA0CB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"15.8.5","matchCriteriaId":"DD4E75D8-6385-450C-879B-2E0C3A6DF6CC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.9.0","versionEndExcluding":"15.9.4","matchCriteriaId":"130F61DA-5561-49A8-8024-88D12819F2E1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.9.0","versionEndExcluding":"15.9.4","matchCriteriaId":"E10FDADF-D6E5-402E-8834-F9BD274FBE2D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.10.0:*:*:*:community:*:*:*","matchCriteriaId":"7803BD85-A126-49E0-8DEC-3D0E98A0CAE1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.10.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"7D831DA8-EE49-41A1-AE77-E8B51E8458A4"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1098.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/383745","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1784294","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1098.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/383745","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1784294","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-1733","sourceIdentifier":"cve@gitlab.com","published":"2023-04-05T20:15:07.707","lastModified":"2026-06-17T05:28:38.300","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A denial of service condition exists in the Prometheus server bundled with GitLab affecting all versions from 11.10 to 15.8.5, 15.9 to 15.9.4 and 15.10 to 15.10.1."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=11.10, <15.8.5","status":"affected"},{"version":">=15.9, <15.9.4","status":"affected"},{"version":">=15.10, <15.10.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L","baseScore":5.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-10T20:45:04.802139Z","id":"CVE-2023-1733","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-400"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.10.0","versionEndExcluding":"15.8.5","matchCriteriaId":"1B9565EF-8F06-4BAB-A386-0E0190B69C7F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.10.0","versionEndExcluding":"15.8.5","matchCriteriaId":"D6FCCE23-6B2E-4683-A8A2-CE70011BE7B1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.9.0","versionEndExcluding":"15.9.4","matchCriteriaId":"130F61DA-5561-49A8-8024-88D12819F2E1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.9.0","versionEndExcluding":"15.9.4","matchCriteriaId":"E10FDADF-D6E5-402E-8834-F9BD274FBE2D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.10.0:*:*:*:community:*:*:*","matchCriteriaId":"7803BD85-A126-49E0-8DEC-3D0E98A0CAE1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.10.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"7D831DA8-EE49-41A1-AE77-E8B51E8458A4"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1733.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/392665","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1723124","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1733.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/392665","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1723124","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-0450","sourceIdentifier":"cve@gitlab.com","published":"2023-04-05T21:15:07.097","lastModified":"2026-06-17T05:25:34.557","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 8.1 to 15.8.5, and from 15.9 to 15.9.4, and from 15.10 to 15.10.1. It was possible to add a branch with an ambiguous name that could be used to social engineer users."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=8.1, <15.8.5","status":"affected"},{"version":">=15.9, <15.9.4","status":"affected"},{"version":">=15.10, <15.10.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N","baseScore":3.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":2.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N","baseScore":4.6,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-11T15:29:20.854471Z","id":"CVE-2023-0450","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.1.0","versionEndExcluding":"15.8.5","matchCriteriaId":"8B1B32A5-101D-42DD-98CF-2BA5F0D1A5D1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.1.0","versionEndExcluding":"15.8.5","matchCriteriaId":"4967C233-160A-4FFC-998E-5FD654FB25FA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.9.0","versionEndExcluding":"15.9.4","matchCriteriaId":"130F61DA-5561-49A8-8024-88D12819F2E1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.9.0","versionEndExcluding":"15.9.4","matchCriteriaId":"E10FDADF-D6E5-402E-8834-F9BD274FBE2D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.10.0:*:*:*:community:*:*:*","matchCriteriaId":"7803BD85-A126-49E0-8DEC-3D0E98A0CAE1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.10.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"7D831DA8-EE49-41A1-AE77-E8B51E8458A4"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-0450.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/388962","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1831547","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-0450.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/388962","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1831547","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-0838","sourceIdentifier":"cve@gitlab.com","published":"2023-04-05T21:15:07.153","lastModified":"2026-06-17T05:26:25.517","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting versions starting from 15.1 before 15.8.5, 15.9 before 15.9.4, and 15.10 before 15.10.1. A maintainer could modify a webhook URL to leak masked webhook secrets by adding a new parameter to the url. This addresses an incomplete fix for CVE-2022-4342."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=15.1, <15.8.5","status":"affected"},{"version":">=15.9, <15.9.4","status":"affected"},{"version":">=15.10, <15.10.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N","baseScore":3.8,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-10T20:59:35.897823Z","id":"CVE-2023-0838","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-200"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.1.0","versionEndExcluding":"15.8.5","matchCriteriaId":"8A5E15F9-D6D7-4BD7-A4BC-D46D6EBF07B3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.1.0","versionEndExcluding":"15.8.5","matchCriteriaId":"FFE0EC05-6B4D-4AC8-A25F-EBFAC6629CF8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.9.0","versionEndExcluding":"15.9.4","matchCriteriaId":"130F61DA-5561-49A8-8024-88D12819F2E1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.9.0","versionEndExcluding":"15.9.4","matchCriteriaId":"E10FDADF-D6E5-402E-8834-F9BD274FBE2D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.10.0:*:*:*:community:*:*:*","matchCriteriaId":"7803BD85-A126-49E0-8DEC-3D0E98A0CAE1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.10.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"7D831DA8-EE49-41A1-AE77-E8B51E8458A4"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-0838.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/391685","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1871136","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-0838.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/391685","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1871136","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-1071","sourceIdentifier":"cve@gitlab.com","published":"2023-04-05T21:15:07.200","lastModified":"2026-06-17T05:27:02.260","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions from 15.5 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. Due to improper permissions checks it was possible for an unauthorised user to remove an issue from an epic."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=15.5, <15.8.5","status":"affected"},{"version":">=15.9, <15.9.4","status":"affected"},{"version":">=15.10, <15.10.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":3.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-10T20:58:37.290511Z","id":"CVE-2023-1071","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-400"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.5.0","versionEndExcluding":"15.8.5","matchCriteriaId":"6DEC473C-C2BF-40DE-8A27-8039EA332061"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.5.0","versionEndExcluding":"15.8.5","matchCriteriaId":"80A8CAD3-BB1E-431E-A8F8-329F47E669C6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.9.0","versionEndExcluding":"15.9.4","matchCriteriaId":"130F61DA-5561-49A8-8024-88D12819F2E1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.9.0","versionEndExcluding":"15.9.4","matchCriteriaId":"E10FDADF-D6E5-402E-8834-F9BD274FBE2D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.10.0:*:*:*:community:*:*:*","matchCriteriaId":"7803BD85-A126-49E0-8DEC-3D0E98A0CAE1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.10.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"7D831DA8-EE49-41A1-AE77-E8B51E8458A4"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1071.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/385434","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1071.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/385434","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2023-1167","sourceIdentifier":"cve@gitlab.com","published":"2023-04-05T21:15:07.243","lastModified":"2026-06-17T05:27:16.160","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Improper authorization in Gitlab EE affecting all versions from 12.3.0 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1 allows an unauthorized access to security reports in MR."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.3.0, <15.8.5","status":"affected"},{"version":">=15.9, <15.9.4","status":"affected"},{"version":">=15.10, <15.10.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-10T20:52:39.535090Z","id":"CVE-2023-1167","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-285"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.3.0","versionEndExcluding":"15.8.5","matchCriteriaId":"FCE75D34-B6C7-4275-9630-8AEEFE40263A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.9.0","versionEndExcluding":"15.9.4","matchCriteriaId":"E10FDADF-D6E5-402E-8834-F9BD274FBE2D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.10.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"7D831DA8-EE49-41A1-AE77-E8B51E8458A4"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1167.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/392715","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1167.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/392715","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2023-1417","sourceIdentifier":"cve@gitlab.com","published":"2023-04-05T21:15:07.283","lastModified":"2026-06-17T05:27:54.977","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. It was possible for an unauthorised user to add child epics linked to victim's epic in an unrelated group."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=15.9, <15.9.4","status":"affected"},{"version":">=15.10, <15.10.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-11T15:26:20.397008Z","id":"CVE-2023-1417","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-639"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.9.0","versionEndExcluding":"15.9.4","matchCriteriaId":"130F61DA-5561-49A8-8024-88D12819F2E1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.9.0","versionEndExcluding":"15.9.4","matchCriteriaId":"E10FDADF-D6E5-402E-8834-F9BD274FBE2D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.10.0:*:*:*:community:*:*:*","matchCriteriaId":"7803BD85-A126-49E0-8DEC-3D0E98A0CAE1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.10.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"7D831DA8-EE49-41A1-AE77-E8B51E8458A4"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1417.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/396720","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1892200","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1417.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/396720","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1892200","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-1708","sourceIdentifier":"cve@gitlab.com","published":"2023-04-05T21:15:07.327","lastModified":"2026-06-17T05:28:35.157","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was identified in GitLab CE/EE affecting all versions from 1.0 prior to 15.8.5, 15.9 prior to 15.9.4, and 15.10 prior to 15.10.1 where non-printable characters gets copied from clipboard, allowing unexpected commands to be executed on victim machine."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=1.0, <15.8.5","status":"affected"},{"version":">=15.9, <15.9.4","status":"affected"},{"version":">=15.10, <15.10.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N","baseScore":5.7,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-10T20:51:48.137803Z","id":"CVE-2023-1708","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-77"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-94"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"1.0.0","versionEndExcluding":"15.8.5","matchCriteriaId":"89ADE59C-825E-4291-8FD7-80859A8BEB78"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"1.0.0","versionEndExcluding":"15.8.5","matchCriteriaId":"5A1F89C2-298A-4388-8792-AD6907E795CF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.9.0","versionEndExcluding":"15.9.4","matchCriteriaId":"130F61DA-5561-49A8-8024-88D12819F2E1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.9.0","versionEndExcluding":"15.9.4","matchCriteriaId":"E10FDADF-D6E5-402E-8834-F9BD274FBE2D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.10.0:*:*:*:community:*:*:*","matchCriteriaId":"7803BD85-A126-49E0-8DEC-3D0E98A0CAE1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.10.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"7D831DA8-EE49-41A1-AE77-E8B51E8458A4"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1708.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/387185","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1805604","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1708.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/387185","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1805604","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-1710","sourceIdentifier":"cve@gitlab.com","published":"2023-04-05T21:15:07.367","lastModified":"2026-06-17T05:28:35.470","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A sensitive information disclosure vulnerability in GitLab affecting all versions from 15.0 prior to 15.8.5, 15.9 prior to 15.9.4 and 15.10 prior to 15.10.1 allows an attacker to view the count of internal notes for a given issue."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=15.0, <15.8.5","status":"affected"},{"version":">=15.9, <15.9.4","status":"affected"},{"version":">=15.10, <15.10.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-10T20:49:20.604846Z","id":"CVE-2023-1710","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-200"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.0.0","versionEndExcluding":"15.8.5","matchCriteriaId":"674B9329-1779-40F7-97EF-B49DC0506B50"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.0.0","versionEndExcluding":"15.8.5","matchCriteriaId":"2DA9CDF4-F3AE-41DA-A39A-FB2AA887CB53"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.9.0","versionEndExcluding":"15.9.4","matchCriteriaId":"130F61DA-5561-49A8-8024-88D12819F2E1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.9.0","versionEndExcluding":"15.9.4","matchCriteriaId":"E10FDADF-D6E5-402E-8834-F9BD274FBE2D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.10.0:*:*:*:community:*:*:*","matchCriteriaId":"7803BD85-A126-49E0-8DEC-3D0E98A0CAE1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.10.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"7D831DA8-EE49-41A1-AE77-E8B51E8458A4"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1710.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/388242","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1829768","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1710.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/388242","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1829768","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-1787","sourceIdentifier":"cve@gitlab.com","published":"2023-04-05T21:15:07.410","lastModified":"2026-06-17T05:28:45.280","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. A search timeout could be triggered if a specific HTML payload was used in the issue description."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=15.9, <15.9.4","status":"affected"},{"version":">=15.10, <15.10.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-10T20:42:14.732862Z","id":"CVE-2023-1787","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-400"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.9.0","versionEndExcluding":"15.9.4","matchCriteriaId":"130F61DA-5561-49A8-8024-88D12819F2E1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.9.0","versionEndExcluding":"15.9.4","matchCriteriaId":"E10FDADF-D6E5-402E-8834-F9BD274FBE2D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.10.0:*:*:*:community:*:*:*","matchCriteriaId":"7803BD85-A126-49E0-8DEC-3D0E98A0CAE1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.10.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"7D831DA8-EE49-41A1-AE77-E8B51E8458A4"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1787.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/394817","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1787.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/394817","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2018-15472","sourceIdentifier":"cve@mitre.org","published":"2023-04-15T23:15:13.353","lastModified":"2026-06-17T01:42:34.877","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. The diff formatter using rouge can block for a long time in Sidekiq jobs without any timeout."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-10T15:08:27.161243Z","id":"CVE-2018-15472","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"11.1.7","matchCriteriaId":"56859B5B-7084-4F58-86B1-55591E4365AB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"11.1.7","matchCriteriaId":"EEE02913-00F2-4386-AADE-E830BF40428C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.2.0","versionEndExcluding":"11.2.4","matchCriteriaId":"9D4901BF-95A2-4A45-A9D9-0E01B29B4288"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.2.0","versionEndExcluding":"11.2.4","matchCriteriaId":"CEC44A89-760A-4238-A11F-A4504DF86D04"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.3.0:*:*:*:community:*:*:*","matchCriteriaId":"9BE513BE-9346-43DC-B9E3-169B84156063"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.3.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"A64EAF5E-EA4B-4E5D-B0FF-04FFD3422829"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes"]},{"url":"https://about.gitlab.com/releases/2018/10/01/security-release-gitlab-11-dot-3-dot-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"]},{"url":"https://about.gitlab.com/releases/2018/10/01/security-release-gitlab-11-dot-3-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-17449","sourceIdentifier":"cve@mitre.org","published":"2023-04-15T23:15:13.400","lastModified":"2026-06-17T01:45:51.553","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Remote attackers could obtain sensitive information about issues, comments, and project titles via events API insecure direct object reference."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-07T16:44:28.616511Z","id":"CVE-2018-17449","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-639"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-639"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"11.1.7","matchCriteriaId":"56859B5B-7084-4F58-86B1-55591E4365AB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"11.1.7","matchCriteriaId":"EEE02913-00F2-4386-AADE-E830BF40428C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.2.0","versionEndExcluding":"11.2.4","matchCriteriaId":"9D4901BF-95A2-4A45-A9D9-0E01B29B4288"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.2.0","versionEndExcluding":"11.2.4","matchCriteriaId":"CEC44A89-760A-4238-A11F-A4504DF86D04"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.3.0:*:*:*:community:*:*:*","matchCriteriaId":"9BE513BE-9346-43DC-B9E3-169B84156063"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.3.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"A64EAF5E-EA4B-4E5D-B0FF-04FFD3422829"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes"]},{"url":"https://about.gitlab.com/releases/2018/10/01/security-release-gitlab-11-dot-3-dot-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"]},{"url":"https://about.gitlab.com/releases/2018/10/01/security-release-gitlab-11-dot-3-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-17450","sourceIdentifier":"cve@mitre.org","published":"2023-04-15T23:15:13.440","lastModified":"2026-06-17T01:45:51.780","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Server-Side Request Forgery (SSRF) via the Kubernetes integration, leading (for example) to disclosure of a GCP service token."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-06T20:38:02.400789Z","id":"CVE-2018-17450","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"11.1.7","matchCriteriaId":"56859B5B-7084-4F58-86B1-55591E4365AB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"11.1.7","matchCriteriaId":"EEE02913-00F2-4386-AADE-E830BF40428C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.2.0","versionEndExcluding":"11.2.4","matchCriteriaId":"9D4901BF-95A2-4A45-A9D9-0E01B29B4288"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.2.0","versionEndExcluding":"11.2.4","matchCriteriaId":"CEC44A89-760A-4238-A11F-A4504DF86D04"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.3.0:*:*:*:community:*:*:*","matchCriteriaId":"9BE513BE-9346-43DC-B9E3-169B84156063"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.3.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"A64EAF5E-EA4B-4E5D-B0FF-04FFD3422829"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes"]},{"url":"https://about.gitlab.com/releases/2018/10/01/security-release-gitlab-11-dot-3-dot-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"]},{"url":"https://about.gitlab.com/releases/2018/10/01/security-release-gitlab-11-dot-3-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-17451","sourceIdentifier":"cve@mitre.org","published":"2023-04-15T23:15:13.480","lastModified":"2026-06-17T01:45:51.997","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Cross Site Request Forgery (CSRF) in the Slack integration for issuing slash commands."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-06T20:36:38.086493Z","id":"CVE-2018-17451","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-352"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-352"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"11.1.7","matchCriteriaId":"56859B5B-7084-4F58-86B1-55591E4365AB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"11.1.7","matchCriteriaId":"EEE02913-00F2-4386-AADE-E830BF40428C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.2.0","versionEndExcluding":"11.2.4","matchCriteriaId":"9D4901BF-95A2-4A45-A9D9-0E01B29B4288"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.2.0","versionEndExcluding":"11.2.4","matchCriteriaId":"CEC44A89-760A-4238-A11F-A4504DF86D04"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.3.0:*:*:*:community:*:*:*","matchCriteriaId":"9BE513BE-9346-43DC-B9E3-169B84156063"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.3.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"A64EAF5E-EA4B-4E5D-B0FF-04FFD3422829"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes"]},{"url":"https://about.gitlab.com/releases/2018/10/01/security-release-gitlab-11-dot-3-dot-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"]},{"url":"https://about.gitlab.com/releases/2018/10/01/security-release-gitlab-11-dot-3-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-17452","sourceIdentifier":"cve@mitre.org","published":"2023-04-15T23:15:13.520","lastModified":"2026-06-17T01:45:52.203","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Server-Side Request Forgery (SSRF) via a loopback address to the validate_localhost function in url_blocker.rb."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-06T20:28:26.363194Z","id":"CVE-2018-17452","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"11.1.7","matchCriteriaId":"56859B5B-7084-4F58-86B1-55591E4365AB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"11.1.7","matchCriteriaId":"EEE02913-00F2-4386-AADE-E830BF40428C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.2.0","versionEndExcluding":"11.2.4","matchCriteriaId":"9D4901BF-95A2-4A45-A9D9-0E01B29B4288"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.2.0","versionEndExcluding":"11.2.4","matchCriteriaId":"CEC44A89-760A-4238-A11F-A4504DF86D04"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.3.0:*:*:*:community:*:*:*","matchCriteriaId":"9BE513BE-9346-43DC-B9E3-169B84156063"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.3.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"A64EAF5E-EA4B-4E5D-B0FF-04FFD3422829"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes"]},{"url":"https://about.gitlab.com/releases/2018/10/01/security-release-gitlab-11-dot-3-dot-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"]},{"url":"https://about.gitlab.com/releases/2018/10/01/security-release-gitlab-11-dot-3-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-17453","sourceIdentifier":"cve@mitre.org","published":"2023-04-15T23:15:13.557","lastModified":"2026-06-17T01:45:52.410","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Attackers may have been able to obtain sensitive access-token data from Sentry logs via the GRPC::Unknown exception."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-06T20:25:14.583558Z","id":"CVE-2018-17453","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"11.1.7","matchCriteriaId":"56859B5B-7084-4F58-86B1-55591E4365AB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"11.1.7","matchCriteriaId":"EEE02913-00F2-4386-AADE-E830BF40428C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.2.0","versionEndExcluding":"11.2.4","matchCriteriaId":"9D4901BF-95A2-4A45-A9D9-0E01B29B4288"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.2.0","versionEndExcluding":"11.2.4","matchCriteriaId":"CEC44A89-760A-4238-A11F-A4504DF86D04"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.3.0:*:*:*:community:*:*:*","matchCriteriaId":"9BE513BE-9346-43DC-B9E3-169B84156063"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.3.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"A64EAF5E-EA4B-4E5D-B0FF-04FFD3422829"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes"]},{"url":"https://about.gitlab.com/releases/2018/10/01/security-release-gitlab-11-dot-3-dot-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"]},{"url":"https://about.gitlab.com/releases/2018/10/01/security-release-gitlab-11-dot-3-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-17454","sourceIdentifier":"cve@mitre.org","published":"2023-04-15T23:15:13.597","lastModified":"2026-06-17T01:45:52.613","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is stored XSS on the issue details screen."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-06T20:19:52.883480Z","id":"CVE-2018-17454","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"11.1.7","matchCriteriaId":"56859B5B-7084-4F58-86B1-55591E4365AB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"11.1.7","matchCriteriaId":"EEE02913-00F2-4386-AADE-E830BF40428C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.2.0","versionEndExcluding":"11.2.4","matchCriteriaId":"9D4901BF-95A2-4A45-A9D9-0E01B29B4288"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.2.0","versionEndExcluding":"11.2.4","matchCriteriaId":"CEC44A89-760A-4238-A11F-A4504DF86D04"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.3.0:*:*:*:community:*:*:*","matchCriteriaId":"9BE513BE-9346-43DC-B9E3-169B84156063"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.3.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"A64EAF5E-EA4B-4E5D-B0FF-04FFD3422829"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes"]},{"url":"https://about.gitlab.com/releases/2018/10/01/security-release-gitlab-11-dot-3-dot-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"]},{"url":"https://about.gitlab.com/releases/2018/10/01/security-release-gitlab-11-dot-3-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-17455","sourceIdentifier":"cve@mitre.org","published":"2023-04-15T23:15:13.637","lastModified":"2026-06-17T01:45:52.827","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Attackers could obtain sensitive information about group names, avatars, LDAP settings, and descriptions via an insecure direct object reference to the \"merge request approvals\" feature."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-06T20:18:48.491962Z","id":"CVE-2018-17455","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-639"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-639"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"11.1.7","matchCriteriaId":"56859B5B-7084-4F58-86B1-55591E4365AB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"11.1.7","matchCriteriaId":"EEE02913-00F2-4386-AADE-E830BF40428C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.2.0","versionEndExcluding":"11.2.4","matchCriteriaId":"9D4901BF-95A2-4A45-A9D9-0E01B29B4288"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.2.0","versionEndExcluding":"11.2.4","matchCriteriaId":"CEC44A89-760A-4238-A11F-A4504DF86D04"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.3.0:*:*:*:community:*:*:*","matchCriteriaId":"9BE513BE-9346-43DC-B9E3-169B84156063"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.3.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"A64EAF5E-EA4B-4E5D-B0FF-04FFD3422829"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes"]},{"url":"https://about.gitlab.com/releases/2018/10/01/security-release-gitlab-11-dot-3-dot-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"]},{"url":"https://about.gitlab.com/releases/2018/10/01/security-release-gitlab-11-dot-3-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-17536","sourceIdentifier":"cve@mitre.org","published":"2023-04-15T23:15:13.680","lastModified":"2026-06-17T01:45:59.223","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is stored XSS on the merge request page via project import."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-06T20:16:19.446885Z","id":"CVE-2018-17536","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"11.1.7","matchCriteriaId":"56859B5B-7084-4F58-86B1-55591E4365AB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"11.1.7","matchCriteriaId":"EEE02913-00F2-4386-AADE-E830BF40428C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.2.0","versionEndExcluding":"11.2.4","matchCriteriaId":"9D4901BF-95A2-4A45-A9D9-0E01B29B4288"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.2.0","versionEndExcluding":"11.2.4","matchCriteriaId":"CEC44A89-760A-4238-A11F-A4504DF86D04"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.3.0:*:*:*:community:*:*:*","matchCriteriaId":"9BE513BE-9346-43DC-B9E3-169B84156063"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.3.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"A64EAF5E-EA4B-4E5D-B0FF-04FFD3422829"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes"]},{"url":"https://about.gitlab.com/releases/2018/10/01/security-release-gitlab-11-dot-3-dot-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"]},{"url":"https://about.gitlab.com/releases/2018/10/01/security-release-gitlab-11-dot-3-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2018-17537","sourceIdentifier":"cve@mitre.org","published":"2023-04-16T00:15:07.103","lastModified":"2026-06-17T01:45:59.433","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. blog-viewer has stored XSS during repository browsing, if package.json exists. ."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-06T16:27:24.218928Z","id":"CVE-2018-17537","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"11.1.7","matchCriteriaId":"56859B5B-7084-4F58-86B1-55591E4365AB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"11.1.7","matchCriteriaId":"EEE02913-00F2-4386-AADE-E830BF40428C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.2.0","versionEndExcluding":"11.2.4","matchCriteriaId":"9D4901BF-95A2-4A45-A9D9-0E01B29B4288"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.2.0","versionEndExcluding":"11.2.4","matchCriteriaId":"CEC44A89-760A-4238-A11F-A4504DF86D04"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.3.0:*:*:*:community:*:*:*","matchCriteriaId":"9BE513BE-9346-43DC-B9E3-169B84156063"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:11.3.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"A64EAF5E-EA4B-4E5D-B0FF-04FFD3422829"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes"]},{"url":"https://about.gitlab.com/releases/2018/10/01/security-release-gitlab-11-dot-3-dot-1-released/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"]},{"url":"https://about.gitlab.com/releases/2018/10/01/security-release-gitlab-11-dot-3-dot-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-14942","sourceIdentifier":"cve@mitre.org","published":"2023-04-16T00:15:07.190","lastModified":"2026-06-17T02:19:21.957","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.11.8, 12 before 12.0.6, and 12.1 before 12.1.6. Cookies for GitLab Pages (which have access control) could be sent over cleartext HTTP."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":3.6},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-06T17:06:41.110865Z","id":"CVE-2019-14942","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-319"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-319"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"11.11.8","matchCriteriaId":"7F01ECC9-538B-4DE8-B358-68C6CB553B53"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"11.11.8","matchCriteriaId":"5EA0F454-6AFE-4FE1-9042-67547617EF9B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.0.0","versionEndExcluding":"12.0.6","matchCriteriaId":"BA0102FF-040D-4FFF-A99B-AE2E5E71A66A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.0.0","versionEndExcluding":"12.0.6","matchCriteriaId":"B8C31873-CB16-4E58-A404-E87407457B41"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.6","matchCriteriaId":"18E1D26C-541A-4A40-9418-44B8D52BC82A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.6","matchCriteriaId":"EC71E6E6-F7E6-4335-897E-CBDE49ADB30A"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes"]},{"url":"https://about.gitlab.com/releases/2019/08/12/critical-security-release-gitlab-12-dot-1-dot-6-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-pages/issues/232","source":"cve@mitre.org","tags":["Broken Link"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"]},{"url":"https://about.gitlab.com/releases/2019/08/12/critical-security-release-gitlab-12-dot-1-dot-6-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab-pages/issues/232","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2019-14944","sourceIdentifier":"cve@mitre.org","published":"2023-04-16T00:15:07.227","lastModified":"2026-06-17T02:19:22.290","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab Community and Enterprise Edition before 11.11.8, 12 before 12.0.6, and 12.1 before 12.1.6. Gitaly allows injection of command-line flags. This sometimes leads to privilege escalation or remote code execution."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":2.5},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-06T17:04:03.448391Z","id":"CVE-2019-14944","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-77"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-77"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"11.11.8","matchCriteriaId":"7F01ECC9-538B-4DE8-B358-68C6CB553B53"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"11.11.8","matchCriteriaId":"5EA0F454-6AFE-4FE1-9042-67547617EF9B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.0.0","versionEndExcluding":"12.0.6","matchCriteriaId":"BA0102FF-040D-4FFF-A99B-AE2E5E71A66A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.0.0","versionEndExcluding":"12.0.6","matchCriteriaId":"B8C31873-CB16-4E58-A404-E87407457B41"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.6","matchCriteriaId":"18E1D26C-541A-4A40-9418-44B8D52BC82A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"12.1.6","matchCriteriaId":"EC71E6E6-F7E6-4335-897E-CBDE49ADB30A"}]}]}],"references":[{"url":"https://about.gitlab.com/blog/categories/releases/","source":"cve@mitre.org","tags":["Release Notes"]},{"url":"https://about.gitlab.com/releases/2019/08/12/critical-security-release-gitlab-12-dot-1-dot-6-released/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitaly/issues/1801","source":"cve@mitre.org","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitaly/issues/1802","source":"cve@mitre.org","tags":["Broken Link"]},{"url":"https://about.gitlab.com/blog/categories/releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"]},{"url":"https://about.gitlab.com/releases/2019/08/12/critical-security-release-gitlab-12-dot-1-dot-6-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitaly/issues/1801","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitaly/issues/1802","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2023-0155","sourceIdentifier":"cve@gitlab.com","published":"2023-05-03T21:15:16.323","lastModified":"2026-06-17T05:24:54.930","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions before 15.8.5, 15.9.4, 15.10.1. Open redirects was possible due to framing arbitrary content on any page allowing user controlled markdown"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=15.7, <15.8.5","status":"affected"},{"version":">=15.8, <15.9.4","status":"affected"},{"version":">=15.9, <15.10.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:L","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":2.3,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:L","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-01-30T14:37:46.263784Z","id":"CVE-2023-0155","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-601"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"15.8.5","matchCriteriaId":"3FD921B9-00B8-4C39-BC84-80DA843763B5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"15.8.5","matchCriteriaId":"535B468A-3815-4E7A-AC3E-D1A42434588A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.9","versionEndExcluding":"15.9.5","matchCriteriaId":"7CE5E35C-CCD0-4C30-8256-38738D268499"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.9","versionEndExcluding":"15.9.5","matchCriteriaId":"AD24CB10-DA4E-4411-A901-384B03B70DCA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.10","versionEndExcluding":"15.10.1","matchCriteriaId":"FAEB14CD-BB39-4C93-8BA0-3D2877F208A2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.10","versionEndExcluding":"15.10.1","matchCriteriaId":"ADCD2B7B-6E9B-444C-AFC7-BE56381F649C"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-0155.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/387638","source":"cve@gitlab.com","tags":["Exploit","Third Party Advisory"]},{"url":"https://hackerone.com/reports/1817250","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-0155.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/387638","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]},{"url":"https://hackerone.com/reports/1817250","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-0485","sourceIdentifier":"cve@gitlab.com","published":"2023-05-03T21:15:16.577","lastModified":"2026-06-17T05:25:39.590","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 13.11 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. It was possible that a project member demoted to a user role to read project updates by doing a diff with a pre-existing fork."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13,11, <15.8.5","status":"affected"},{"version":">=15.9, <15.9.4","status":"affected"},{"version":">=15.10, <15.10.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-01-30T14:36:43.631342Z","id":"CVE-2023-0485","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-668"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.11","versionEndExcluding":"15.8.5","matchCriteriaId":"5709DC7C-DB07-41E0-8260-E2ED19B8FFAC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"15.9","versionEndExcluding":"15.9.4","matchCriteriaId":"B1317C77-8DC5-4F9C-928A-3F561C8D3CAD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"15.11","versionEndExcluding":"15.11.1","matchCriteriaId":"324922C6-938D-42CA-BA80-8BEEB29DAEC0"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-0485.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/389191","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1837937","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-0485.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/389191","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1837937","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-1204","sourceIdentifier":"cve@gitlab.com","published":"2023-05-03T21:15:16.707","lastModified":"2026-06-17T05:27:21.197","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.1 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A user could use an unverified email as a public email and commit email by sending a specifically crafted request on user update settings."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=10.0, <12.9.8","status":"affected"},{"version":">=12.10, <12.10.7","status":"affected"},{"version":">=13.0, <13.0.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-01-30T15:23:08.800214Z","id":"CVE-2023-1204","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-347"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"10.0","versionEndExcluding":"12.9.8","matchCriteriaId":"97201C83-37F2-46AB-B62A-CC351E6BF563"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"12.10","versionEndExcluding":"12.10.7","matchCriteriaId":"C227F637-E792-4A56-AF4C-81837FDFCA91"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.0","versionEndExcluding":"13.0.1","matchCriteriaId":"D5EA4F3B-E5F3-4CFD-AE17-4FDF3FE78535"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1204.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/394745","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1881598","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1204.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/394745","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1881598","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/394745","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2023-1265","sourceIdentifier":"cve@gitlab.com","published":"2023-05-03T21:15:17.307","lastModified":"2026-06-17T05:27:30.160","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 11.9 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. The condition allows for a privileged attacker, under certain conditions, to obtain session tokens from all users of a GitLab instance."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=11.9, <15.9.6","status":"affected"},{"version":">=15.10, <15.10.5","status":"affected"},{"version":">=15.11, <15.11.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:N/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.0,"impactScore":4.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N","baseScore":4.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":0.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-01-29T21:48:32.750181Z","id":"CVE-2023-1265","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-384"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"11.9","versionEndExcluding":"15.9.6","matchCriteriaId":"A26A6860-E64D-44E7-BFCC-DBD19A6501C2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"15.10","versionEndExcluding":"15.10.5","matchCriteriaId":"CF774F65-31C6-4F4A-8979-57D1568757E2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"15.11","versionEndExcluding":"15.11.1","matchCriteriaId":"324922C6-938D-42CA-BA80-8BEEB29DAEC0"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1265.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/394960","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1888690","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1265.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/394960","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1888690","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-1836","sourceIdentifier":"cve@gitlab.com","published":"2023-05-03T21:15:17.807","lastModified":"2026-06-17T05:28:51.533","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. When viewing an XML file in a repository in \"raw\" mode, it can be made to render as HTML if viewed under specific circumstances"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=5.1, <15.9.6","status":"affected"},{"version":">=15.10, <15.10.5","status":"affected"},{"version":">=15.11, <15.11.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":4.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.3,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-01-29T21:46:31.405437Z","id":"CVE-2023-1836","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"5.1","versionEndExcluding":"15.9.6","matchCriteriaId":"06A634B5-D0D2-49D4-B119-0F69CF07D016"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.10","versionEndExcluding":"15.10.5","matchCriteriaId":"128CE092-2826-422E-BE7A-D2DDE15FAFC3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.11","versionEndExcluding":"15.11.1","matchCriteriaId":"C8959805-2A8C-48BE-A0C2-8A1B1049826B"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1836.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/404613","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1923293","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1836.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/404613","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1923293","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-1965","sourceIdentifier":"cve@gitlab.com","published":"2023-05-03T21:15:18.220","lastModified":"2026-06-17T05:29:09.227","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions starting from 14.2 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. Lack of verification on RelayState parameter allowed a maliciously crafted URL to obtain access tokens granted for 3rd party Group SAML SSO logins. This feature isn't enabled by default."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=14.2, <15.9.6","status":"affected"},{"version":">=15.10, <15.10.5","status":"affected"},{"version":">=15.11, <15.11.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N","baseScore":6.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-01-29T21:39:52.850255Z","id":"CVE-2023-1965","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-352"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.2","versionEndExcluding":"15.9.6","matchCriteriaId":"25ED245F-8280-4467-A6C1-33F5CA94AC72"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.10","versionEndExcluding":"15.10.5","matchCriteriaId":"4A0D75F4-8D11-4C69-B761-3312B5CDFCE2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.11","versionEndExcluding":"15.11.1","matchCriteriaId":"E7B0DA1F-87DA-411A-8C20-3BF410B6EDB8"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1965.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/406235","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1923672","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1965.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/406235","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1923672","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-2069","sourceIdentifier":"cve@gitlab.com","published":"2023-05-03T21:15:21.590","lastModified":"2026-06-17T05:51:20.013","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 10.0 before 12.9.8, all versions starting from 12.10 before 12.10.7, all versions starting from 13.0 before 13.0.1. A user with the role of developer could use the import project feature to leak CI/CD variables."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=10.0, <12.9.8","status":"affected"},{"version":">=12.10, <12.10.7","status":"affected"},{"version":">=13.0, <13.0.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-01-30T20:29:57.265626Z","id":"CVE-2023-2069","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-668"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"10.0","versionEndExcluding":"12.9.8","matchCriteriaId":"97201C83-37F2-46AB-B62A-CC351E6BF563"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"12.10.0","versionEndExcluding":"12.10.7","matchCriteriaId":"A60404F1-9B3B-4249-A49F-407E09B1377F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.0","versionEndExcluding":"13.0.1","matchCriteriaId":"D5EA4F3B-E5F3-4CFD-AE17-4FDF3FE78535"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-2069.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/407374","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1939987","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-2069.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/407374","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1939987","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2022-4376","sourceIdentifier":"cve@gitlab.com","published":"2023-05-03T22:15:15.793","lastModified":"2026-06-17T05:20:44.173","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. Under certain conditions, an attacker may be able to map a private email of a GitLab user to their GitLab account on an instance."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=15.2, <15.9.6","status":"affected"},{"version":">=15.10, <15.10.5","status":"affected"},{"version":">=15.11, <15.11.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":3.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-01-30T14:38:12.535735Z","id":"CVE-2022-4376","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"8.6.0","versionEndExcluding":"15.9.6","matchCriteriaId":"098EA22B-472A-43B5-8373-B60A532739FB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"15.10","versionEndExcluding":"15.10.5","matchCriteriaId":"CF774F65-31C6-4F4A-8979-57D1568757E2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"15.11","versionEndExcluding":"15.11.1","matchCriteriaId":"324922C6-938D-42CA-BA80-8BEEB29DAEC0"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4376.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/385246","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1794713","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4376.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/385246","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1794713","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-0756","sourceIdentifier":"cve@gitlab.com","published":"2023-05-03T22:15:16.073","lastModified":"2026-06-17T05:26:14.413","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. The main branch of a repository with a specially crafted name allows an attacker to create repositories with malicious code, victims who clone or download these repositories will execute arbitrary code on their systems."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":"<15.9.6","status":"affected"},{"version":">=15.10, <15.10.5","status":"affected"},{"version":">=15.11, <15.11.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N","baseScore":4.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","baseScore":8.0,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.1,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-12T16:08:01.558818Z","id":"CVE-2023-0756","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionEndExcluding":"15.9.6","matchCriteriaId":"1C574941-CFBA-4F52-9375-00D3E4525293"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"15.10","versionEndExcluding":"15.10.5","matchCriteriaId":"CF774F65-31C6-4F4A-8979-57D1568757E2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"15.11","versionEndExcluding":"15.11.1","matchCriteriaId":"324922C6-938D-42CA-BA80-8BEEB29DAEC0"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-0756.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/390910","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1864278","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-0756.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/390910","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1864278","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-0805","sourceIdentifier":"cve@gitlab.com","published":"2023-05-03T22:15:16.553","lastModified":"2026-06-17T05:26:21.167","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions starting from 15.2 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. A malicious group member may continue to have access to the public projects of a public group even after being banned from the public group by the owner."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=15.2, <15.9.6","status":"affected"},{"version":">=15.10, <15.10.5","status":"affected"},{"version":">=15.11, <15.11.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-01-30T14:33:35.321901Z","id":"CVE-2023-0805","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.2","versionEndExcluding":"15.9.6","matchCriteriaId":"E2E34F11-F5E9-4EEE-954D-D3EEEB3F9AFE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.10","versionEndExcluding":"15.10.5","matchCriteriaId":"4A0D75F4-8D11-4C69-B761-3312B5CDFCE2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.11","versionEndExcluding":"15.11.1","matchCriteriaId":"E7B0DA1F-87DA-411A-8C20-3BF410B6EDB8"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-0805.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/391433","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1850046","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-0805.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/391433","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1850046","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-1178","sourceIdentifier":"cve@gitlab.com","published":"2023-05-03T22:15:17.027","lastModified":"2026-06-17T05:27:17.380","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 8.6 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. File integrity may be compromised when source code or installation packages are pulled from a tag or from a release containing a ref to another commit."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=8.6, <15.9.6","status":"affected"},{"version":">=15.10, <15.10.5","status":"affected"},{"version":">=15.11, <15.11.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N","baseScore":5.7,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N","baseScore":5.7,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-01-30T14:32:24.326581Z","id":"CVE-2023-1178","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-94"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.6.0","versionEndExcluding":"15.9.6","matchCriteriaId":"C649F4ED-B614-4133-853F-12DE8FD60E37"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.6.0","versionEndExcluding":"15.9.6","matchCriteriaId":"9C77C875-FEA0-43C4-B7B7-9EA1C6473C69"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.10","versionEndExcluding":"15.10.5","matchCriteriaId":"128CE092-2826-422E-BE7A-D2DDE15FAFC3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.10","versionEndExcluding":"15.10.5","matchCriteriaId":"4A0D75F4-8D11-4C69-B761-3312B5CDFCE2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.11","versionEndExcluding":"15.11.1","matchCriteriaId":"C8959805-2A8C-48BE-A0C2-8A1B1049826B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.11","versionEndExcluding":"15.11.1","matchCriteriaId":"E7B0DA1F-87DA-411A-8C20-3BF410B6EDB8"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1178.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/381815","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1778009","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1178.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/381815","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1778009","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2023-2182","sourceIdentifier":"cve@gitlab.com","published":"2023-05-03T22:15:19.513","lastModified":"2026-06-17T05:51:56.263","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. Under certain conditions when OpenID Connect is enabled on an instance, it may allow users who are marked as 'external' to become 'regular' users thus leading to privilege escalation for those users."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=15.10, <15.10.5","status":"affected"},{"version":">=15.11, <15.11.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","baseScore":6.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-01-30T20:50:39.401805Z","id":"CVE-2023-2182","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.10.0","versionEndExcluding":"15.10.5","matchCriteriaId":"1A3B26FC-86C2-400D-8025-C4C6E2949549"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.11.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"49CD6C7F-81E5-422B-B29C-0C63B8FDF431"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-2182.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/403012","source":"cve@gitlab.com","tags":["Exploit","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-2182.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/403012","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2023-2478","sourceIdentifier":"cve@gitlab.com","published":"2023-05-08T21:15:10.997","lastModified":"2026-06-17T05:52:40.850","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.9.7, all versions starting from 15.10 before 15.10.6, all versions starting from 15.11 before 15.11.2. Under certain conditions, a malicious unauthorized GitLab user may use a GraphQL endpoint to attach a malicious runner to any project."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=15.4, <15.9.7","status":"affected"},{"version":">=15.10, <15.10.6","status":"affected"},{"version":">=15.11, <15.11.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N","baseScore":9.6,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-01-29T17:16:17.035313Z","id":"CVE-2023-2478","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-732"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-732"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.4.0","versionEndExcluding":"15.9.7","matchCriteriaId":"F31A1A1D-8935-4F28-B2D6-7BC226014DDF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.4.0","versionEndExcluding":"15.9.7","matchCriteriaId":"946B8298-406C-4426-B9D5-3C3259073DDE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.10.0","versionEndExcluding":"15.10.6","matchCriteriaId":"769E332B-9DBA-4751-B0F8-9F6484E3E49B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.10.0","versionEndExcluding":"15.10.6","matchCriteriaId":"6EDA3CE4-6830-44A0-9F6B-9DC550F62AD1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.11.0","versionEndExcluding":"15.11.2","matchCriteriaId":"7432A843-DCCD-46CA-8339-1D5F108DB796"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.11.0","versionEndExcluding":"15.11.2","matchCriteriaId":"756390DB-9929-4EC6-9273-854E3654968B"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-2478.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/409470","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1969599","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-2478.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/409470","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1969599","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/409470","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2023-2181","sourceIdentifier":"cve@gitlab.com","published":"2023-05-12T21:15:09.490","lastModified":"2026-06-17T05:51:56.123","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions before 15.9.8, 15.10.0 before 15.10.7, and 15.11.0 before 15.11.3. A malicious developer could use a git feature called refs/replace to smuggle content into a merge request which would not be visible during review in the UI."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":"<15.9.8","status":"affected"},{"version":">=15.10, <15.10.7","status":"affected"},{"version":">=15.11, <15.11.3","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:N","baseScore":6.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":4.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-01-24T15:46:53.314318Z","id":"CVE-2023-2181","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionEndExcluding":"15.9.8","matchCriteriaId":"30A38F00-9BEB-4F52-B352-19A660D77D25"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"15.10.0","versionEndExcluding":"15.10.7","matchCriteriaId":"69BCC2E4-6B4E-490B-8439-9155D691F8EA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"15.11.0","versionEndExcluding":"15.11.3","matchCriteriaId":"3005DEA5-BB75-4703-8BE9-3DE477C015CB"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-2181.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/407859","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1938185","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-2181.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/407859","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1938185","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-2825","sourceIdentifier":"cve@gitlab.com","published":"2023-05-26T21:15:16.740","lastModified":"2026-06-17T05:53:33.087","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a path traversal vulnerability to read arbitrary files on the server when an attachment exists in a public project nested within at least five groups."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":"16.0.0","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N","baseScore":10.0,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-01-15T15:45:06.932561Z","id":"CVE-2023-2825","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-22"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-22"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.0.0:*:*:*:community:*:*:*","matchCriteriaId":"55994094-1FD2-45BD-86AC-CE90041EC6BE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"A58B93FC-628E-4B79-8970-CD5E8CE28EE8"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-2825.json","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/412371","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1994725","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-2825.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/412371","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1994725","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2023-0921","sourceIdentifier":"cve@gitlab.com","published":"2023-06-06T17:15:12.747","lastModified":"2026-06-17T05:26:38.463","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A lack of length validation in GitLab CE/EE affecting all versions from 8.3 before 15.10.8, 15.11 before 15.11.7, and 16.0 before 16.0.2 allows an authenticated attacker to create a large Issue description via GraphQL which, when repeatedly requested, saturates CPU usage."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=8.3, <15.10.8","status":"affected"},{"version":">=15.11, <15.11.7","status":"affected"},{"version":">=16.0, <16.0.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-01-07T21:41:02.829811Z","id":"CVE-2023-0921","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.3.0","versionEndExcluding":"15.10.8","matchCriteriaId":"BFC6BDDE-CB74-47B6-9655-453DE9708F34"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.3.0","versionEndExcluding":"15.10.8","matchCriteriaId":"A28C670F-257D-437A-8566-FF4694730A76"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.11.0","versionEndExcluding":"15.11.7","matchCriteriaId":"C612DD9C-BFBD-49A3-9936-BB7D2C7ADBED"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.11.0","versionEndExcluding":"15.11.7","matchCriteriaId":"A6944880-86FD-4D58-8217-667BD48B019A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"16.0.2","matchCriteriaId":"C060C573-5005-487A-8AB2-DE66531685A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"16.0.2","matchCriteriaId":"D19BAB29-C57C-4410-A093-44AFFF3984DF"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-0921.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/392433","source":"cve@gitlab.com","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1869839","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-0921.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/392433","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1869839","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2023-2132","sourceIdentifier":"cve@gitlab.com","published":"2023-06-06T17:15:14.090","lastModified":"2026-06-17T05:51:29.720","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A DollarMathPostFilter Regular Expression Denial of Service in was possible by sending crafted payloads to the preview_markdown endpoint."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=15.4.0, <15.10.8","status":"affected"},{"version":">=15.11, <15.11.7","status":"affected"},{"version":">=16.0, <16.0.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-01-07T21:33:44.920668Z","id":"CVE-2023-2132","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-1333"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-1333"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.4.0","versionEndExcluding":"15.10.8","matchCriteriaId":"FF09675D-DF86-415B-AF42-7A6F43100C53"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.4.0","versionEndExcluding":"15.10.8","matchCriteriaId":"3939EBF5-9026-48D1-AAAF-1658A5A28388"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.11.0","versionEndExcluding":"15.11.7","matchCriteriaId":"C612DD9C-BFBD-49A3-9936-BB7D2C7ADBED"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.11.0","versionEndExcluding":"15.11.7","matchCriteriaId":"A6944880-86FD-4D58-8217-667BD48B019A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"16.0.2","matchCriteriaId":"C060C573-5005-487A-8AB2-DE66531685A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"16.0.2","matchCriteriaId":"D19BAB29-C57C-4410-A093-44AFFF3984DF"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-2132.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/407586","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1934711","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-2132.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/407586","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1934711","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2023-1621","sourceIdentifier":"cve@gitlab.com","published":"2023-06-06T20:15:10.227","lastModified":"2026-06-17T05:28:23.383","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions starting from 12.0 before 15.10.5, all versions starting from 15.11 before 15.11.1. A malicious group member may continue to commit to projects even from a restricted IP address."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.0, <15.10.5","status":"affected"},{"version":">=15.11, <15.11.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-01-07T21:37:54.967077Z","id":"CVE-2023-1621","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.0.0","versionEndExcluding":"15.10.5","matchCriteriaId":"362657BB-66CB-4F41-8258-CF037235EC5F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.11.0","versionEndExcluding":"15.11.1","matchCriteriaId":"4690D9EC-4B6C-4DC3-8B47-EBDFE88CE810"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1621.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/399774","source":"cve@gitlab.com","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1914049","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1621.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/399774","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1914049","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2023-2442","sourceIdentifier":"cve@gitlab.com","published":"2023-06-07T16:15:09.403","lastModified":"2026-06-17T05:52:35.820","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A specially crafted merge request could lead to a stored XSS on the client side which allows attackers to perform arbitrary actions on behalf of victims."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=15.11, <15.11.7","status":"affected"},{"version":">=16.0, <16.0.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-01-07T16:29:40.764929Z","id":"CVE-2023-2442","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.11.0","versionEndExcluding":"15.11.7","matchCriteriaId":"C612DD9C-BFBD-49A3-9936-BB7D2C7ADBED"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.11.0","versionEndExcluding":"15.11.7","matchCriteriaId":"A6944880-86FD-4D58-8217-667BD48B019A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"16.0.2","matchCriteriaId":"C060C573-5005-487A-8AB2-DE66531685A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"16.0.2","matchCriteriaId":"D19BAB29-C57C-4410-A093-44AFFF3984DF"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-2442.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/409346","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1965750","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-2442.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/409346","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1965750","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/409346","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2023-0121","sourceIdentifier":"cve@gitlab.com","published":"2023-06-07T17:15:09.727","lastModified":"2026-06-17T05:24:49.730","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A denial of service issue was discovered in GitLab CE/EE affecting all versions starting from 13.2.4 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2 which allows an attacker to cause high resource consumption using malicious test report artifacts."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=13.2.4, <15.10.8","status":"affected"},{"version":">=15.11, <15.11.7","status":"affected"},{"version":">=16.0, <16.0.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-01-07T17:00:02.776718Z","id":"CVE-2023-0121","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.2.4","versionEndExcluding":"15.10.8","matchCriteriaId":"47CF7160-B10A-4F08-9F88-CD16666A78D0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.2.4","versionEndExcluding":"15.10.8","matchCriteriaId":"71449E20-5C25-48A6-901F-9A1A57855717"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.11.0","versionEndExcluding":"15.11.7","matchCriteriaId":"C612DD9C-BFBD-49A3-9936-BB7D2C7ADBED"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.11.0","versionEndExcluding":"15.11.7","matchCriteriaId":"A6944880-86FD-4D58-8217-667BD48B019A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"16.0.2","matchCriteriaId":"C060C573-5005-487A-8AB2-DE66531685A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"16.0.2","matchCriteriaId":"D19BAB29-C57C-4410-A093-44AFFF3984DF"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-0121.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/387549","source":"cve@gitlab.com","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1774688","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-0121.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/387549","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1774688","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/387549","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Issue Tracking","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2023-0508","sourceIdentifier":"cve@gitlab.com","published":"2023-06-07T17:15:09.823","lastModified":"2026-06-17T05:25:42.860","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. Open redirection was possible via HTTP response splitting in the NPM package API."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.9, <15.10.8","status":"affected"},{"version":">=15.11, <15.11.7","status":"affected"},{"version":">=16.0, <16.0.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N","baseScore":3.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-01-07T16:58:14.042909Z","id":"CVE-2023-0508","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-113"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.4.0","versionEndExcluding":"15.10.8","matchCriteriaId":"FF09675D-DF86-415B-AF42-7A6F43100C53"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.4.0","versionEndExcluding":"15.10.8","matchCriteriaId":"3939EBF5-9026-48D1-AAAF-1658A5A28388"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.11.0","versionEndExcluding":"15.11.7","matchCriteriaId":"C612DD9C-BFBD-49A3-9936-BB7D2C7ADBED"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.11.0","versionEndExcluding":"15.11.7","matchCriteriaId":"A6944880-86FD-4D58-8217-667BD48B019A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"16.0.2","matchCriteriaId":"C060C573-5005-487A-8AB2-DE66531685A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"16.0.2","matchCriteriaId":"D19BAB29-C57C-4410-A093-44AFFF3984DF"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-0508.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/389328","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1842314","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-0508.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/389328","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1842314","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/389328","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2023-1825","sourceIdentifier":"cve@gitlab.com","published":"2023-06-07T17:15:09.900","lastModified":"2026-06-17T05:28:50.270","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions starting from 15.7 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. It was possible to disclose issue notes to an unauthorized user at project export."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=15.7, <15.10.8","status":"affected"},{"version":">=15.11, <15.11.7","status":"affected"},{"version":">=16.0, <16.0.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":3.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-01-07T16:56:35.894355Z","id":"CVE-2023-1825","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-201"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.7.0","versionEndExcluding":"15.10.8","matchCriteriaId":"FAB9401E-A399-46FF-A992-EE795C92B8F0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.11.0","versionEndExcluding":"15.11.7","matchCriteriaId":"A6944880-86FD-4D58-8217-667BD48B019A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"16.0.2","matchCriteriaId":"D19BAB29-C57C-4410-A093-44AFFF3984DF"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1825.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/384035","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1825.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/384035","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2023-2001","sourceIdentifier":"cve@gitlab.com","published":"2023-06-07T17:15:09.967","lastModified":"2026-06-17T05:51:10.400","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. An attacker was able to spoof protected tags, which could potentially lead a victim to download malicious code."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=0.0, <15.10.8","status":"affected"},{"version":">=15.11, <15.11.7","status":"affected"},{"version":">=16.0, <16.0.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-01-07T16:54:01.097905Z","id":"CVE-2023-2001","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-290"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"15.10.8","matchCriteriaId":"23B36DD0-0B07-4CF1-A521-A58D43C6CB26"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"15.10.8","matchCriteriaId":"FCB6D202-8EC7-4305-A540-8E9EC1E7F337"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.11.0","versionEndExcluding":"15.11.7","matchCriteriaId":"C612DD9C-BFBD-49A3-9936-BB7D2C7ADBED"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.11.0","versionEndExcluding":"15.11.7","matchCriteriaId":"A6944880-86FD-4D58-8217-667BD48B019A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"16.0.2","matchCriteriaId":"C060C573-5005-487A-8AB2-DE66531685A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"16.0.2","matchCriteriaId":"D19BAB29-C57C-4410-A093-44AFFF3984DF"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-2001.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/406764","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1908423","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-2001.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/406764","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1908423","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/406764","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2023-2013","sourceIdentifier":"cve@gitlab.com","published":"2023-06-07T17:15:10.030","lastModified":"2026-06-17T05:51:11.840","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 1.2 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. An issue was found that allows someone to abuse a discrepancy between the Web application display and the git command line interface to social engineer victims into cloning non-trusted code."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=1.2, <15.10.8","status":"affected"},{"version":">=15.11, <15.11.7","status":"affected"},{"version":">=16.0, <16.0.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N","baseScore":2.6,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-01-07T16:50:51.856808Z","id":"CVE-2023-2013","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-1021"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"1.2.0","versionEndExcluding":"15.10.8","matchCriteriaId":"191878CA-7DF1-4895-A267-78B0EC6284DF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"1.2.0","versionEndExcluding":"15.10.8","matchCriteriaId":"21D45CBA-6F26-4822-8DA6-CD07667D8520"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.11.0","versionEndExcluding":"15.11.7","matchCriteriaId":"C612DD9C-BFBD-49A3-9936-BB7D2C7ADBED"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.11.0","versionEndExcluding":"15.11.7","matchCriteriaId":"A6944880-86FD-4D58-8217-667BD48B019A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"16.0.2","matchCriteriaId":"C060C573-5005-487A-8AB2-DE66531685A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"16.0.2","matchCriteriaId":"D19BAB29-C57C-4410-A093-44AFFF3984DF"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-2013.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/406844","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1940441","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-2013.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/406844","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1940441","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/406844","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2023-2015","sourceIdentifier":"cve@gitlab.com","published":"2023-06-07T17:15:10.087","lastModified":"2026-06-17T05:51:12.130","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.8 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A reflected XSS was possible when creating new abuse reports which allows attackers to perform arbitrary actions on behalf of victims."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":"> 15.8, <15.10.8","status":"affected"},{"version":">=15.11, <15.11.7","status":"affected"},{"version":">=16.0, <16.0.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":4.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.3,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-01-07T16:47:55.540963Z","id":"CVE-2023-2015","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.8.0","versionEndExcluding":"15.10.8","matchCriteriaId":"AE098F93-5FF4-4DFF-A63F-D188E1D53FC4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.8.0","versionEndExcluding":"15.10.8","matchCriteriaId":"505C9224-85B9-4390-827C-DDA3FF73C34E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.11.0","versionEndExcluding":"15.11.7","matchCriteriaId":"C612DD9C-BFBD-49A3-9936-BB7D2C7ADBED"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.11.0","versionEndExcluding":"15.11.7","matchCriteriaId":"A6944880-86FD-4D58-8217-667BD48B019A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"16.0.2","matchCriteriaId":"C060C573-5005-487A-8AB2-DE66531685A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"16.0.2","matchCriteriaId":"D19BAB29-C57C-4410-A093-44AFFF3984DF"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-2015.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/407137","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1941091","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-2015.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/407137","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1941091","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/407137","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2023-2198","sourceIdentifier":"cve@gitlab.com","published":"2023-06-07T17:15:10.150","lastModified":"2026-06-17T05:51:58.353","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.7 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A Regular Expression Denial of Service was possible via sending crafted payloads to the preview_markdown endpoint."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=8.7, <15.10.8","status":"affected"},{"version":">=15.11, <15.11.7","status":"affected"},{"version":">=16.0, <16.0.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-01-07T16:46:50.392119Z","id":"CVE-2023-2198","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-1333"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-1333"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.7.0","versionEndExcluding":"15.10.8","matchCriteriaId":"87236166-9FB8-4766-AB87-AA4F6AEB8EE6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.7.0","versionEndExcluding":"15.10.8","matchCriteriaId":"79D863F6-D709-4F8F-A078-EB1D3AB14F1D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.11.0","versionEndExcluding":"15.11.7","matchCriteriaId":"C612DD9C-BFBD-49A3-9936-BB7D2C7ADBED"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.11.0","versionEndExcluding":"15.11.7","matchCriteriaId":"A6944880-86FD-4D58-8217-667BD48B019A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"16.0.2","matchCriteriaId":"C060C573-5005-487A-8AB2-DE66531685A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"16.0.2","matchCriteriaId":"D19BAB29-C57C-4410-A093-44AFFF3984DF"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-2198.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/408273","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1947187","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-2198.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/408273","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1947187","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/408273","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2023-2199","sourceIdentifier":"cve@gitlab.com","published":"2023-06-07T17:15:10.207","lastModified":"2026-06-17T05:51:58.490","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.0 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A Regular Expression Denial of Service was possible via sending crafted payloads to the preview_markdown endpoint."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.0, <15.10.8","status":"affected"},{"version":">=15.11, <15.11.7","status":"affected"},{"version":">=16.0, <16.0.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-01-07T16:45:26.839872Z","id":"CVE-2023-2199","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-1333"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-1333"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.0.0","versionEndExcluding":"15.10.8","matchCriteriaId":"A59F1E9F-514F-4A85-B7DF-53599B79D1AC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.0.0","versionEndExcluding":"15.10.8","matchCriteriaId":"5C2C66EB-C376-4326-BDE9-5C49B5EA8A87"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.11.0","versionEndExcluding":"15.11.7","matchCriteriaId":"C612DD9C-BFBD-49A3-9936-BB7D2C7ADBED"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.11.0","versionEndExcluding":"15.11.7","matchCriteriaId":"A6944880-86FD-4D58-8217-667BD48B019A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"16.0.2","matchCriteriaId":"C060C573-5005-487A-8AB2-DE66531685A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"16.0.2","matchCriteriaId":"D19BAB29-C57C-4410-A093-44AFFF3984DF"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-2199.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/408272","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1943819","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-2199.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/408272","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1943819","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/408272","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2023-2485","sourceIdentifier":"cve@gitlab.com","published":"2023-06-07T17:15:10.270","lastModified":"2026-06-17T05:52:41.693","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.1 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A malicious maintainer in a project can escalate other users to Owners in that project if they import members from another project that those other users are Owners of."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=14.1, <15.10.8","status":"affected"},{"version":">=15.11, <15.11.7","status":"affected"},{"version":">=16.0, <16.0.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N","baseScore":4.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":0.7,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-01-07T15:44:06.611726Z","id":"CVE-2023-2485","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-266"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"15.10.8","matchCriteriaId":"F855EF03-FB8C-4C0C-A465-A87B8641E5BA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"15.10.8","matchCriteriaId":"E21C80C9-AD43-4B65-A358-9AAE14996997"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.11.0","versionEndExcluding":"15.11.7","matchCriteriaId":"C612DD9C-BFBD-49A3-9936-BB7D2C7ADBED"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.11.0","versionEndExcluding":"15.11.7","matchCriteriaId":"A6944880-86FD-4D58-8217-667BD48B019A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"16.0.2","matchCriteriaId":"C060C573-5005-487A-8AB2-DE66531685A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"16.0.2","matchCriteriaId":"D19BAB29-C57C-4410-A093-44AFFF3984DF"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-2485.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/407830","source":"cve@gitlab.com","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1934811","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-2485.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/407830","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1934811","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2023-2589","sourceIdentifier":"cve@gitlab.com","published":"2023-06-07T17:15:10.330","lastModified":"2026-06-17T05:52:57.410","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions starting from 12.0 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. An attacker can clone a repository from a public project, from a disallowed IP, even after the top-level group has enabled IP restrictions on the group."},{"lang":"es","value":"Se ha descubierto un problema en GitLab EE que afecta a todas las versiones a partir de la 12.0 hasta la 15.10.8, a todas las versiones a partir de la 15.11 hasta la 15.11.7 y a todas las versiones a partir de la 16.0 hasta la 16.0.2. Un atacante puede clonar un repositorio de un proyecto público, desde una dirección IP no permitida, incluso después de que el grupo de nivel superior haya habilitado restricciones de IP en el grupo."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=12.0, <15.10.8","status":"affected"},{"version":">=15.11, <15.11.7","status":"affected"},{"version":">=16.0, <16.0.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-01-07T16:25:11.583571Z","id":"CVE-2023-2589","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-346"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.0.0","versionEndExcluding":"15.10.8","matchCriteriaId":"A59F1E9F-514F-4A85-B7DF-53599B79D1AC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.0.0","versionEndExcluding":"15.10.8","matchCriteriaId":"5C2C66EB-C376-4326-BDE9-5C49B5EA8A87"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.11.0","versionEndExcluding":"15.11.7","matchCriteriaId":"C612DD9C-BFBD-49A3-9936-BB7D2C7ADBED"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.11.0","versionEndExcluding":"15.11.7","matchCriteriaId":"A6944880-86FD-4D58-8217-667BD48B019A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"16.0.2","matchCriteriaId":"C060C573-5005-487A-8AB2-DE66531685A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"16.0.2","matchCriteriaId":"D19BAB29-C57C-4410-A093-44AFFF3984DF"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-2589.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/407891","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1941803","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-2589.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/407891","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1941803","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/407891","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2022-4143","sourceIdentifier":"cve@gitlab.com","published":"2023-06-28T21:15:09.290","lastModified":"2026-06-17T05:20:04.733","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 15.7 before 15.8.5, from 15.9 before 15.9.4, and from 15.10 before 15.10.1 that allows for crafted, unapproved MRs to be introduced and merged without authorization"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=15.7, <15.8.5","status":"affected"},{"version":">=15.9, <15.9.4","status":"affected"},{"version":">=15.10, <15.10.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-12-03T19:58:44.826636Z","id":"CVE-2022-4143","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-367"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.7.0","versionEndExcluding":"15.8.5","matchCriteriaId":"FC607BB4-60B6-421C-86F0-A0A410CE0559"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.7.0","versionEndExcluding":"15.8.5","matchCriteriaId":"30D138B4-1678-4969-96DC-29143687FA20"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.9.0","versionEndExcluding":"15.9.4","matchCriteriaId":"130F61DA-5561-49A8-8024-88D12819F2E1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.9.0","versionEndExcluding":"15.9.4","matchCriteriaId":"E10FDADF-D6E5-402E-8834-F9BD274FBE2D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.10.0:*:*:*:community:*:*:*","matchCriteriaId":"7803BD85-A126-49E0-8DEC-3D0E98A0CAE1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:15.10.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"7D831DA8-EE49-41A1-AE77-E8B51E8458A4"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4143.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/383776","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/1767639","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4143.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/383776","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/1767639","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-2232","sourceIdentifier":"cve@gitlab.com","published":"2023-06-28T21:15:09.707","lastModified":"2026-06-17T05:52:03.527","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 15.10 before 16.1, leading to a ReDoS vulnerability in the Jira prefix"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","versions":[{"version":">=15.10, <16.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-11-27T18:57:13.129137Z","id":"CVE-2023-2232","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-1333"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"15.10","versionEndExcluding":"16.1","matchCriteriaId":"F23C98C0-1171-4509-99AB-3D7C6589CE2D"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-2232.json","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/408352","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/1934802","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-2232.json","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/408352","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/1934802","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-1936","sourceIdentifier":"cve@gitlab.com","published":"2023-07-11T08:15:10.380","lastModified":"2026-06-17T05:29:04.267","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows an attacker to leak the email address of a user who created a service desk issue."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"13.7","lessThan":"15.11.10","versionType":"semver","status":"affected"},{"version":"16.0","lessThan":"16.0.6","versionType":"semver","status":"affected"},{"version":"16.1","lessThan":"16.1.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N","baseScore":3.5,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-11-12T16:22:37.925822Z","id":"CVE-2023-1936","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-359"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.7","versionEndExcluding":"15.11.10","matchCriteriaId":"7B7F05A8-554B-4418-A8C7-D556F2600FDE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.7","versionEndExcluding":"15.11.10","matchCriteriaId":"F4029F02-A742-456F-9FB6-A23D2D753D72"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"16.0.6","matchCriteriaId":"691225A9-E175-41A1-A413-0FE619DF9ACF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"16.0.6","matchCriteriaId":"8D33EB2F-DB0F-40DA-9C1C-4A33856EABDD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.1","versionEndExcluding":"16.1.1","matchCriteriaId":"8C47692F-480C-4804-BA0D-E9AF1DB74B28"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.1","versionEndExcluding":"16.1.1","matchCriteriaId":"36D2F9C4-8B76-49F4-B9EE-DC2FBAA9EE2C"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/405150","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1933829","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/405150","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1933829","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-2190","sourceIdentifier":"cve@gitlab.com","published":"2023-07-13T02:15:09.203","lastModified":"2026-06-17T05:51:57.277","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.10 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1. It may be possible for users to view new commits to private projects in a fork created while the project was public."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"13.10","lessThan":"15.11.10","versionType":"semver","status":"affected"},{"version":"16.0","lessThan":"16.0.6","versionType":"semver","status":"affected"},{"version":"16.1","lessThan":"16.1.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-10-30T19:52:59.360319Z","id":"CVE-2023-2190","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-639"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-639"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.10.0","versionEndExcluding":"15.11.10","matchCriteriaId":"6F408655-1F07-4AFE-9BA2-5B073706F30B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.10.0","versionEndExcluding":"15.11.10","matchCriteriaId":"EE54DFF5-10AD-4890-A37F-2AF99505389E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"16.0.6","matchCriteriaId":"691225A9-E175-41A1-A413-0FE619DF9ACF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"16.0.6","matchCriteriaId":"8D33EB2F-DB0F-40DA-9C1C-4A33856EABDD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.1.0","versionEndExcluding":"16.1.1","matchCriteriaId":"EDBA8049-0CB9-4B64-B803-52210D57624F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.1.0","versionEndExcluding":"16.1.1","matchCriteriaId":"8365BE79-8EB8-4739-993B-851506085865"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/408137","source":"cve@gitlab.com","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1944500","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/408137","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1944500","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2023-2200","sourceIdentifier":"cve@gitlab.com","published":"2023-07-13T03:15:09.240","lastModified":"2026-06-17T05:51:58.643","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 7.14 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows an attacker to inject HTML in an email address field."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"7.14","lessThan":"15.11.10","versionType":"semver","status":"affected"},{"version":"16.0","lessThan":"16.0.6","versionType":"semver","status":"affected"},{"version":"16.1","lessThan":"16.1.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N","baseScore":4.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-10-30T19:30:59.856688Z","id":"CVE-2023-2200","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-116"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"7.14.0","versionEndExcluding":"15.11.10","matchCriteriaId":"7FFC59B5-FE82-44EB-98BC-AFD892AA1BA5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"7.14.0","versionEndExcluding":"15.11.10","matchCriteriaId":"5429AC1F-EA8D-4B4F-8BAF-71C48210F4C8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"16.0.6","matchCriteriaId":"691225A9-E175-41A1-A413-0FE619DF9ACF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"16.0.6","matchCriteriaId":"8D33EB2F-DB0F-40DA-9C1C-4A33856EABDD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.1.0","versionEndExcluding":"16.1.1","matchCriteriaId":"EDBA8049-0CB9-4B64-B803-52210D57624F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.1.0","versionEndExcluding":"16.1.1","matchCriteriaId":"8365BE79-8EB8-4739-993B-851506085865"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/408281","source":"cve@gitlab.com","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1935628","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/408281","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1935628","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2023-2576","sourceIdentifier":"cve@gitlab.com","published":"2023-07-13T03:15:09.317","lastModified":"2026-06-17T05:52:53.313","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1. This allowed a developer to remove the CODEOWNERS rules and merge to a protected branch."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"13.7","lessThan":"15.11.10","versionType":"semver","status":"affected"},{"version":"16.0","lessThan":"16.0.6","versionType":"semver","status":"affected"},{"version":"16.1","lessThan":"16.1.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-10-30T19:24:28.022972Z","id":"CVE-2023-2576","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"15.11.10","matchCriteriaId":"FAF95B4F-011A-4CA8-9B77-B2402A890546"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"15.11.10","matchCriteriaId":"693862A6-080F-463F-95F5-F3BC3E01BA45"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"16.0.6","matchCriteriaId":"691225A9-E175-41A1-A413-0FE619DF9ACF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"16.0.6","matchCriteriaId":"8D33EB2F-DB0F-40DA-9C1C-4A33856EABDD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.1.0","versionEndExcluding":"16.1.1","matchCriteriaId":"EDBA8049-0CB9-4B64-B803-52210D57624F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.1.0","versionEndExcluding":"16.1.1","matchCriteriaId":"8365BE79-8EB8-4739-993B-851506085865"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/410123","source":"cve@gitlab.com","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1898054","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/410123","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1898054","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2023-2620","sourceIdentifier":"cve@gitlab.com","published":"2023-07-13T03:15:09.393","lastModified":"2026-06-17T05:53:01.723","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.1 prior to 15.11.10, all versions from 16.0 prior to 16.0.6, all versions from 16.1 prior to 16.1.1. A maintainer could modify a webhook URL to leak masked webhook secrets by manipulating other masked portions. This addresses an incomplete fix for CVE-2023-0838."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.1","lessThan":"15.11.10","versionType":"semver","status":"affected"},{"version":"16.0","lessThan":"16.0.6","versionType":"semver","status":"affected"},{"version":"16.1","lessThan":"16.1.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N","baseScore":3.8,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-11-06T14:22:12.165370Z","id":"CVE-2023-2620","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-201"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.1.0","versionEndExcluding":"15.11.10","matchCriteriaId":"360C9FA7-D45C-45BC-B580-B045004AD490"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.1.0","versionEndExcluding":"15.11.10","matchCriteriaId":"E7E52754-B59F-4605-817A-E6D8CB1F1C28"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"16.0.6","matchCriteriaId":"691225A9-E175-41A1-A413-0FE619DF9ACF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"16.0.6","matchCriteriaId":"8D33EB2F-DB0F-40DA-9C1C-4A33856EABDD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.1.0","versionEndExcluding":"16.1.1","matchCriteriaId":"EDBA8049-0CB9-4B64-B803-52210D57624F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.1.0","versionEndExcluding":"16.1.1","matchCriteriaId":"8365BE79-8EB8-4739-993B-851506085865"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/410433","source":"cve@gitlab.com","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1976206","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/410433","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1976206","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2023-3362","sourceIdentifier":"cve@gitlab.com","published":"2023-07-13T03:15:10.217","lastModified":"2026-06-17T06:13:53.793","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An information disclosure issue in GitLab CE/EE affecting all versions from 16.0 prior to 16.0.6, and version 16.1.0 allows unauthenticated actors to access the import error information if a project was imported from GitHub."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.0","lessThan":"16.0.6","versionType":"semver","status":"affected"},{"version":"16.1","lessThan":"16.1.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-11-05T15:10:42.731379Z","id":"CVE-2023-3362","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-209"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-209"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"16.0.6","matchCriteriaId":"691225A9-E175-41A1-A413-0FE619DF9ACF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"16.0.6","matchCriteriaId":"8D33EB2F-DB0F-40DA-9C1C-4A33856EABDD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.1.0:*:*:*:community:*:*:*","matchCriteriaId":"C4071EE0-CDB1-49B9-9B64-1783597A4EC3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"5E6C33D0-3B6E-434F-A1B9-5495B1C35308"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/415131","source":"cve@gitlab.com","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/415131","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2023-3363","sourceIdentifier":"cve@gitlab.com","published":"2023-07-13T03:15:10.280","lastModified":"2026-06-17T06:13:53.927","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An information disclosure issue in Gitlab CE/EE affecting all versions from 13.6 prior to 15.11.10, all versions from 16.0 prior to 16.0.6, all versions from 16.1 prior to 16.1.1, resulted in the Sidekiq log including webhook tokens when the log format was set to `default`."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"13.6","lessThan":"15.11.10","versionType":"semver","status":"affected"},{"version":"16.0","lessThan":"16.0.6","versionType":"semver","status":"affected"},{"version":"16.1","lessThan":"16.1.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N","baseScore":3.9,"baseSeverity":"LOW","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":0.8,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N","baseScore":3.8,"baseSeverity":"LOW","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.0,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-11-05T15:13:58.915898Z","id":"CVE-2023-3363","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-532"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-532"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.6","versionEndExcluding":"15.11.10","matchCriteriaId":"577B87FF-E7E0-4E87-A5CC-7D0605BAE647"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.6","versionEndExcluding":"15.11.10","matchCriteriaId":"5A342CED-40DE-4E6A-B8A1-F64D21987F04"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"16.0.6","matchCriteriaId":"691225A9-E175-41A1-A413-0FE619DF9ACF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"16.0.6","matchCriteriaId":"8D33EB2F-DB0F-40DA-9C1C-4A33856EABDD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.1","versionEndExcluding":"16.1.1","matchCriteriaId":"8C47692F-480C-4804-BA0D-E9AF1DB74B28"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.1","versionEndExcluding":"16.1.1","matchCriteriaId":"36D2F9C4-8B76-49F4-B9EE-DC2FBAA9EE2C"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/409034","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/409034","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2023-3424","sourceIdentifier":"cve@gitlab.com","published":"2023-07-13T03:15:10.347","lastModified":"2026-06-17T06:14:02.733","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.3 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1. A Regular Expression Denial of Service was possible via sending crafted payloads to the preview_markdown endpoint."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"10.3","lessThan":"15.11.10","versionType":"semver","status":"affected"},{"version":"16.0","lessThan":"16.0.6","versionType":"semver","status":"affected"},{"version":"16.1","lessThan":"16.1.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-10-30T19:29:14.694767Z","id":"CVE-2023-3424","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1333"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-1333"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.3.0","versionEndExcluding":"15.11.10","matchCriteriaId":"85F16F5A-A24C-463E-A8C1-13B6DC4A5FC0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.3.0","versionEndExcluding":"15.11.10","matchCriteriaId":"0BF67728-D908-4A42-8FCA-F44C6C8909B5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"16.0.6","matchCriteriaId":"691225A9-E175-41A1-A413-0FE619DF9ACF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"16.0.6","matchCriteriaId":"8D33EB2F-DB0F-40DA-9C1C-4A33856EABDD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.1.0","versionEndExcluding":"16.1.1","matchCriteriaId":"EDBA8049-0CB9-4B64-B803-52210D57624F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.1.0","versionEndExcluding":"16.1.1","matchCriteriaId":"8365BE79-8EB8-4739-993B-851506085865"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/409802","source":"cve@gitlab.com","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1960970","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/409802","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1960970","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2023-3444","sourceIdentifier":"cve@gitlab.com","published":"2023-07-13T03:15:10.413","lastModified":"2026-06-17T06:14:05.167","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.3 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows an attacker to merge arbitrary code into protected branches."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.3","lessThan":"15.11.10","versionType":"semver","status":"affected"},{"version":"16.0","lessThan":"16.0.6","versionType":"semver","status":"affected"},{"version":"16.1","lessThan":"16.1.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N","baseScore":5.7,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-11-05T15:15:19.899476Z","id":"CVE-2023-3444","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.3.0","versionEndExcluding":"15.11.10","matchCriteriaId":"49DE9F51-690B-4278-86B5-2E5A942D72AB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.3.0","versionEndExcluding":"15.11.10","matchCriteriaId":"3D11BBB3-C99F-4D4D-93D9-F81A3F3D119B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"16.0.6","matchCriteriaId":"691225A9-E175-41A1-A413-0FE619DF9ACF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"16.0.6","matchCriteriaId":"8D33EB2F-DB0F-40DA-9C1C-4A33856EABDD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.1.0","versionEndExcluding":"16.1.1","matchCriteriaId":"EDBA8049-0CB9-4B64-B803-52210D57624F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.1.0","versionEndExcluding":"16.1.1","matchCriteriaId":"8365BE79-8EB8-4739-993B-851506085865"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/406803","source":"cve@gitlab.com","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1928709","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/406803","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1928709","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2023-3484","sourceIdentifier":"cve@gitlab.com","published":"2023-07-21T14:15:10.010","lastModified":"2026-06-17T06:14:11.573","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions starting from 12.8 before 15.11.11, all versions starting from 16.0 before 16.0.7, all versions starting from 16.1 before 16.1.2. An attacker could change the name or path of a public top-level group in certain situations."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"12.8","lessThan":"15.11.11","versionType":"semver","status":"affected"},{"version":"16.0","lessThan":"16.0.7","versionType":"semver","status":"affected"},{"version":"16.1","lessThan":"16.1.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H","baseScore":8.0,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.3,"impactScore":6.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-24T18:14:49.788917Z","id":"CVE-2023-3484","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.8.0","versionEndExcluding":"15.11.11","matchCriteriaId":"32F2AE09-2A49-4C15-AA12-2A3921C0299A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"16.0.7","matchCriteriaId":"9BEC60C3-6725-4F2A-ABCF-E536C8DD4D63"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.1.0","versionEndExcluding":"16.1.2","matchCriteriaId":"A33FDEA1-2885-400D-BCE7-C1EEE80A6E3E"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/416773","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2035687","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://about.gitlab.com/releases/2023/07/05/security-release-gitlab-16-1-2-released/","source":"nvd@nist.gov","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/416773","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2035687","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-3102","sourceIdentifier":"cve@gitlab.com","published":"2023-07-21T16:15:10.053","lastModified":"2026-06-17T06:13:21.707","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A sensitive information leak issue has been discovered in GitLab EE affecting all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows access to titles of private issue and MR."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.0","lessThan":"16.0.6","versionType":"semver","status":"affected"},{"version":"16.1","lessThan":"16.1.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-24T18:25:32.964663Z","id":"CVE-2023-3102","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-201"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"16.0.6","matchCriteriaId":"8D33EB2F-DB0F-40DA-9C1C-4A33856EABDD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"5E6C33D0-3B6E-434F-A1B9-5495B1C35308"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/414269","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2012073","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/414269","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2012073","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-1401","sourceIdentifier":"cve@gitlab.com","published":"2023-07-26T07:15:09.103","lastModified":"2026-06-17T05:27:52.633","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab DAST scanner affecting all versions starting from 3.0.29 before 4.0.5, in which the DAST scanner leak cross site cookies on redirect during authorization."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"3.0.29","lessThan":"4.0.5","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N","baseScore":5.0,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-08-30T14:03:48.092750Z","id":"CVE-2023-1401","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-201"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"3.0.29","versionEndExcluding":"4.0.5","matchCriteriaId":"F96480B2-9541-4E3E-BD5E-A93D2AA8D8D3"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/396533","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1889255","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/396533","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1889255","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2023-0632","sourceIdentifier":"cve@gitlab.com","published":"2023-08-02T00:15:16.163","lastModified":"2026-06-17T05:25:58.307","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A Regular Expression Denial of Service was possible by using crafted payloads to search Harbor Registry."},{"lang":"es","value":"Se ha descubierto un problema en GitLab que afecta a todas las versiones a partir de la 15.2 antes de la 16.0.8, todas las versiones a partir de la 16.1 antes de la 16.1.3, todas las versiones a partir de la 16.2 antes de la 16.2.2. Una denegación de servicio de expresión regular era posible mediante el uso de cargas útiles crafteadas para buscar en Harbor Registry.\n"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.2","lessThan":"16.0.8","versionType":"semver","status":"affected"},{"version":"16.1.0","lessThan":"16.1.3","versionType":"semver","status":"affected"},{"version":"16.2.0","lessThan":"16.2.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-24T13:33:10.385422Z","id":"CVE-2023-0632","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1333"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-1333"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.2","versionEndExcluding":"16.0.8","matchCriteriaId":"42FDC222-8F8F-43D7-8E8A-0924345E3085"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.2","versionEndExcluding":"16.0.8","matchCriteriaId":"B8B268E0-D27B-46F2-AC29-EAA56BCDC5E9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.1","versionEndExcluding":"16.1.3","matchCriteriaId":"5866BCA4-7C2D-4808-84FE-310E5D23454F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.1","versionEndExcluding":"16.1.3","matchCriteriaId":"F3157827-C742-45E6-B301-AD19559B1990"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.2","versionEndExcluding":"16.2.2","matchCriteriaId":"B5F4AA39-7E7A-4BF9-BF67-A7317308314A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.2","versionEndExcluding":"16.2.2","matchCriteriaId":"08D3BB71-01AC-47D7-ADD8-9D4EF67E66ED"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/390148","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1852677","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/390148","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1852677","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-1210","sourceIdentifier":"cve@gitlab.com","published":"2023-08-02T00:15:16.430","lastModified":"2026-06-17T05:27:22.083","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 12.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible to leak a user's email via an error message for groups that restrict membership by email domain."},{"lang":"es","value":"Se ha descubierto un problema en GitLab que afecta a todas las versiones a partir de la 12.9 antes de la 16.0.8, todas las versiones a partir de la 16.1 antes de la 16.1.3, todas las versiones a partir de la 16.2 antes de la 16.2.2. Era posible filtrar el correo electrónico de un usuario a través de un mensaje de error para los grupos que restringen la pertenencia por dominio de correo electrónico.\n"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"12.9","lessThan":"16.0.8","versionType":"semver","status":"affected"},{"version":"16.1.0","lessThan":"16.1.3","versionType":"semver","status":"affected"},{"version":"16.2.0","lessThan":"16.2.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":3.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-25T13:26:38.599217Z","id":"CVE-2023-1210","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-209"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"12.9","versionEndExcluding":"16.0.8","matchCriteriaId":"C8A2AFFB-9F5E-4AFE-AB72-F6FB839F4D62"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"16.1","versionEndExcluding":"16.1.3","matchCriteriaId":"3D0B2324-59E8-4149-A9C4-F3A3BAD537BD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"16.2","versionEndExcluding":"16.2.2","matchCriteriaId":"B6919591-CF6C-4E0C-9CD1-54932E43706E"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/394775","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1884672","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/394775","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1884672","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-2164","sourceIdentifier":"cve@gitlab.com","published":"2023-08-02T00:15:16.683","lastModified":"2026-06-17T05:51:53.943","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 15.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for an attacker to trigger a stored XSS vulnerability via user interaction with a crafted URL in the WebIDE beta."},{"lang":"es","value":"Se ha descubierto un problema en GitLab que afecta a todas las versiones a partir de la 15.9 antes de la 16.0.8, todas las versiones a partir de la 16.1 antes de la 16.1.3, todas las versiones a partir de la 16.2 antes de la 16.2.2. Era posible para un atacante desencadenar una vulnerabilidad XSS almacenada a través de la interacción del usuario con una URL crafteada en la beta WebIDE.\n"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.9","lessThan":"16.0.8","versionType":"semver","status":"affected"},{"version":"16.1.0","lessThan":"16.1.3","versionType":"semver","status":"affected"},{"version":"16.2.0","lessThan":"16.2.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-24T13:21:41.347556Z","id":"CVE-2023-2164","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.9","versionEndExcluding":"16.0.8","matchCriteriaId":"FFD938FB-5A38-41C5-AA6E-01AB91BF26A8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.9","versionEndExcluding":"16.0.8","matchCriteriaId":"E55AA8A4-B949-4500-B094-4C87970AA259"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.1","versionEndExcluding":"16.1.3","matchCriteriaId":"5866BCA4-7C2D-4808-84FE-310E5D23454F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.1","versionEndExcluding":"16.1.3","matchCriteriaId":"F3157827-C742-45E6-B301-AD19559B1990"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.2","versionEndExcluding":"16.2.2","matchCriteriaId":"B5F4AA39-7E7A-4BF9-BF67-A7317308314A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.2","versionEndExcluding":"16.2.2","matchCriteriaId":"08D3BB71-01AC-47D7-ADD8-9D4EF67E66ED"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/407783","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1940598","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/407783","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1940598","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-3364","sourceIdentifier":"cve@gitlab.com","published":"2023-08-02T00:15:18.467","lastModified":"2026-06-17T06:13:54.060","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.14 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A Regular Expression Denial of Service was possible via sending crafted payloads which use AutolinkFilter to the preview_markdown endpoint."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones a partir de la 8.14 antes de la 16.0.8, a todas las versiones a partir de la 16.1 antes de la 16.1.3, a todas las versiones a partir de la 16.2 antes de la 16.2.2. Una Denegación de Servicio de Expresión Regular era posible a través del envío de payloads crafteados que utilizan AutolinkFilter al endpoint preview_markdown.\n"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"8.14","lessThan":"16.0.8","versionType":"semver","status":"affected"},{"version":"16.1","lessThan":"16.1.3","versionType":"semver","status":"affected"},{"version":"16.2","lessThan":"16.2.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-08-30T14:22:23.720889Z","id":"CVE-2023-3364","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1333"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-1333"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.14","versionEndExcluding":"16.0.8","matchCriteriaId":"96C16180-BCE3-49C6-8802-7B4AAA6438EF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.14","versionEndExcluding":"16.0.8","matchCriteriaId":"CC5FEFB6-F11C-4BAA-8A53-29B563F0B234"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.1","versionEndExcluding":"16.1.3","matchCriteriaId":"5866BCA4-7C2D-4808-84FE-310E5D23454F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.1","versionEndExcluding":"16.1.3","matchCriteriaId":"F3157827-C742-45E6-B301-AD19559B1990"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.2","versionEndExcluding":"16.2.2","matchCriteriaId":"B5F4AA39-7E7A-4BF9-BF67-A7317308314A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.2","versionEndExcluding":"16.2.2","matchCriteriaId":"08D3BB71-01AC-47D7-ADD8-9D4EF67E66ED"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/415995","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1959727","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/415995","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1959727","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-3385","sourceIdentifier":"cve@gitlab.com","published":"2023-08-02T00:15:18.690","lastModified":"2026-06-17T06:13:56.590","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 8.10 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. Under specific circumstances, a user importing a project 'from export' could access and read unrelated files via uploading a specially crafted file. This was due to a bug in `tar`, fixed in [`tar-1.35`](https://lists.gnu.org/archive/html/info-gnu/2023-07/msg00005.html)."},{"lang":"es","value":"Se ha descubierto un problema en GitLab que afecta a todas las versiones a partir de la 8.10 antes de la 16.0.8, todas las versiones a partir de la 16.1 antes de la 16.1.3, todas las versiones a partir de la 16.2 antes de la 16.2.2. En determinadas circunstancias, un usuario que importaba un proyecto \"desde exportación\" podía acceder a archivos no relacionados y leerlos mediante la carga de un archivo especialmente diseñado. Esto se debía a un error en `tar`, corregido en [`tar-1.35`](https://lists.gnu.org/archive/html/info-gnu/2023-07/msg00005.html).\n"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"8.10","lessThan":"16.0.8","versionType":"semver","status":"affected"},{"version":"16.1.0","lessThan":"16.1.3","versionType":"semver","status":"affected"},{"version":"16.2.0","lessThan":"16.2.2","versionType":"semver","status":"affected"}]}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","affectedData":[{"vendor":"gitlab","product":"gitlab","defaultStatus":"unknown","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"versions":[{"version":"8.10","lessThan":"16.0.8","versionType":"custom","status":"affected"},{"version":"16.1.0","lessThan":"16.1.3","versionType":"custom","status":"affected"},{"version":"16.2.0","lessThan":"16.2.2","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N","baseScore":6.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.8,"impactScore":4.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-24T13:39:50.321710Z","id":"CVE-2023-3385","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-22"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-22"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.10","versionEndExcluding":"16.0.8","matchCriteriaId":"464745AD-160C-49DD-926D-50839EAEB751"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.10","versionEndExcluding":"16.0.8","matchCriteriaId":"42A815DE-E4CE-471C-9C2F-E75EF5F6E276"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.1","versionEndExcluding":"16.1.3","matchCriteriaId":"5866BCA4-7C2D-4808-84FE-310E5D23454F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.1","versionEndExcluding":"16.1.3","matchCriteriaId":"F3157827-C742-45E6-B301-AD19559B1990"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.2","versionEndExcluding":"16.2.2","matchCriteriaId":"B5F4AA39-7E7A-4BF9-BF67-A7317308314A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.2","versionEndExcluding":"16.2.2","matchCriteriaId":"08D3BB71-01AC-47D7-ADD8-9D4EF67E66ED"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/416161","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2032730","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/416161","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2032730","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-3500","sourceIdentifier":"cve@gitlab.com","published":"2023-08-02T01:15:09.520","lastModified":"2026-06-17T06:14:13.400","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.0 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A reflected XSS was possible when creating specific PlantUML diagrams that allowed the attacker to perform arbitrary actions on behalf of victims."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones a partir de la 10.0 antes de la 16.0.8, todas las versiones a partir de la 16.1 antes de la 16.1.3, todas las versiones a partir de la 16.2 antes de la 16.2.2. Un XSS reflejado era posible al crear diagramas PlantUML específicos que permitían al atacante realizar acciones arbitrarias en nombre de las víctimas.\n"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"10.0","lessThan":"16.0.8","versionType":"semver","status":"affected"},{"version":"16.1","lessThan":"16.1.3","versionType":"semver","status":"affected"},{"version":"16.2","lessThan":"16.2.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","baseScore":4.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":2.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-24T14:25:36.387559Z","id":"CVE-2023-3500","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.0","versionEndExcluding":"16.0.8","matchCriteriaId":"33EFD75A-D814-4EAE-A197-66A761D713AC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.0","versionEndExcluding":"16.0.8","matchCriteriaId":"B3CAAD60-BA19-456F-B81D-275DFE3BE09C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.1","versionEndExcluding":"16.1.3","matchCriteriaId":"5866BCA4-7C2D-4808-84FE-310E5D23454F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.1","versionEndExcluding":"16.1.3","matchCriteriaId":"F3157827-C742-45E6-B301-AD19559B1990"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.2","versionEndExcluding":"16.2.2","matchCriteriaId":"B5F4AA39-7E7A-4BF9-BF67-A7317308314A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.2","versionEndExcluding":"16.2.2","matchCriteriaId":"08D3BB71-01AC-47D7-ADD8-9D4EF67E66ED"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/416902","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2010926","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/416902","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2010926","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-3900","sourceIdentifier":"cve@gitlab.com","published":"2023-08-02T01:15:09.607","lastModified":"2026-06-17T06:15:17.370","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. An invalid 'start_sha' value on merge requests page may lead to Denial of Service as Changes tab would not load."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones a partir de 16.1 antes de 16.1.3, todas las versiones a partir de 16.2 antes de 16.2.2. Un valor no válido de 'start_sha' en la página de solicitudes de fusión puede provocar una denegación de servicio, ya que la pestaña Cambios no se carga.\n"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.1","lessThan":"16.1.3","versionType":"semver","status":"affected"},{"version":"16.2","lessThan":"16.2.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-25T13:45:19.965687Z","id":"CVE-2023-3900","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1287"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.1","versionEndExcluding":"16.1.3","matchCriteriaId":"5866BCA4-7C2D-4808-84FE-310E5D23454F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.1","versionEndExcluding":"16.1.3","matchCriteriaId":"F3157827-C742-45E6-B301-AD19559B1990"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.2","versionEndExcluding":"16.2.2","matchCriteriaId":"B5F4AA39-7E7A-4BF9-BF67-A7317308314A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.2","versionEndExcluding":"16.2.2","matchCriteriaId":"08D3BB71-01AC-47D7-ADD8-9D4EF67E66ED"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/418770","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2058514","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/418770","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2058514","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-3993","sourceIdentifier":"cve@gitlab.com","published":"2023-08-02T01:15:09.690","lastModified":"2026-06-17T06:15:38.953","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions starting from 14.3 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. Access tokens may have been logged when a query was made to a specific endpoint."},{"lang":"es","value":"Se ha descubierto un problema en GitLab EE que afecta a todas las versiones a partir de la 14.3 antes de la 16.0.8, a todas las versiones a partir de la 16.1 antes de la 16.1.3, a todas las versiones a partir de la 16.2 antes de la 16.2.2. Es posible que se hayan registrado tokens de acceso al realizar una consulta a un endpoint específico.\n"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"14.3","lessThan":"16.0.8","versionType":"semver","status":"affected"},{"version":"16.1","lessThan":"16.1.3","versionType":"semver","status":"affected"},{"version":"16.2","lessThan":"16.2.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-08-30T15:41:18.693629Z","id":"CVE-2023-3993","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-532"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.3","versionEndExcluding":"16.0.8","matchCriteriaId":"B99C90C5-9A45-49BB-83F2-D23633449084"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.3","versionEndExcluding":"16.0.8","matchCriteriaId":"FB8EB90A-C474-4EDB-BD23-7E8073647693"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.1","versionEndExcluding":"16.1.3","matchCriteriaId":"5866BCA4-7C2D-4808-84FE-310E5D23454F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.1","versionEndExcluding":"16.1.3","matchCriteriaId":"F3157827-C742-45E6-B301-AD19559B1990"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.2","versionEndExcluding":"16.2.2","matchCriteriaId":"B5F4AA39-7E7A-4BF9-BF67-A7317308314A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.2","versionEndExcluding":"16.2.2","matchCriteriaId":"08D3BB71-01AC-47D7-ADD8-9D4EF67E66ED"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/409570","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/409570","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2023-3994","sourceIdentifier":"cve@gitlab.com","published":"2023-08-02T01:15:09.773","lastModified":"2026-06-17T06:15:39.307","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 9.3 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A Regular Expression Denial of Service was possible via sending crafted payloads which use ProjectReferenceFilter to the preview_markdown endpoint."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones a partir de la 9.3 antes de la 16.0.8, todas las versiones a partir de la 16.1 antes de la 16.1.3, todas las versiones a partir de la 16.2 antes de la 16.2.2. Una Denegación de Servicio de Expresión Regular era posible a través del envío de payloads elaborados que utilizan ProjectReferenceFilter al endpoint preview_markdown.\n"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"9.3","lessThan":"16.0.8","versionType":"semver","status":"affected"},{"version":"16.1","lessThan":"16.1.3","versionType":"semver","status":"affected"},{"version":"16.2","lessThan":"16.2.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-08-30T15:42:16.495069Z","id":"CVE-2023-3994","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1333"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-1333"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"9.3","versionEndExcluding":"16.0.8","matchCriteriaId":"3F7DB54F-5D96-480D-BD9F-DEA5B6DBB088"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"9.3","versionEndExcluding":"16.0.8","matchCriteriaId":"D855EB5B-6592-4DEB-BA47-B40A808A1616"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.1","versionEndExcluding":"16.1.3","matchCriteriaId":"5866BCA4-7C2D-4808-84FE-310E5D23454F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.1","versionEndExcluding":"16.1.3","matchCriteriaId":"F3157827-C742-45E6-B301-AD19559B1990"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.2","versionEndExcluding":"16.2.2","matchCriteriaId":"B5F4AA39-7E7A-4BF9-BF67-A7317308314A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.2","versionEndExcluding":"16.2.2","matchCriteriaId":"08D3BB71-01AC-47D7-ADD8-9D4EF67E66ED"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/416225","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1963255","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/416225","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1963255","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-4011","sourceIdentifier":"cve@gitlab.com","published":"2023-08-02T06:15:11.523","lastModified":"2026-06-17T06:36:54.570","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions from 15.11 prior to 16.2.2 which allows an attacker to spike the resource consumption resulting in DoS."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.11","lessThan":"16.2.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-08-30T15:46:43.855469Z","id":"CVE-2023-4011","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.11","versionEndExcluding":"16.2.2","matchCriteriaId":"C638D3E0-9C3B-4F09-8F29-F9458A7969E9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.11","versionEndExcluding":"16.2.2","matchCriteriaId":"83F067C5-B12E-4984-A7FB-74D79CFFAA1D"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/409367","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/409367","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2023-2022","sourceIdentifier":"cve@gitlab.com","published":"2023-08-02T09:15:13.877","lastModified":"2026-06-17T05:51:12.923","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2, which leads to developers being able to create pipeline schedules on protected branches even if they don't have access to merge"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"0","lessThan":"16.0.8","versionType":"semver","status":"affected"},{"version":"16.1.0","lessThan":"16.1.3","versionType":"semver","status":"affected"},{"version":"16.2.0","lessThan":"16.2.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-24T14:47:23.774881Z","id":"CVE-2023-2022","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-262"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"16.0.8","matchCriteriaId":"9F473D69-05B2-445E-A730-5588C6B05EF4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"16.0.8","matchCriteriaId":"E15435E7-2E57-422F-ACD4-9E89181F7DFE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.1","versionEndExcluding":"16.1.3","matchCriteriaId":"5866BCA4-7C2D-4808-84FE-310E5D23454F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.1","versionEndExcluding":"16.1.3","matchCriteriaId":"F3157827-C742-45E6-B301-AD19559B1990"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.2","versionEndExcluding":"16.2.2","matchCriteriaId":"B5F4AA39-7E7A-4BF9-BF67-A7317308314A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.2","versionEndExcluding":"16.2.2","matchCriteriaId":"08D3BB71-01AC-47D7-ADD8-9D4EF67E66ED"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/407166","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1936572","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/407166","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1936572","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-3401","sourceIdentifier":"cve@gitlab.com","published":"2023-08-02T09:15:14.023","lastModified":"2026-06-17T06:14:00.170","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. The main branch of a repository with a specially designed name allows an attacker to create repositories with malicious code."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"0","lessThan":"16.0.8","versionType":"semver","status":"affected"},{"version":"16.1.0","lessThan":"16.1.3","versionType":"semver","status":"affected"},{"version":"16.2.0","lessThan":"16.2.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N","baseScore":4.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-24T13:55:12.534381Z","id":"CVE-2023-3401","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-94"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-94"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionEndExcluding":"16.0.8","matchCriteriaId":"CDE1E3A5-954A-4274-BEEC-DB42AE39BF9F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"16.1","versionEndExcluding":"16.1.3","matchCriteriaId":"3D0B2324-59E8-4149-A9C4-F3A3BAD537BD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"16.2","versionEndExcluding":"16.2.2","matchCriteriaId":"B6919591-CF6C-4E0C-9CD1-54932E43706E"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/416252","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2031845","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/416252","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2031845","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-3932","sourceIdentifier":"cve@gitlab.com","published":"2023-08-03T05:15:10.723","lastModified":"2026-06-17T06:15:21.010","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for an attacker to run pipeline jobs as an arbitrary user via scheduled security scan policies."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"13.12","lessThan":"16.0.8","versionType":"semver","status":"affected"},{"version":"16.1.0","lessThan":"16.1.3","versionType":"semver","status":"affected"},{"version":"16.2.0","lessThan":"16.2.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N","baseScore":8.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.8,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-24T13:25:44.895120Z","id":"CVE-2023-3932","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-286"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.12.0","versionEndExcluding":"16.0.8","matchCriteriaId":"91EEA705-42BA-4BFE-A96D-185938DB0FF4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.1.0","versionEndExcluding":"16.1.3","matchCriteriaId":"B6C23B24-069B-4665-9CA6-8D40AC5DDA91"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.2.0","versionEndExcluding":"16.2.2","matchCriteriaId":"4E16595C-02B7-4143-8991-E47770CCA461"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/417594","source":"cve@gitlab.com","tags":["Exploit"]},{"url":"https://hackerone.com/reports/2057633","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/417594","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"]},{"url":"https://hackerone.com/reports/2057633","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-4008","sourceIdentifier":"cve@gitlab.com","published":"2023-08-03T07:15:13.190","lastModified":"2026-06-17T06:36:54.150","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible to takeover GitLab Pages with unique domain URLs if the random string added was known."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.9","lessThan":"16.0.8","versionType":"semver","status":"affected"},{"version":"16.1","lessThan":"16.1.3","versionType":"semver","status":"affected"},{"version":"16.2","lessThan":"16.2.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-08-30T15:44:36.361443Z","id":"CVE-2023-4008","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-708"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.9.0","versionEndExcluding":"16.0.8","matchCriteriaId":"81EC4F22-AFD0-451E-A5CF-7EE70A69EABE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.9.0","versionEndExcluding":"16.0.8","matchCriteriaId":"C2213296-540C-40AF-921F-20D375B4A3C6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.1","versionEndExcluding":"16.1.3","matchCriteriaId":"5866BCA4-7C2D-4808-84FE-310E5D23454F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.1","versionEndExcluding":"16.1.3","matchCriteriaId":"F3157827-C742-45E6-B301-AD19559B1990"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.2","versionEndExcluding":"16.2.2","matchCriteriaId":"B5F4AA39-7E7A-4BF9-BF67-A7317308314A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.2","versionEndExcluding":"16.2.2","matchCriteriaId":"08D3BB71-01AC-47D7-ADD8-9D4EF67E66ED"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/415942","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/415942","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2023-4002","sourceIdentifier":"cve@gitlab.com","published":"2023-08-04T01:15:10.557","lastModified":"2026-06-17T06:36:53.207","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions starting from 14.1 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for EE-licensed users to link any security policy project by its ID to projects or groups the user has access to, potentially revealing the security projects's configured security policies."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"14.1","lessThan":"16.0.8","versionType":"semver","status":"affected"},{"version":"16.1.0","lessThan":"16.1.3","versionType":"semver","status":"affected"},{"version":"16.2.0","lessThan":"16.2.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-08-30T15:43:20.277244Z","id":"CVE-2023-4002","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-201"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"16.0.8","matchCriteriaId":"7AEF082A-297E-451B-AFE1-CD59360D328C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.1.0","versionEndExcluding":"16.1.3","matchCriteriaId":"B6C23B24-069B-4665-9CA6-8D40AC5DDA91"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.2.0","versionEndExcluding":"16.2.2","matchCriteriaId":"4E16595C-02B7-4143-8991-E47770CCA461"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/416647","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/416647","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2023-4522","sourceIdentifier":"cve@gitlab.com","published":"2023-08-30T08:15:52.673","lastModified":"2026-06-17T06:38:00.847","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions before 16.2.0. Committing directories containing LF character results in 500 errors when viewing the commit."},{"lang":"es","value":"Se ha descubierto un problema en GitLab que afecta a todas las versiones anteriores a la 16.2.0. La confirmación de directorios que contienen el carácter LF resulta en errores 500 al ver la confirmación."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"0","lessThan":"16.2.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":1.4}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1287"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionEndExcluding":"16.2.0","matchCriteriaId":"9083DA3B-05EC-402A-9942-0C83766A1AEB"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/406817","source":"cve@gitlab.com","tags":["Exploit"]},{"url":"https://hackerone.com/reports/1937213","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/406817","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"]},{"url":"https://hackerone.com/reports/1937213","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SJ42V7O7F4OU6R7QSQQECLB6LDHKZIMQ/","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2022-4343","sourceIdentifier":"cve@gitlab.com","published":"2023-09-01T11:15:40.037","lastModified":"2026-06-17T05:20:38.363","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 in which a project member can leak credentials stored in site profile."},{"lang":"es","value":"Se ha descubierto un problema en GitLab EE que afecta a todas las versiones a partir de 13.12 y antes de 16.1.5, todas las versiones a partir de 16.2 y antes de 16.2.5, todas las versiones a partir de 16.3 y antes de 16.3.1, en el que un miembro del proyecto puede filtrar las credenciales almacenadas del perfil del sitio."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"13.12","lessThan":"16.1.5","versionType":"semver","status":"affected"},{"version":"16.2","lessThan":"16.2.5","versionType":"semver","status":"affected"},{"version":"16.3","lessThan":"16.3.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N","baseScore":5.0,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-24T18:26:51.952665Z","id":"CVE-2022-4343","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-200"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.12","versionEndExcluding":"16.1.5","matchCriteriaId":"2E1E64DE-3BE7-4319-B93C-EB549C036847"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.2","versionEndExcluding":"16.2.5","matchCriteriaId":"4E03E8BA-63C8-47D5-B5A1-26DF199E1F65"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.3.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"08D6B555-39B6-493D-8460-3DC998BAF651"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/385124","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1767797","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/385124","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1767797","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-0120","sourceIdentifier":"cve@gitlab.com","published":"2023-09-01T11:15:40.287","lastModified":"2026-06-17T05:24:49.603","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 10.0 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. Due to improper permission validation it was possible to edit labels description by an unauthorised user."},{"lang":"es","value":"Se ha descubierto un problema en GitLab que afecta a todas las versiones a partir de la 10.0 antes de la 16.1.5, todas las versiones a partir de la 16.2 antes de la 16.2.5 y todas las versiones a partir de la 16.3 antes de la 16.3.1. Debido a una incorrecta validación de permisos era posible editar la descripción de las etiquetas por un usuario no autorizado. "}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"10.0","lessThan":"16.1.5","versionType":"semver","status":"affected"},{"version":"16.2","lessThan":"16.2.5","versionType":"semver","status":"affected"},{"version":"16.3","lessThan":"16.3.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N","baseScore":3.5,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-24T14:22:08.863186Z","id":"CVE-2023-0120","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.0.0","versionEndExcluding":"16.1.5","matchCriteriaId":"3A887955-FFCC-41E7-9EB0-C7C2E99955F9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.0.0","versionEndExcluding":"16.1.5","matchCriteriaId":"EDDBF1C4-0446-4795-8BBC-4CD0049126D8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.2","versionEndExcluding":"16.2.5","matchCriteriaId":"18116007-7452-495F-80A1-39499882656E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.2","versionEndExcluding":"16.2.5","matchCriteriaId":"4E03E8BA-63C8-47D5-B5A1-26DF199E1F65"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.3.0:*:*:*:community:*:*:*","matchCriteriaId":"EE9B8DE8-9990-494B-BDBE-F867DDBB9D57"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.3.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"08D6B555-39B6-493D-8460-3DC998BAF651"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/387531","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1818425","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/387531","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1818425","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-1279","sourceIdentifier":"cve@gitlab.com","published":"2023-09-01T11:15:40.473","lastModified":"2026-06-17T05:27:32.703","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 4.1 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 where it was possible to create a URL that would redirect to a different project."},{"lang":"es","value":"Se ha descubierto un problema en GitLab que afecta a todas las versiones a partir de 4.1 y antes de 16.1.5, todas las versiones a partir de 16.2 y antes de 16.2.5, todas las versiones a partir de 16.3 y antes de 16.3.1, donde es posible crear una URL que podría redireccionar a un proyecto diferente."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"4.1","lessThan":"16.1.5","versionType":"semver","status":"affected"},{"version":"16.2","lessThan":"16.2.5","versionType":"semver","status":"affected"},{"version":"16.3","lessThan":"16.3.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N","baseScore":2.6,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-08-30T13:46:06.407789Z","id":"CVE-2023-1279","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-601"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-601"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"4.1.0","versionEndExcluding":"16.1.5","matchCriteriaId":"EC779153-17C6-446D-ABEA-6CC063291EB7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"4.1.0","versionEndExcluding":"16.1.5","matchCriteriaId":"20DAB667-C975-4AA3-BDC0-87DFCE838B76"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.2","versionEndExcluding":"16.2.5","matchCriteriaId":"18116007-7452-495F-80A1-39499882656E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.2","versionEndExcluding":"16.2.5","matchCriteriaId":"4E03E8BA-63C8-47D5-B5A1-26DF199E1F65"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.3.0:*:*:*:community:*:*:*","matchCriteriaId":"EE9B8DE8-9990-494B-BDBE-F867DDBB9D57"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.3.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"08D6B555-39B6-493D-8460-3DC998BAF651"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/395437","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1889230","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/395437","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1889230","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-1555","sourceIdentifier":"cve@gitlab.com","published":"2023-09-01T11:15:40.663","lastModified":"2026-06-17T05:28:14.813","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. A namespace-level banned user can access the API."},{"lang":"es","value":"Se ha descubierto un problema en GitLab que afecta a todas las versiones a partir de la 15.2 antes de la 16.1.5, todas las versiones a partir de la 16.2 antes de la 16.2.5 y todas las versiones a partir de la 16.3 antes de la 16.3.1. Un usuario baneado a nivel de espacio de nombres puede acceder a la API. "}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.2","lessThan":"16.1.5","versionType":"semver","status":"affected"},{"version":"16.2","lessThan":"16.2.5","versionType":"semver","status":"affected"},{"version":"16.3","lessThan":"16.3.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N","baseScore":2.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-24T13:38:03.812458Z","id":"CVE-2023-1555","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-262"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.2.0","versionEndExcluding":"16.1.5","matchCriteriaId":"0BB62198-2175-4319-9754-A55F5AA20EDD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.2.0","versionEndExcluding":"16.1.5","matchCriteriaId":"8EBBBC86-4F64-4EAB-AF11-5552ED8FD0F8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.2","versionEndExcluding":"16.2.5","matchCriteriaId":"18116007-7452-495F-80A1-39499882656E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.2","versionEndExcluding":"16.2.5","matchCriteriaId":"4E03E8BA-63C8-47D5-B5A1-26DF199E1F65"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.3.0:*:*:*:community:*:*:*","matchCriteriaId":"EE9B8DE8-9990-494B-BDBE-F867DDBB9D57"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.3.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"08D6B555-39B6-493D-8460-3DC998BAF651"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/398587","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1911908","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/398587","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1911908","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-3205","sourceIdentifier":"cve@gitlab.com","published":"2023-09-01T11:15:41.850","lastModified":"2026-06-17T06:13:34.687","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 15.11 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. An authenticated user could trigger a denial of service when importing or cloning malicious content."},{"lang":"es","value":"Se ha descubierto un problema en GitLab que afecta a todas las versiones a partir de la 15.11 antes de la 16.1.5, a todas las versiones a partir de la 16.2 antes de la 16.2.5 y a todas las versiones a partir de la 16.3 antes de la 16.3.1. Un usuario autenticado podría desencadenar una denegación de servicio al importar o clonar contenido malicioso. "}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.11","lessThan":"16.1.5","versionType":"semver","status":"affected"},{"version":"16.2","lessThan":"16.2.5","versionType":"semver","status":"affected"},{"version":"16.3","lessThan":"16.3.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-24T13:18:58.862603Z","id":"CVE-2023-3205","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1333"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-1333"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.11","versionEndExcluding":"16.1.5","matchCriteriaId":"190E843E-6F15-4DD2-A5C4-C797BE750DA0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.11","versionEndExcluding":"16.1.5","matchCriteriaId":"1933945E-1CCB-4611-ABA6-9CD834CA6E62"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.2","versionEndExcluding":"16.2.5","matchCriteriaId":"18116007-7452-495F-80A1-39499882656E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.2","versionEndExcluding":"16.2.5","matchCriteriaId":"4E03E8BA-63C8-47D5-B5A1-26DF199E1F65"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.3.0:*:*:*:community:*:*:*","matchCriteriaId":"EE9B8DE8-9990-494B-BDBE-F867DDBB9D57"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.3.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"08D6B555-39B6-493D-8460-3DC998BAF651"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/415067","source":"cve@gitlab.com","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/2011464","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/415067","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/2011464","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-3210","sourceIdentifier":"cve@gitlab.com","published":"2023-09-01T11:15:42.053","lastModified":"2026-06-17T06:13:35.190","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 15.11 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. An authenticated user could trigger a denial of service when importing or cloning malicious content."},{"lang":"es","value":"Se ha descubierto un problema en GitLab que afecta a todas las versiones a partir de la 15.11 antes de la 16.1.5, a todas las versiones a partir de la 16.2 antes de la 16.2.5 y a todas las versiones a partir de la 16.3 antes de la 16.3.1. Un usuario autenticado podría desencadenar una denegación de servicio al importar o clonar contenido malicioso. "}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.11","lessThan":"16.1.5","versionType":"semver","status":"affected"},{"version":"16.2","lessThan":"16.2.5","versionType":"semver","status":"affected"},{"version":"16.3","lessThan":"16.3.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-25T13:55:32.325650Z","id":"CVE-2023-3210","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1333"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-1333"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.11","versionEndExcluding":"16.1.5","matchCriteriaId":"190E843E-6F15-4DD2-A5C4-C797BE750DA0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.11","versionEndExcluding":"16.1.5","matchCriteriaId":"1933945E-1CCB-4611-ABA6-9CD834CA6E62"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.2","versionEndExcluding":"16.2.5","matchCriteriaId":"18116007-7452-495F-80A1-39499882656E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.2","versionEndExcluding":"16.2.5","matchCriteriaId":"4E03E8BA-63C8-47D5-B5A1-26DF199E1F65"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.3.0:*:*:*:community:*:*:*","matchCriteriaId":"EE9B8DE8-9990-494B-BDBE-F867DDBB9D57"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.3.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"08D6B555-39B6-493D-8460-3DC998BAF651"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/415074","source":"cve@gitlab.com","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/2011474","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/415074","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/2011474","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-3915","sourceIdentifier":"cve@gitlab.com","published":"2023-09-01T11:15:42.267","lastModified":"2026-06-17T06:15:19.490","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions starting from 16.1 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. If an external user is given an owner role on any group, that external user may escalate their privileges on the instance by creating a service account in that group. This service account is not classified as external and may be used to access internal projects."},{"lang":"es","value":"Se ha descubierto un problema en GitLab EE que afecta a todas las versiones a partir de la 16.1 antes de la 16.1.5, todas las versiones a partir de la 16.2 antes de la 16.2.5 y todas las versiones a partir de la 16.3 antes de la 16.3.1. Si a un usuario externo se le otorga un rol de propietario en cualquier grupo, ese usuario externo puede escalar sus privilegios en la instancia creando una cuenta de servicio en ese grupo. Esta cuenta de servicio no se clasifica como externa y puede utilizarse para acceder a proyectos internos. "}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.1","lessThan":"16.1.5","versionType":"semver","status":"affected"},{"version":"16.2","lessThan":"16.2.5","versionType":"semver","status":"affected"},{"version":"16.3","lessThan":"16.3.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-24T13:59:46.729499Z","id":"CVE-2023-3915","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-279"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-732"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.1.0","versionEndExcluding":"16.1.5","matchCriteriaId":"9CE5E96F-15A1-43AB-ABF6-3B1490B5D12C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.1.0","versionEndExcluding":"16.1.5","matchCriteriaId":"D8DD59A9-B682-4B74-8E18-29210812CAFD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.2","versionEndExcluding":"16.2.5","matchCriteriaId":"18116007-7452-495F-80A1-39499882656E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.2","versionEndExcluding":"16.2.5","matchCriteriaId":"4E03E8BA-63C8-47D5-B5A1-26DF199E1F65"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.3.0:*:*:*:community:*:*:*","matchCriteriaId":"EE9B8DE8-9990-494B-BDBE-F867DDBB9D57"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.3.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"08D6B555-39B6-493D-8460-3DC998BAF651"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/417664","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2040834","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/417664","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2040834","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-3950","sourceIdentifier":"cve@gitlab.com","published":"2023-09-01T11:15:42.457","lastModified":"2026-06-17T06:15:26.660","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An information disclosure issue in GitLab EE affecting all versions from 16.2 prior to 16.2.5, and 16.3 prior to 16.3.1 allowed other Group Owners to see the Public Key for a Google Cloud Logging audit event streaming destination, if configured. Owners can now only write the key, not read it."},{"lang":"es","value":"Un problema de divulgación de información en GitLab EE que afectaba a todas las versiones desde la 16.2 hasta la 16.2.5, y desde la 16.3 hasta la 16.3.1 permitía a otros propietarios de grupo ver la clave pública de un destino de transmisión de eventos de auditoría de Google Cloud Logging, si estaba configurado. Ahora los propietarios solo pueden escribir la clave, no leerla. "}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.2","lessThan":"16.2.5","versionType":"semver","status":"affected"},{"version":"16.3","lessThan":"16.3.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N","baseScore":3.8,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-24T13:26:30.561894Z","id":"CVE-2023-3950","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-312"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-312"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.2","versionEndExcluding":"16.2.5","matchCriteriaId":"18116007-7452-495F-80A1-39499882656E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.2","versionEndExcluding":"16.2.5","matchCriteriaId":"4E03E8BA-63C8-47D5-B5A1-26DF199E1F65"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.3.0:*:*:*:community:*:*:*","matchCriteriaId":"EE9B8DE8-9990-494B-BDBE-F867DDBB9D57"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.3.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"08D6B555-39B6-493D-8460-3DC998BAF651"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/419675","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2079154","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/419675","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2079154","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-4018","sourceIdentifier":"cve@gitlab.com","published":"2023-09-01T11:15:43.037","lastModified":"2026-06-17T06:36:55.407","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. Due to improper permission validation it was possible to create model experiments in public projects."},{"lang":"es","value":"Se ha descubierto un problema en GitLab que afecta a todas las versiones desde la 16.2 antes de la 16.2.5, y a todas las versiones desde la 16.3 antes de la 16.3.1. Debido a una validación de permisos incorrecta, era posible crear experimentos de modelos en proyectos públicos."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.2","lessThan":"16.2.5","versionType":"semver","status":"affected"},{"version":"16.3","lessThan":"16.3.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-24T13:31:06.799486Z","id":"CVE-2023-4018","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-425"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.2","versionEndExcluding":"16.2.5","matchCriteriaId":"18116007-7452-495F-80A1-39499882656E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.2","versionEndExcluding":"16.2.5","matchCriteriaId":"4E03E8BA-63C8-47D5-B5A1-26DF199E1F65"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.3.0:*:*:*:community:*:*:*","matchCriteriaId":"EE9B8DE8-9990-494B-BDBE-F867DDBB9D57"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.3.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"08D6B555-39B6-493D-8460-3DC998BAF651"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/420301","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2083440","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/420301","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2083440","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-4378","sourceIdentifier":"cve@gitlab.com","published":"2023-09-01T11:15:43.113","lastModified":"2026-06-17T06:37:42.350","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. A malicious Maintainer can, under specific circumstances, leak the sentry token by changing the configured URL in the Sentry error tracking settings page. This was as a result of an incomplete fix for CVE-2022-4365."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones a partir de la 11.8 anteriores a la 16.1.5, todas las versiones a partir de la 16.2 anteriores a la 16.2.5, todas las versiones a partir de la 16.3 anteriores a la 16.3.1. Un mantenedor malicioso puede, bajo circunstancias específicas, filtrar el token de Sentry al cambiar la URL configurada en la página de configuración de seguimiento de errores de Sentry. Esto fue como resultado de una solución incompleta para CVE-2022-4365."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"11.8","lessThan":"16.1.5","versionType":"semver","status":"affected"},{"version":"16.2","lessThan":"16.2.5","versionType":"semver","status":"affected"},{"version":"16.3","lessThan":"16.3.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-08-30T15:48:23.298311Z","id":"CVE-2023-4378","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-201"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"16.1.5","matchCriteriaId":"593DB34F-FA65-443F-B5E8-D6C2FA38EC1A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"16.1.5","matchCriteriaId":"BF3A9B30-D096-478C-A38E-BC0620852F65"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.2","versionEndExcluding":"16.2.5","matchCriteriaId":"18116007-7452-495F-80A1-39499882656E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.2","versionEndExcluding":"16.2.5","matchCriteriaId":"4E03E8BA-63C8-47D5-B5A1-26DF199E1F65"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.3.0:*:*:*:community:*:*:*","matchCriteriaId":"EE9B8DE8-9990-494B-BDBE-F867DDBB9D57"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.3.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"08D6B555-39B6-493D-8460-3DC998BAF651"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/422134","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2104591","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/422134","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2104591","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-4647","sourceIdentifier":"cve@gitlab.com","published":"2023-09-01T11:15:43.363","lastModified":"2026-06-17T06:38:17.543","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 in which the projects API pagination can be skipped, potentially leading to DoS on certain instances."},{"lang":"es","value":"Se ha descubierto un problema en GitLab que afecta a todas las versiones desde la 15.2 anteriores a la 16.1.5, todas las versiones desde la 16.2 anteriores a la 16.2.5, todas las versiones desde la 16.3 anteriores a la 16.3.1 en las que la paginación de la API de proyectos puede omitirse, lo que podría llevar a un DoS en ciertas instancias."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.2","lessThan":"16.1.5","versionType":"semver","status":"affected"},{"version":"16.2","lessThan":"16.2.5","versionType":"semver","status":"affected"},{"version":"16.3","lessThan":"16.3.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":1.6,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-08-30T15:17:28.282038Z","id":"CVE-2023-4647","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.2.0","versionEndExcluding":"16.1.5","matchCriteriaId":"0BB62198-2175-4319-9754-A55F5AA20EDD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.2.0","versionEndExcluding":"16.1.5","matchCriteriaId":"8EBBBC86-4F64-4EAB-AF11-5552ED8FD0F8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.2","versionEndExcluding":"16.2.5","matchCriteriaId":"18116007-7452-495F-80A1-39499882656E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.2","versionEndExcluding":"16.2.5","matchCriteriaId":"4E03E8BA-63C8-47D5-B5A1-26DF199E1F65"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.3.0:*:*:*:community:*:*:*","matchCriteriaId":"EE9B8DE8-9990-494B-BDBE-F867DDBB9D57"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.3.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"08D6B555-39B6-493D-8460-3DC998BAF651"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/414502","source":"cve@gitlab.com","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/414502","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2023-4630","sourceIdentifier":"cve@gitlab.com","published":"2023-09-11T14:15:09.343","lastModified":"2026-06-17T06:38:15.613","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 10.6 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 in which any user can read limited information about any project's imports."},{"lang":"es","value":"Se ha descubierto un problema en GitLab que afecta a todas las versiones desde 10.6 anteriores a 16.1.5, todas las versiones desde 16.2 anteriores a 16.2.5, todas las versiones desde 16.3 anteriores a 16.3.1 en el que cualquier usuario puede leer información limitada sobre las importaciones de cualquier proyecto."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"10.6","lessThan":"16.1.5","versionType":"semver","status":"affected"},{"version":"16.2","lessThan":"16.2.5","versionType":"semver","status":"affected"},{"version":"16.3","lessThan":"16.3.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N","baseScore":5.0,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-08-30T15:19:12.333205Z","id":"CVE-2023-4630","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.6.0","versionEndExcluding":"16.1.5","matchCriteriaId":"F9BDADFA-ADB1-488F-AB5A-209A19FC70A2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.6.0","versionEndExcluding":"16.1.5","matchCriteriaId":"21BFE27A-793C-4B3C-BC89-B341A0777F7E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.2.0","versionEndExcluding":"16.2.5","matchCriteriaId":"0892F9AB-63DF-4753-9463-34C81A2174B5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.2.0","versionEndExcluding":"16.2.5","matchCriteriaId":"D678B1CF-DAF8-4A11-80D4-0CB0796A104C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.3.0:*:*:*:community:*:*:*","matchCriteriaId":"EE9B8DE8-9990-494B-BDBE-F867DDBB9D57"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.3.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"08D6B555-39B6-493D-8460-3DC998BAF651"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/415117","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://about.gitlab.com/releases/2023/08/31/security-release-gitlab-16-3-1-released/","source":"nvd@nist.gov","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/415117","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2023-5009","sourceIdentifier":"cve@gitlab.com","published":"2023-09-19T08:16:07.203","lastModified":"2026-06-17T06:47:20.077","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.2.7, all versions starting from 16.3 before 16.3.4. It was possible for an attacker to run pipeline jobs as an arbitrary user via scheduled security scan policies. This was a bypass of [CVE-2023-3932](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3932) showing additional impact."},{"lang":"es","value":"Se ha descubierto un problema en GitLab EE que afecta a todas las versiones a partir de 13.12 antes de 16.2.7, todas las versiones a partir de 16.3 antes de 16.3.4. Era posible que un atacante ejecutara trabajos de canalización como un usuario arbitrario a través de directivas de análisis de seguridad programadas. Esta fue una omisión de [CVE-2023-3932](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3932) que muestra un impacto adicional. "}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"13.12","lessThan":"16.2.7","versionType":"semver","status":"affected"},{"version":"16.3","lessThan":"16.3.4","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N","baseScore":8.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.8,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-26T21:51:08.131679Z","id":"CVE-2023-5009","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.12","versionEndExcluding":"16.2.7","matchCriteriaId":"705EDAB3-930B-4B00-BAD7-B5035FB0B1F6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.3","versionEndExcluding":"16.3.4","matchCriteriaId":"5CCAE929-1AE7-4E4E-BBF9-3D2A7D1ACBDA"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/425304","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2147126","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/425304","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2147126","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-0989","sourceIdentifier":"cve@gitlab.com","published":"2023-09-29T07:15:12.520","lastModified":"2026-06-17T05:26:50.400","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An information disclosure issue in GitLab CE/EE affecting all versions starting from 13.11 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows an attacker to extract non-protected CI/CD variables by tricking a user to visit a fork with a malicious CI/CD configuration."},{"lang":"es","value":"Un problema de divulgación de información en GitLab CE/EE que afecta a todas las versiones a partir de 13.11 anterior a 16.2.8, 16.3 anterior a 16.3.5 y 16.4 anterior a 16.4.1 permite a un atacante extraer variables CI/CD no protegidas engañando a un usuario visite un fork con una configuración CI/CD maliciosa."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"0","lessThan":"16.2.8","versionType":"semver","status":"affected"},{"version":"16.3","lessThan":"16.3.5","versionType":"semver","status":"affected"},{"version":"16.4","lessThan":"16.4.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N","baseScore":5.7,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-24T13:25:59.406671Z","id":"CVE-2023-0989","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-282"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.11","versionEndExcluding":"16.2.8","matchCriteriaId":"CAC76B33-DE62-4035-B31B-2FE3FCBAEF12"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.11","versionEndExcluding":"16.2.8","matchCriteriaId":"A3FF5950-206F-48B5-8212-23142D0704BC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.3.0","versionEndExcluding":"16.3.5","matchCriteriaId":"50271B2B-7070-4ED0-AB68-65B99D44A68A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.3.0","versionEndExcluding":"16.3.5","matchCriteriaId":"CC5696C9-592A-4D50-B5BB-9A250DAB6589"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.4.0:*:*:*:community:*:*:*","matchCriteriaId":"B5D4FDD1-7A68-4245-A4D5-842E4FD03FAE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.4.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"6696C987-61C1-462E-8A73-016F9902BC67"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/417275","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1875515","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/417275","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1875515","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-2233","sourceIdentifier":"cve@gitlab.com","published":"2023-09-29T07:15:12.927","lastModified":"2026-06-17T05:52:03.683","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An improper authorization issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 16.2.8, all versions starting from 16.3 before 16.3.5 and all versions starting from 16.4 before 16.4.1. It allows a project reporter to leak the owner's Sentry instance projects."},{"lang":"es","value":"Se descubrió un problema de autorización incorrecta en GitLab CE/EE que afecta a todas las versiones desde 11.8 anteriores a 16.2.8, todas las versiones desde 16.3 anteriores a 16.3.5 y todas las versiones desde 16.4 anteriores a 16.4.1. Permite que un reportero de proyecto filtre los proyectos de instancia Sentry del propietario."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"11.8","lessThan":"16.2.8","versionType":"semver","status":"affected"},{"version":"16.3","lessThan":"16.3.5","versionType":"semver","status":"affected"},{"version":"16.4","lessThan":"16.4.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":3.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-08-30T14:19:07.736908Z","id":"CVE-2023-2233","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.8","versionEndExcluding":"16.2.8","matchCriteriaId":"E5FBAA53-BF11-42BB-8438-C3A59D8CA34A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.8","versionEndExcluding":"16.2.8","matchCriteriaId":"5E362959-B840-4765-BEB7-DD7D21D4C0BD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.3.0","versionEndExcluding":"16.3.5","matchCriteriaId":"50271B2B-7070-4ED0-AB68-65B99D44A68A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.3.0","versionEndExcluding":"16.3.5","matchCriteriaId":"CC5696C9-592A-4D50-B5BB-9A250DAB6589"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.4.0:*:*:*:community:*:*:*","matchCriteriaId":"B5D4FDD1-7A68-4245-A4D5-842E4FD03FAE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.4.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"6696C987-61C1-462E-8A73-016F9902BC67"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/408359","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1947211","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/408359","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/1947211","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-3115","sourceIdentifier":"cve@gitlab.com","published":"2023-09-29T07:15:13.100","lastModified":"2026-06-17T06:13:23.480","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions affecting all versions from 11.11 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. Single Sign On restrictions were not correctly enforced for indirect project members accessing public members-only project repositories."},{"lang":"es","value":"Se descubrió un problema en GitLab EE que afecta a todas las versiones desde 11.11 anteriores a 16.2.8, 16.3 anteriores a 16.3.5 y 16.4 anteriores a 16.4.1. Las restricciones de Inicio de Sesión Único no se aplicaron correctamente para los miembros indirectos del proyecto que acceden a repositorios de proyectos públicos exclusivos para miembros."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"11.11","lessThan":"16.2.8","versionType":"semver","status":"affected"},{"version":"16.3","lessThan":"16.3.5","versionType":"semver","status":"affected"},{"version":"16.4","lessThan":"16.4.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-24T14:12:41.068956Z","id":"CVE-2023-3115","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-286"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.11","versionEndExcluding":"16.2.8","matchCriteriaId":"382FDBDE-2195-437C-8DAB-0EB4A077E5E1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.11","versionEndExcluding":"16.2.8","matchCriteriaId":"18284C5A-7019-4E00-B2A0-CCC5B4C2C7D1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.3.0","versionEndExcluding":"16.3.5","matchCriteriaId":"50271B2B-7070-4ED0-AB68-65B99D44A68A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.3.0","versionEndExcluding":"16.3.5","matchCriteriaId":"CC5696C9-592A-4D50-B5BB-9A250DAB6589"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.4.0:*:*:*:community:*:*:*","matchCriteriaId":"B5D4FDD1-7A68-4245-A4D5-842E4FD03FAE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.4.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"6696C987-61C1-462E-8A73-016F9902BC67"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/414367","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2004158","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/414367","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2004158","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-3906","sourceIdentifier":"cve@gitlab.com","published":"2023-09-29T07:15:13.233","lastModified":"2026-06-17T06:15:18.010","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An input validation issue in the asset proxy in GitLab EE, affecting all versions from 12.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1, allowed an authenticated attacker to craft image urls which bypass the asset proxy."},{"lang":"es","value":"Un problema de validación de entrada en el proxy de activos en GitLab EE, que afectó a todas las versiones desde 12.3 anterior a 16.2.8, 16.3 anterior a 16.3.5 y 16.4 anterior a 16.4.1, permitió a un atacante autenticado crear URL de imágenes que omitían el activo apoderado."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"12.3","lessThan":"16.2.8","versionType":"semver","status":"affected"},{"version":"16.3","lessThan":"16.3.5","versionType":"semver","status":"affected"},{"version":"16.4","lessThan":"16.4.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N","baseScore":3.5,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N","baseScore":3.5,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-08-30T14:28:00.520335Z","id":"CVE-2023-3906","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1287"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.3","versionEndExcluding":"16.2.8","matchCriteriaId":"8C9F0162-43D7-44C5-BC3D-85ACC3272FAB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.3","versionEndExcluding":"16.2.8","matchCriteriaId":"CA3C9D7F-FD61-4C19-9FB2-DEEA44B931F3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.3.0","versionEndExcluding":"16.3.5","matchCriteriaId":"50271B2B-7070-4ED0-AB68-65B99D44A68A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.3.0","versionEndExcluding":"16.3.5","matchCriteriaId":"CC5696C9-592A-4D50-B5BB-9A250DAB6589"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.4.0:*:*:*:community:*:*:*","matchCriteriaId":"B5D4FDD1-7A68-4245-A4D5-842E4FD03FAE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.4.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"6696C987-61C1-462E-8A73-016F9902BC67"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/419213","source":"cve@gitlab.com","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/2071411","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/419213","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/2071411","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-3914","sourceIdentifier":"cve@gitlab.com","published":"2023-09-29T07:15:13.380","lastModified":"2026-06-17T06:15:19.133","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A business logic error in GitLab EE affecting all versions prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows access to internal projects. A service account is not deleted when a namespace is deleted, allowing access to internal projects."},{"lang":"es","value":"Un error de lógica de negocios en GitLab EE que afecta a todas las versiones anteriores a 16.2.8, 16.3 anterior a 16.3.5 y 16.4 anterior a 16.4.1 permite el acceso a proyectos internos. Una cuenta de servicio no se elimina cuando se elimina un espacio de nombres, lo que permite el acceso a proyectos internos."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"0","lessThan":"16.2.8","versionType":"semver","status":"affected"},{"version":"16.3","lessThan":"16.3.5","versionType":"semver","status":"affected"},{"version":"16.4","lessThan":"16.4.1","versionType":"semver","status":"affected"}]}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","affectedData":[{"vendor":"gitlab","product":"gitlab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"versions":[{"version":"0","lessThan":"16.2.8","versionType":"semver","status":"affected"}]},{"vendor":"gitlab","product":"gitlab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:16.3.0:*:*:*:enterprise:*:*:*"],"versions":[{"version":"16.3.0","lessThan":"16.3.5","versionType":"semver","status":"affected"}]},{"vendor":"gitlab","product":"gitlab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:16.4.0:*:*:*:enterprise:*:*:*"],"versions":[{"version":"16.4.0","lessThan":"16.4.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-24T13:49:27.658392Z","id":"CVE-2023-3914","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-286"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"16.2.8","matchCriteriaId":"CC944069-5F94-4E2A-A13F-5D070BA4E5EB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.3.0","versionEndExcluding":"16.3.5","matchCriteriaId":"CC5696C9-592A-4D50-B5BB-9A250DAB6589"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.4.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"6696C987-61C1-462E-8A73-016F9902BC67"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/418115","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2040822","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/418115","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2040822","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-3917","sourceIdentifier":"cve@gitlab.com","published":"2023-09-29T07:15:13.557","lastModified":"2026-06-17T06:15:19.870","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Denial of Service in pipelines affecting all versions of Gitlab EE and CE prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows attacker to cause pipelines to fail."},{"lang":"es","value":"La Denegación de Servicio en pipelines afectan a todas las versiones de Gitlab EE y CE anteriores a 16.2.8, 16.3 anterior a 16.3.5 y 16.4 anterior a 16.4.1 permite que un atacante provoque fallas en los pipelines."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"0","lessThan":"16.2.8","versionType":"semver","status":"affected"},{"version":"16.3","lessThan":"16.3.5","versionType":"semver","status":"affected"},{"version":"16.4","lessThan":"16.4.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-08-30T15:40:36.735432Z","id":"CVE-2023-3917","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1287"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"16.2.8","matchCriteriaId":"F9180E94-B3C4-4DD4-A2DA-B6E818DAFFF4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"16.2.8","matchCriteriaId":"CC944069-5F94-4E2A-A13F-5D070BA4E5EB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.3.0","versionEndExcluding":"16.3.5","matchCriteriaId":"50271B2B-7070-4ED0-AB68-65B99D44A68A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.3.0","versionEndExcluding":"16.3.5","matchCriteriaId":"CC5696C9-592A-4D50-B5BB-9A250DAB6589"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.4.0:*:*:*:community:*:*:*","matchCriteriaId":"B5D4FDD1-7A68-4245-A4D5-842E4FD03FAE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.4.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"6696C987-61C1-462E-8A73-016F9902BC67"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/417896","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2055158","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/417896","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2055158","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-3920","sourceIdentifier":"cve@gitlab.com","published":"2023-09-29T07:15:13.777","lastModified":"2026-06-17T06:15:20.250","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 11.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible that a maintainer to create a fork relationship between existing projects contrary to the documentation."},{"lang":"es","value":"Se ha descubierto un problema en GitLab que afecta a todas las versiones desde 11.2 anteriores a 16.2.8, todas las versiones desde 16.3 anteriores a 16.3.5, todas las versiones desde 16.4 anteriores a 16.4.1. Era posible que un maintainer creara una relación de fork entre proyectos existentes en contraria a la documentación."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"11.2","lessThan":"16.2.8","versionType":"semver","status":"affected"},{"version":"16.3","lessThan":"16.3.5","versionType":"semver","status":"affected"},{"version":"16.4","lessThan":"16.4.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-24T18:28:54.700432Z","id":"CVE-2023-3920","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.2","versionEndExcluding":"16.2.8","matchCriteriaId":"50E3FE26-231D-4331-9334-D17F81A13692"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.2","versionEndExcluding":"16.2.8","matchCriteriaId":"50445735-D0E7-456C-9879-0856BD857601"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.3.0","versionEndExcluding":"16.3.5","matchCriteriaId":"50271B2B-7070-4ED0-AB68-65B99D44A68A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.3.0","versionEndExcluding":"16.3.5","matchCriteriaId":"CC5696C9-592A-4D50-B5BB-9A250DAB6589"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.4.0:*:*:*:community:*:*:*","matchCriteriaId":"B5D4FDD1-7A68-4245-A4D5-842E4FD03FAE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.4.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"6696C987-61C1-462E-8A73-016F9902BC67"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/417481","source":"cve@gitlab.com","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/2058121","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/417481","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/2058121","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-3979","sourceIdentifier":"cve@gitlab.com","published":"2023-09-29T07:15:13.910","lastModified":"2026-06-17T06:15:34.633","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 10.6 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible that upstream members to collaborate with you on your branch get permission to write to the merge request’s source branch."},{"lang":"es","value":"Se ha descubierto un problema en GitLab que afecta a todas las versiones desde 10.6 anteriores a 16.2.8, todas las versiones desde 16.3 anteriores a 16.3.5, todas las versiones desde 16.4 anteriores a 16.4.1. Era posible que los miembros upstream que colaboraran en su sucursal obtuvieran permisos para escribir en la sucursal fuente de la solicitud de fusión."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"10.6","lessThan":"16.2.8","versionType":"semver","status":"affected"},{"version":"16.3","lessThan":"16.3.5","versionType":"semver","status":"affected"},{"version":"16.4","lessThan":"16.4.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":3.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-25T14:04:09.768079Z","id":"CVE-2023-3979","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.6","versionEndExcluding":"16.2.8","matchCriteriaId":"049BDC78-13F1-4F9D-B6C1-C50F9109A1A6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.6","versionEndExcluding":"16.2.8","matchCriteriaId":"084AF463-DF79-4CF3-A85B-BDF6BF60AA57"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.3.0","versionEndExcluding":"16.3.5","matchCriteriaId":"50271B2B-7070-4ED0-AB68-65B99D44A68A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.3.0","versionEndExcluding":"16.3.5","matchCriteriaId":"CC5696C9-592A-4D50-B5BB-9A250DAB6589"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.4.0:*:*:*:community:*:*:*","matchCriteriaId":"B5D4FDD1-7A68-4245-A4D5-842E4FD03FAE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.4.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"6696C987-61C1-462E-8A73-016F9902BC67"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/419972","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2082560","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/419972","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2082560","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-4532","sourceIdentifier":"cve@gitlab.com","published":"2023-09-29T07:15:14.200","lastModified":"2026-06-17T06:38:01.800","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 16.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. Users were capable of linking CI/CD jobs of private projects which they are not a member of."},{"lang":"es","value":"Se ha descubierto un problema en GitLab que afecta a todas las versiones desde 16.2 anteriores a 16.2.8, todas las versiones desde 16.3 anteriores a 16.3.5, todas las versiones desde 16.4 anteriores a 16.4.1. Los usuarios pudieron vincular trabajos de CI/CD de proyectos privados de los que no son miembros."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.2","lessThan":"16.2.8","versionType":"semver","status":"affected"},{"version":"16.3","lessThan":"16.3.5","versionType":"semver","status":"affected"},{"version":"16.4","lessThan":"16.4.1","versionType":"semver","status":"affected"}]}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","affectedData":[{"vendor":"gitlab","product":"gitlab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:16.2:*:*:*:*:*:*:*"],"versions":[{"version":"16.2","lessThan":"16.2.8","versionType":"semver","status":"affected"}]},{"vendor":"gitlab","product":"gitlab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:16.4:*:*:*:*:*:*:*"],"versions":[{"version":"16.4","lessThan":"16.4.1","versionType":"semver","status":"affected"}]},{"vendor":"gitlab","product":"gitlab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:16.3:*:*:*:*:*:*:*"],"versions":[{"version":"16.3","lessThan":"16.3.5","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-24T14:37:07.802802Z","id":"CVE-2023-4532","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.2","versionEndExcluding":"16.2.8","matchCriteriaId":"168E0D83-64EF-4A48-8251-6AE3BDF006D8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.2","versionEndExcluding":"16.2.8","matchCriteriaId":"8215D0EC-C0BF-417C-8D70-7F1493A82BB1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.3.0","versionEndExcluding":"16.3.5","matchCriteriaId":"50271B2B-7070-4ED0-AB68-65B99D44A68A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.3.0","versionEndExcluding":"16.3.5","matchCriteriaId":"CC5696C9-592A-4D50-B5BB-9A250DAB6589"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.4.0:*:*:*:community:*:*:*","matchCriteriaId":"B5D4FDD1-7A68-4245-A4D5-842E4FD03FAE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.4.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"6696C987-61C1-462E-8A73-016F9902BC67"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/423357","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2084199","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/423357","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2084199","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-3922","sourceIdentifier":"cve@gitlab.com","published":"2023-09-29T08:15:09.537","lastModified":"2026-06-17T06:15:20.613","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 8.15 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible to hijack some links and buttons on the GitLab UI to a malicious page."},{"lang":"es","value":"Se ha descubierto un problema en GitLab que afecta a todas las versiones desde 8.15 anteriores a 16.2.8, todas las versiones desde 16.3 anteriores a 16.3.5, todas las versiones desde 16.4 anteriores a 16.4.1. Fue posible secuestrar algunos enlaces y botones en la interfaz de usuario de GitLab a una página maliciosa."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.2","lessThan":"16.2.8","versionType":"semver","status":"affected"},{"version":"16.3","lessThan":"16.3.5","versionType":"semver","status":"affected"},{"version":"16.4","lessThan":"16.4.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:N/A:L","baseScore":3.0,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":1.3,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":3.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-24T14:07:32.409128Z","id":"CVE-2023-3922","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-601"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-601"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.15","versionEndExcluding":"16.2.8","matchCriteriaId":"BDDBDB1B-AC24-4A29-BA7C-86000095393F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.15","versionEndExcluding":"16.2.8","matchCriteriaId":"36F30B4B-BB02-42CF-B173-AFFC924B9965"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.3.0","versionEndExcluding":"16.3.5","matchCriteriaId":"50271B2B-7070-4ED0-AB68-65B99D44A68A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.3.0","versionEndExcluding":"16.3.5","matchCriteriaId":"CC5696C9-592A-4D50-B5BB-9A250DAB6589"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.4.0:*:*:*:community:*:*:*","matchCriteriaId":"B5D4FDD1-7A68-4245-A4D5-842E4FD03FAE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.4.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"6696C987-61C1-462E-8A73-016F9902BC67"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/394770","source":"cve@gitlab.com","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1887323","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/394770","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1887323","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-5198","sourceIdentifier":"cve@gitlab.com","published":"2023-09-29T08:15:09.610","lastModified":"2026-06-17T06:48:04.567","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions prior to 16.2.7, all versions starting from 16.3 before 16.3.5, and all versions starting from 16.4 before 16.4.1. It was possible for a removed project member to write to protected branches using deploy keys."},{"lang":"es","value":"Se descubrió un problema en GitLab que afecta a todas las versiones anteriores a 16.2.7, todas las versiones desde 16.3 anteriores a 16.3.5 y todas las versiones desde 16.4 anteriores a 16.4.1. Era posible que un miembro eliminado del proyecto escribiera en sucursales protegidas utilizando claves de implementación."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"0","lessThanOrEqual":"16.2.7","versionType":"semver","status":"affected"},{"version":"16.3","lessThan":"16.3.5","versionType":"semver","status":"affected"},{"version":"16.4","lessThan":"16.4.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-08-30T15:12:22.702062Z","id":"CVE-2023-5198","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.15","versionEndExcluding":"16.2.8","matchCriteriaId":"BDDBDB1B-AC24-4A29-BA7C-86000095393F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.15","versionEndExcluding":"16.2.8","matchCriteriaId":"36F30B4B-BB02-42CF-B173-AFFC924B9965"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.3.0","versionEndExcluding":"16.3.5","matchCriteriaId":"50271B2B-7070-4ED0-AB68-65B99D44A68A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.3.0","versionEndExcluding":"16.3.5","matchCriteriaId":"CC5696C9-592A-4D50-B5BB-9A250DAB6589"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.4.0:*:*:*:community:*:*:*","matchCriteriaId":"B5D4FDD1-7A68-4245-A4D5-842E4FD03FAE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.4.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"6696C987-61C1-462E-8A73-016F9902BC67"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/416957","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2041789","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/416957","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2041789","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-3413","sourceIdentifier":"cve@gitlab.com","published":"2023-09-29T09:15:10.180","lastModified":"2026-06-17T06:14:01.550","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 16.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible to read the source code of a project through a fork created before changing visibility to only project members."},{"lang":"es","value":"Se ha descubierto un problema en GitLab que afecta a todas las versiones desde 16.2 anteriores a 16.2.8, todas las versiones desde 16.3 anteriores a 16.3.5, todas las versiones desde 16.4 anteriores a 16.4.1. Era posible leer el código fuente de un proyecto a través de un fork creado antes de cambiar la visibilidad solo a los miembros del proyecto."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.2","lessThan":"16.2.8","versionType":"semver","status":"affected"},{"version":"16.3","lessThan":"16.3.5","versionType":"semver","status":"affected"},{"version":"16.4","lessThan":"16.4.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-08-30T14:27:04.414291Z","id":"CVE-2023-3413","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-201"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.2","versionEndExcluding":"16.2.8","matchCriteriaId":"168E0D83-64EF-4A48-8251-6AE3BDF006D8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.2","versionEndExcluding":"16.2.8","matchCriteriaId":"8215D0EC-C0BF-417C-8D70-7F1493A82BB1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.3.0","versionEndExcluding":"16.3.5","matchCriteriaId":"50271B2B-7070-4ED0-AB68-65B99D44A68A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.3.0","versionEndExcluding":"16.3.5","matchCriteriaId":"CC5696C9-592A-4D50-B5BB-9A250DAB6589"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.4.0:*:*:*:community:*:*:*","matchCriteriaId":"B5D4FDD1-7A68-4245-A4D5-842E4FD03FAE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.4.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"6696C987-61C1-462E-8A73-016F9902BC67"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/416284","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2027967","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/416284","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2027967","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-5207","sourceIdentifier":"cve@gitlab.com","published":"2023-09-30T09:15:14.933","lastModified":"2026-06-17T06:48:05.540","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability was discovered in GitLab CE and EE affecting all versions starting 16.0 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. An authenticated attacker could perform arbitrary pipeline execution under the context of another user."},{"lang":"es","value":"Se descubrió una vulnerabilidad en GitLab CE y EE que afecta a todas las versiones desde 16.0 anteriores a 16.2.8, 16.3 anteriores a 16.3.5 y 16.4 anteriores a 16.4.1. Un atacante autenticado podría realizar una ejecución del pipeline arbitrario en el contexto de otro usuario."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.4","lessThan":"16.4.1","versionType":"semver","status":"affected"},{"version":"16.3","lessThan":"16.3.5","versionType":"semver","status":"affected"},{"version":"16.0.0","lessThan":"16.2.8","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N","baseScore":8.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.8,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-24T18:29:24.441970Z","id":"CVE-2023-5207","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-250"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"16.2.8","matchCriteriaId":"F6BEB145-6709-4993-837A-2B34438CFEA5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"16.2.8","matchCriteriaId":"69D101D1-BBDD-4EC6-9891-4684D3FB8F26"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.3.0","versionEndExcluding":"16.3.5","matchCriteriaId":"50271B2B-7070-4ED0-AB68-65B99D44A68A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.3.0","versionEndExcluding":"16.3.5","matchCriteriaId":"CC5696C9-592A-4D50-B5BB-9A250DAB6589"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.4.0:*:*:*:community:*:*:*","matchCriteriaId":"B5D4FDD1-7A68-4245-A4D5-842E4FD03FAE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.4.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"6696C987-61C1-462E-8A73-016F9902BC67"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/425604","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/425857","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2174141","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/425604","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/425857","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2174141","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-5106","sourceIdentifier":"cve@gitlab.com","published":"2023-10-02T12:15:09.997","lastModified":"2026-06-17T06:47:32.770","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in Ultimate-licensed GitLab EE affecting all versions starting 13.12 prior to 16.2.8, 16.3.0 prior to 16.3.5, and 16.4.0 prior to 16.4.1 that could allow an attacker to impersonate users in CI pipelines through direct transfer group imports."},{"lang":"es","value":"Se ha descubierto un problema en Ultimate-licensed GitLab EE que afecta a todas las versiones desde 13.12 anteriores a 16.2.8, 16.3.0 anteriores a 16.3.5 y 16.4.0 anteriores a 16.4.1 y que podría permitir a un atacante hacerse pasar por usuarios en CI pipelines mediante importaciones de grupos de transferencia directa."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"13.12","lessThan":"16.2.8","versionType":"semver","status":"affected"},{"version":"16.3.0","lessThan":"16.3.5","versionType":"semver","status":"affected"},{"version":"16.4.0","lessThan":"16.4.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N","baseScore":8.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.8,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-08-30T15:13:29.457533Z","id":"CVE-2023-5106","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.12","versionEndExcluding":"16.2.8","matchCriteriaId":"3A19F87C-BD40-4995-BCF4-9D3C324FDA93"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.3.0","versionEndExcluding":"16.3.5","matchCriteriaId":"CC5696C9-592A-4D50-B5BB-9A250DAB6589"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.4.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"6696C987-61C1-462E-8A73-016F9902BC67"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/commit/67039cfcae80b8fc0496f79be88714873cd169b3","source":"cve@gitlab.com","tags":["Patch"]},{"url":"https://gitlab.com/gitlab-org/security/gitlab/-/issues/980","source":"cve@gitlab.com"},{"url":"https://gitlab.com/gitlab-org/gitlab/-/commit/67039cfcae80b8fc0496f79be88714873cd169b3","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"]}]}},{"cve":{"id":"CVE-2023-5825","sourceIdentifier":"cve@gitlab.com","published":"2023-11-06T11:15:09.740","lastModified":"2026-06-17T06:49:26.963","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.2 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. A low-privileged attacker can point a CI/CD Component to an incorrect path and cause the server to exhaust all available memory through an infinite loop and cause Denial of Service."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde 16.2 anteriores a 16.3.6, todas las versiones desde 16.4 anteriores a 16.4.2, todas las versiones desde 16.5 anteriores a 16.5.1. Un atacante con pocos privilegios puede señalar un Componente CI/CD a una ruta incorrecta y hacer que el servidor agote toda la memoria disponible a través de un bucle infinito y provocar una Denegación de Servicio."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.2","lessThan":"16.3.6","versionType":"semver","status":"affected"},{"version":"16.4","lessThan":"16.4.2","versionType":"semver","status":"affected"},{"version":"16.5","lessThan":"16.5.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-24T13:51:52.958241Z","id":"CVE-2023-5825","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-835"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-835"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.2.0","versionEndExcluding":"16.3.6","matchCriteriaId":"11237024-8EE5-45AF-9911-3A57E6B8592F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.2.0","versionEndExcluding":"16.3.6","matchCriteriaId":"4F00F14B-EBED-4FBA-9F07-D927DA6D734F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.4.0","versionEndExcluding":"16.4.2","matchCriteriaId":"92775555-546E-4760-BD66-94E15B33DC8A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.4.0","versionEndExcluding":"16.4.2","matchCriteriaId":"F67E4E44-65EA-494F-B1FA-D080F53329AD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.5.0:*:*:*:community:*:*:*","matchCriteriaId":"28AC2266-BC77-48CA-82CC-00E1D3825AD9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.5.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"A7286C51-077E-4093-9AF9-66CEE22915AA"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/428984","source":"cve@gitlab.com","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/2218566","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/428984","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/2218566","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-5831","sourceIdentifier":"cve@gitlab.com","published":"2023-11-06T11:15:09.810","lastModified":"2026-06-17T06:49:27.770","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.0 before 16.3.6, all versions starting from 16.4 before 16.4.2, and all versions starting from 16.5.0 before 16.5.1 which have the `super_sidebar_logged_out` feature flag enabled. Affected versions with this default-disabled feature flag enabled may unintentionally disclose GitLab version metadata to unauthorized actors."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde 16.0 anteriores a 16.3.6, todas las versiones desde 16.4 anteriores a 16.4.2 y todas las versiones desde 16.5.0 anteriores a 16.5.1 que tienen la función `super_sidebar_logged_out` bandera habilitada. Las versiones afectadas con este indicador de función deshabilitado de forma predeterminada habilitado pueden revelar involuntariamente metadatos de la versión de GitLab a actores no autorizados."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.0","lessThan":"16.3.6","versionType":"semver","status":"affected"},{"version":"16.4","lessThan":"16.4.2","versionType":"semver","status":"affected"},{"version":"16.5","lessThan":"16.5.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":3.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-08-29T20:48:15.446663Z","id":"CVE-2023-5831","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-201"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"16.3.6","matchCriteriaId":"1F24E5BC-D85F-406D-8D60-F9D0A4AADF46"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"16.3.6","matchCriteriaId":"D460B5B4-689D-46C2-ADCE-EB1220EAC0D1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.4.0","versionEndExcluding":"16.4.2","matchCriteriaId":"92775555-546E-4760-BD66-94E15B33DC8A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.4.0","versionEndExcluding":"16.4.2","matchCriteriaId":"F67E4E44-65EA-494F-B1FA-D080F53329AD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.5.0:*:*:*:community:*:*:*","matchCriteriaId":"28AC2266-BC77-48CA-82CC-00E1D3825AD9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.5.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"A7286C51-077E-4093-9AF9-66CEE22915AA"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/428919","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/428919","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2023-3246","sourceIdentifier":"cve@gitlab.com","published":"2023-11-06T13:15:09.397","lastModified":"2026-06-17T06:13:40.077","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE/CE affecting all versions starting before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1 which allows an attackers to block Sidekiq job processor."},{"lang":"es","value":"Se ha descubierto un problema en GitLab EE/CE que afecta a todas las versiones anteriores a 16.3.6, todas las versiones desde 16.4 anteriores a 16.4.2, todas las versiones desde 16.5 anteriores a 16.5.1, lo que permite a los atacantes bloquear el procesador de trabajos Sidekiq."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"10.3","lessThan":"16.3.6","versionType":"semver","status":"affected"},{"version":"16.4.0","lessThan":"16.4.2","versionType":"semver","status":"affected"},{"version":"16.5.0","lessThan":"16.5.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-24T13:25:13.356774Z","id":"CVE-2023-3246","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"16.3.6","matchCriteriaId":"0626B056-CD25-4415-8810-88A44E63EE41"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"16.3.6","matchCriteriaId":"D9031D50-9DF6-407B-B3C1-2B659D981A72"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.4.0","versionEndExcluding":"16.4.2","matchCriteriaId":"92775555-546E-4760-BD66-94E15B33DC8A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.4.0","versionEndExcluding":"16.4.2","matchCriteriaId":"F67E4E44-65EA-494F-B1FA-D080F53329AD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.5.0:*:*:*:community:*:*:*","matchCriteriaId":"28AC2266-BC77-48CA-82CC-00E1D3825AD9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.5.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"A7286C51-077E-4093-9AF9-66CEE22915AA"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/415371","source":"cve@gitlab.com","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/2014157","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/415371","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/2014157","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-3399","sourceIdentifier":"cve@gitlab.com","published":"2023-11-06T13:15:09.503","lastModified":"2026-06-17T06:14:00.050","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions starting from 11.6 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. It was possible for an unauthorised project or group member to read the CI/CD variables using the custom project templates."},{"lang":"es","value":"Se descubrió un problema en GitLab EE que afecta a todas las versiones desde 11.6 anteriores a 16.3.6, todas las versiones desde 16.4 anteriores a 16.4.2, todas las versiones desde 16.5 anteriores a 16.5.1. Era posible que un proyecto o miembro de grupo no autorizado leyera las variables CI/CD utilizando las plantillas de proyecto personalizadas."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"11.6","lessThan":"16.3.6","versionType":"semver","status":"affected"},{"version":"16.4","lessThan":"16.4.2","versionType":"semver","status":"affected"},{"version":"16.5","lessThan":"16.5.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N","baseScore":8.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":4.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","baseScore":7.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":4.0}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-24T13:40:19.625133Z","id":"CVE-2023-3399","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-201"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"12.9.8","matchCriteriaId":"3BA56397-C9B1-4CE4-8FB7-CAB1DD973E02"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"12.9.8","matchCriteriaId":"9878DD67-6675-4E1A-A309-A3473D2D0BED"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.10.0","versionEndExcluding":"12.10.7","matchCriteriaId":"C9ED9593-9837-4849-A890-C2FDDC56C5A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.10.0","versionEndExcluding":"12.10.7","matchCriteriaId":"846CD4C7-BFCB-4DFC-901E-46CCA8ADA56A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:13.0.0:*:*:*:community:*:*:*","matchCriteriaId":"439E1C57-8846-4EB8-A78A-DE6BDAF6CAF5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:13.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"F6CA871C-BEFF-4951-AC88-ACA603C25CE1"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/416244","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2021616","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/416244","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2021616","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-3909","sourceIdentifier":"cve@gitlab.com","published":"2023-11-06T13:15:09.653","lastModified":"2026-06-17T06:15:18.740","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.3 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. A Regular Expression Denial of Service was possible by adding a large string in timeout input in gitlab-ci.yml file."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde 12.3 anteriores a 16.3.6, todas las versiones desde 16.4 anteriores a 16.4.2, todas las versiones desde 16.5 anteriores a 16.5.1. Fue posible una Regular Expression Denial of Service agregando una cadena grande en la entrada de tiempo de espera en el archivo gitlab-ci.yml."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"12.3","lessThan":"16.3.6","versionType":"semver","status":"affected"},{"version":"16.4","lessThan":"16.4.2","versionType":"semver","status":"affected"},{"version":"16.5","lessThan":"16.5.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-24T13:29:29.851628Z","id":"CVE-2023-3909","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1333"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-1333"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.3.0","versionEndExcluding":"16.3.6","matchCriteriaId":"C306683A-74F6-435B-B374-5277E0F471A7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.3.0","versionEndExcluding":"16.3.6","matchCriteriaId":"1F14AD03-5C49-4D52-85C6-E726A3909152"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.4.0","versionEndExcluding":"16.4.2","matchCriteriaId":"92775555-546E-4760-BD66-94E15B33DC8A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.4.0","versionEndExcluding":"16.4.2","matchCriteriaId":"F67E4E44-65EA-494F-B1FA-D080F53329AD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.5.0:*:*:*:community:*:*:*","matchCriteriaId":"28AC2266-BC77-48CA-82CC-00E1D3825AD9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.5.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"A7286C51-077E-4093-9AF9-66CEE22915AA"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/418763","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2050269","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/418763","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2050269","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-5963","sourceIdentifier":"cve@gitlab.com","published":"2023-11-06T13:15:10.110","lastModified":"2026-06-17T06:49:45.310","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE with Advanced Search affecting all versions from 13.9 to 16.3.6, 16.4 prior to 16.4.2 and 16.5 prior to 16.5.1 that could allow a denial of service in the Advanced Search function by chaining too many syntax operators."},{"lang":"es","value":"Se ha descubierto un problema en GitLab EE con Advanced Search que afecta a todas las versiones desde 13.9 a 16.3.6, 16.4 anterior a 16.4.2 y 16.5 anterior a 16.5.1 que podría permitir una denegación de servicio en la función de Advanced Search al encadenar demasiadas operadores de sintaxis."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"13.9","lessThan":"16.3.6","versionType":"semver","status":"affected"},{"version":"16.4.0","lessThan":"16.4.2","versionType":"semver","status":"affected"},{"version":"16.5.0","lessThan":"16.5.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":3.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":1.6,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-08-29T20:45:18.819304Z","id":"CVE-2023-5963","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.9.0","versionEndIncluding":"16.3.6","matchCriteriaId":"8DB025EB-A6AD-4E36-89A1-6410F3C4D306"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.4.0","versionEndExcluding":"16.4.2","matchCriteriaId":"F67E4E44-65EA-494F-B1FA-D080F53329AD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.5.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"A7286C51-077E-4093-9AF9-66CEE22915AA"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/423468","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/423468","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2023-4700","sourceIdentifier":"cve@gitlab.com","published":"2023-11-06T18:15:08.730","lastModified":"2026-06-17T06:38:24.633","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An authorization issue affecting GitLab EE affecting all versions from 14.7 prior to 16.3.6, 16.4 prior to 16.4.2, and 16.5 prior to 16.5.1, allowed a user to run jobs in protected environments, bypassing any required approvals."},{"lang":"es","value":"Un problema de autorización que afectaba a GitLab EE y afectaba a todas las versiones desde 14.7 anterior a 16.3.6, 16.4 anterior a 16.4.2 y 16.5 anterior a 16.5.1, permitía a un usuario ejecutar trabajos en entornos protegidos, sin pasar por las aprobaciones requeridas."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"14.7","lessThan":"16.3.6","versionType":"semver","status":"affected"},{"version":"16.4.0","lessThan":"16.4.2","versionType":"semver","status":"affected"},{"version":"16.5.0","lessThan":"16.5.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N","baseScore":3.5,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-24T14:01:29.263850Z","id":"CVE-2023-4700","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.7.0","versionEndExcluding":"16.3.6","matchCriteriaId":"33EC121E-A987-4A2C-9E09-C875620BA4B5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.4.0","versionEndExcluding":"16.4.2","matchCriteriaId":"F67E4E44-65EA-494F-B1FA-D080F53329AD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.5.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"A7286C51-077E-4093-9AF9-66CEE22915AA"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/421937","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2129826","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/421937","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2129826","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-4379","sourceIdentifier":"cve@gitlab.com","published":"2023-11-09T21:15:24.930","lastModified":"2026-06-17T06:37:42.490","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions starting from 15.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. Code owner approval was not removed from merge requests when the target branch was updated."},{"lang":"es","value":"Se descubrió un problema en GitLab EE que afecta a todas las versiones desde la 15.3 anterior a la 16.2.8, la 16.3 anterior a la 16.3.5 y la 16.4 anterior a la 16.4.1. La aprobación del propietario del código no se eliminó de las solicitudes de fusión cuando se actualizó la rama de destino."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.3","lessThan":"16.2.8","versionType":"semver","status":"affected"},{"version":"16.3","lessThan":"16.3.5","versionType":"semver","status":"affected"},{"version":"16.4","lessThan":"16.4.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.7,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-08-30T15:30:35.330645Z","id":"CVE-2023-4379","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.3.0","versionEndExcluding":"16.2.8","matchCriteriaId":"863E98A5-7F1C-4CFA-A209-19E66F04A718"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.3.0","versionEndExcluding":"16.3.5","matchCriteriaId":"CC5696C9-592A-4D50-B5BB-9A250DAB6589"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.4.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"6696C987-61C1-462E-8A73-016F9902BC67"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/415496","source":"cve@gitlab.com","tags":["Issue Tracking"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/415496","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking"]}]}},{"cve":{"id":"CVE-2023-3443","sourceIdentifier":"cve@gitlab.com","published":"2023-12-01T07:15:07.600","lastModified":"2026-06-17T06:14:05.040","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 12.1 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for a Guest user to add an emoji on confidential work items."},{"lang":"es","value":"Se ha descubierto un problema en GitLab que afecta a todas las versiones desde 12.1 anteriores a 16.4.3, todas las versiones desde 16.5 anteriores a 16.5.3, todas las versiones desde 16.6 anteriores a 16.6.1. Un usuario invitado podía agregar un emoji en elementos de trabajo confidenciales."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"12.1","lessThan":"16.4.3","versionType":"semver","status":"affected"},{"version":"16.5","lessThan":"16.5.3","versionType":"semver","status":"affected"},{"version":"16.6","lessThan":"16.6.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":3.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"16.4.3","matchCriteriaId":"5C01C1BA-42EF-451E-911B-9D8CBEBC711A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"16.4.3","matchCriteriaId":"AA7BF2A9-47BC-4F49-B706-C9CB817E405F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.5.0","versionEndExcluding":"16.5.3","matchCriteriaId":"B1AC7763-4EA9-4E9A-8711-FEEA9D111D68"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.5.0","versionEndExcluding":"16.5.3","matchCriteriaId":"6B77E904-2562-4F78-A787-7F51871054BA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.6.0:*:*:*:community:*:*:*","matchCriteriaId":"FAB408DE-FE19-4CD6-B026-44AF7AD36405"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.6.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"8D5674D6-E26B-4F62-9B59-C15DEEDDB4B1"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/416497","source":"cve@gitlab.com","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/2036500","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/416497","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/2036500","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2023-3949","sourceIdentifier":"cve@gitlab.com","published":"2023-12-01T07:15:08.973","lastModified":"2026-06-17T06:15:26.307","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 11.3 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for unauthorized users to view a public projects' release descriptions via an atom endpoint when release access on the public was set to only project members."},{"lang":"es","value":"Se ha descubierto un problema en GitLab que afecta a todas las versiones desde 11.3 anteriores a 16.4.3, todas las versiones desde 16.5 anteriores a 16.5.3, todas las versiones desde 16.6 anteriores a 16.6.1. Era posible que usuarios no autorizados vieran las descripciones de la versión de un proyecto público a través de un endpoint Atom cuando el acceso a la versión pública estaba configurado solo para los miembros del proyecto."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"11.3","lessThan":"16.4.3","versionType":"semver","status":"affected"},{"version":"16.5","lessThan":"16.5.3","versionType":"semver","status":"affected"},{"version":"16.6","lessThan":"16.6.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-01-10T16:38:37.303405Z","id":"CVE-2023-3949","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-201"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"16.4.3","matchCriteriaId":"EAC69A79-4900-45F1-A299-E449ED2D0057"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"16.4.3","matchCriteriaId":"79FABBE9-AC1C-46A9-8337-C2352E29B3C3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.5.0","versionEndExcluding":"16.5.3","matchCriteriaId":"B1AC7763-4EA9-4E9A-8711-FEEA9D111D68"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.5.0","versionEndExcluding":"16.5.3","matchCriteriaId":"6B77E904-2562-4F78-A787-7F51871054BA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.6.0:*:*:*:community:*:*:*","matchCriteriaId":"FAB408DE-FE19-4CD6-B026-44AF7AD36405"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.6.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"8D5674D6-E26B-4F62-9B59-C15DEEDDB4B1"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/419664","source":"cve@gitlab.com","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/2079374","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/419664","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/2079374","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2023-3964","sourceIdentifier":"cve@gitlab.com","published":"2023-12-01T07:15:09.620","lastModified":"2026-06-17T06:15:30.280","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 13.2 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for users to access composer packages on public projects that have package registry disabled in the project settings."},{"lang":"es","value":"Se ha descubierto un problema en GitLab que afecta a todas las versiones desde 13.2 anteriores a 16.4.3, todas las versiones desde 16.5 anteriores a 16.5.3, todas las versiones desde 16.6 anteriores a 16.6.1. Los usuarios podían acceder a paquetes de compositor en proyectos públicos que tenían el registro de paquetes deshabilitado en la configuración del proyecto."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"13.2","lessThan":"16.4.3","versionType":"semver","status":"affected"},{"version":"16.5","lessThan":"16.5.3","versionType":"semver","status":"affected"},{"version":"16.6","lessThan":"16.6.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-06-03T02:22:14.694015Z","id":"CVE-2023-3964","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"16.4.3","matchCriteriaId":"21810033-2473-41F9-9001-CCCE1DB23783"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"16.4.3","matchCriteriaId":"EEC3E75B-194E-400C-8985-F50F144D1DDE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.5.0","versionEndExcluding":"16.5.3","matchCriteriaId":"B1AC7763-4EA9-4E9A-8711-FEEA9D111D68"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.5.0","versionEndExcluding":"16.5.3","matchCriteriaId":"6B77E904-2562-4F78-A787-7F51871054BA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.6.0:*:*:*:community:*:*:*","matchCriteriaId":"FAB408DE-FE19-4CD6-B026-44AF7AD36405"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.6.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"8D5674D6-E26B-4F62-9B59-C15DEEDDB4B1"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/419857","source":"cve@gitlab.com","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/2037316","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/419857","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/2037316","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2023-4317","sourceIdentifier":"cve@gitlab.com","published":"2023-12-01T07:15:10.197","lastModified":"2026-06-17T06:37:33.583","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 9.2 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for a user with the Developer role to update a pipeline schedule from an unprotected branch to a protected branch."},{"lang":"es","value":"Se ha descubierto un problema en GitLab que afecta a todas las versiones desde 9.2 anteriores a 16.4.3, todas las versiones desde 16.5 anteriores a 16.5.3, todas las versiones desde 16.6 anteriores a 16.6.1. Un usuario con el rol de Desarrollador podía actualizar una programación de canalización desde una rama desprotegida a una rama protegida."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"9.2","lessThan":"16.4.3","versionType":"semver","status":"affected"},{"version":"16.5","lessThan":"16.5.3","versionType":"semver","status":"affected"},{"version":"16.6","lessThan":"16.6.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"9.2.0","versionEndExcluding":"16.4.3","matchCriteriaId":"8CA7AD90-9FD3-42C2-B080-16E710EC77A5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"9.2.0","versionEndExcluding":"16.4.3","matchCriteriaId":"15FC7658-7A3E-4B65-93A9-0CAABC1F339E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.5.0","versionEndExcluding":"16.5.3","matchCriteriaId":"B1AC7763-4EA9-4E9A-8711-FEEA9D111D68"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.5.0","versionEndExcluding":"16.5.3","matchCriteriaId":"6B77E904-2562-4F78-A787-7F51871054BA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.6.0:*:*:*:community:*:*:*","matchCriteriaId":"FAB408DE-FE19-4CD6-B026-44AF7AD36405"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.6.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"8D5674D6-E26B-4F62-9B59-C15DEEDDB4B1"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/421846","source":"cve@gitlab.com","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/2089517","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/421846","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/2089517","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2023-4658","sourceIdentifier":"cve@gitlab.com","published":"2023-12-01T07:15:10.807","lastModified":"2026-06-17T06:38:18.697","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions starting from 8.13 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to abuse the `Allowed to merge` permission as a guest user, when granted the permission through a group."},{"lang":"es","value":"Se descubrió un problema en GitLab EE que afecta a todas las versiones desde 8.13 anteriores a 16.4.3, todas las versiones desde 16.5 anteriores a 16.5.3, todas las versiones desde 16.6 anteriores a 16.6.1. Era posible que un atacante abusara del permiso \"Permitido fusionar\" como usuario invitado, cuando se le concedía el permiso a través de un grupo."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"8.13","lessThan":"16.4.3","versionType":"semver","status":"affected"},{"version":"16.5","lessThan":"16.5.3","versionType":"semver","status":"affected"},{"version":"16.6","lessThan":"16.6.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":3.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":3.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":1.4}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.13.0","versionEndExcluding":"16.4.3","matchCriteriaId":"ED3112DB-4343-44FC-BF0C-91336099167C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.5.0","versionEndExcluding":"16.5.3","matchCriteriaId":"6B77E904-2562-4F78-A787-7F51871054BA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.6.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"8D5674D6-E26B-4F62-9B59-C15DEEDDB4B1"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/423835","source":"cve@gitlab.com","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/2104540","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/423835","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/2104540","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2023-4912","sourceIdentifier":"cve@gitlab.com","published":"2023-12-01T07:15:11.387","lastModified":"2026-06-17T06:38:53.093","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions starting from 10.5 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to cause a client-side denial of service using malicious crafted mermaid diagram input."},{"lang":"es","value":"Se descubrió un problema en GitLab EE que afecta a todas las versiones desde 10.5 anteriores a 16.4.3, todas las versiones desde 16.5 anteriores a 16.5.3, todas las versiones desde 16.6 anteriores a 16.6.1. Era posible que un atacante provocara una denegación de servicio en el lado del cliente utilizando una entrada de diagrama de sirena manipulada con fines maliciosos."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"10.5","lessThan":"16.4.3","versionType":"semver","status":"affected"},{"version":"16.5","lessThan":"16.5.3","versionType":"semver","status":"affected"},{"version":"16.6","lessThan":"16.6.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:L","baseScore":2.6,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":1.2,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.5.0","versionEndExcluding":"16.4.3","matchCriteriaId":"582A4F39-AFFB-4F2F-AEEE-DE4CFF955576"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.5.0","versionEndExcluding":"16.5.3","matchCriteriaId":"6B77E904-2562-4F78-A787-7F51871054BA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.6.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"8D5674D6-E26B-4F62-9B59-C15DEEDDB4B1"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/424882","source":"cve@gitlab.com","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/2137421","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/424882","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/2137421","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2023-5226","sourceIdentifier":"cve@gitlab.com","published":"2023-12-01T07:15:12.003","lastModified":"2026-06-17T06:48:07.420","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. Under certain circumstances, a malicious actor bypass prohibited branch checks using a specially crafted branch name to manipulate repository content in the UI."},{"lang":"es","value":"Se ha descubierto un problema en GitLab que afecta a todas las versiones anteriores a 16.4.3, todas las versiones a partir de 16.5 anteriores a 16.5.3, todas las versiones a partir de 16.6 anteriores a 16.6.1. En determinadas circunstancias, un actor malintencionado elude las comprobaciones de sucursales prohibidas utilizando un nombre de sucursal especialmente manipulado para manipular el contenido del repositorio en la interfaz de usuario."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"0","lessThan":"16.4.3","versionType":"semver","status":"affected"},{"version":"16.5","lessThan":"16.5.3","versionType":"semver","status":"affected"},{"version":"16.6","lessThan":"16.6.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N","baseScore":4.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-94"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"16.4.3","matchCriteriaId":"7269551A-80EB-4E8B-8022-0B66994C7601"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"16.4.3","matchCriteriaId":"B9CF956D-DF30-47A7-8710-262AC4C76F2E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.5.0","versionEndExcluding":"16.5.3","matchCriteriaId":"B1AC7763-4EA9-4E9A-8711-FEEA9D111D68"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.5.0","versionEndExcluding":"16.5.3","matchCriteriaId":"6B77E904-2562-4F78-A787-7F51871054BA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.6.0:*:*:*:community:*:*:*","matchCriteriaId":"FAB408DE-FE19-4CD6-B026-44AF7AD36405"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.6.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"8D5674D6-E26B-4F62-9B59-C15DEEDDB4B1"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/426400","source":"cve@gitlab.com","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/2173053","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/426400","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/2173053","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2023-5995","sourceIdentifier":"cve@gitlab.com","published":"2023-12-01T07:15:13.033","lastModified":"2026-06-17T06:49:49.193","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions starting from 16.2 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to abuse the policy bot to gain access to internal projects."},{"lang":"es","value":"Se ha descubierto un problema en GitLab EE que afecta a todas las versiones desde 16.2 anteriores a 16.4.3, todas las versiones desde 16.5 anteriores a 16.5.3, todas las versiones desde 16.6 anteriores a 16.6.1. Era posible que un atacante abusara del robot de políticas para obtener acceso a proyectos internos."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.2","lessThan":"16.4.3","versionType":"semver","status":"affected"},{"version":"16.5","lessThan":"16.5.3","versionType":"semver","status":"affected"},{"version":"16.6","lessThan":"16.6.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N","baseScore":4.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":0.7,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.2.0","versionEndExcluding":"16.4.3","matchCriteriaId":"2F963AF1-CC28-43B9-A5F2-1F1722B87D04"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.5.0","versionEndExcluding":"16.5.3","matchCriteriaId":"6B77E904-2562-4F78-A787-7F51871054BA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.6.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"8D5674D6-E26B-4F62-9B59-C15DEEDDB4B1"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/425361","source":"cve@gitlab.com","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/2138880","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/425361","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/2138880","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2023-6033","sourceIdentifier":"cve@gitlab.com","published":"2023-12-01T07:15:13.633","lastModified":"2026-06-17T06:49:53.150","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Improper neutralization of input in Jira integration configuration in GitLab CE/EE, affecting all versions from 15.10 prior to 16.6.1, 16.5 prior to 16.5.3, and 16.4 prior to 16.4.3 allows attacker to execute javascript in victim's browser."},{"lang":"es","value":"La neutralización inadecuada de la entrada en la configuración de integración de Jira en GitLab CE/EE, que afecta a todas las versiones desde 15.10 anteriores a 16.6.1, 16.5 anteriores a 16.5.3 y 16.4 anteriores a 16.4.3, permite al atacante ejecutar javascript en el navegador de la víctima."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.10","lessThan":"16.4.3","versionType":"semver","status":"affected"},{"version":"16.5","lessThan":"16.5.3","versionType":"semver","status":"affected"},{"version":"16.6","lessThan":"16.6.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-12-02T17:52:16.452046Z","id":"CVE-2023-6033","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.10","versionEndExcluding":"16.6.1","matchCriteriaId":"D7E9318B-8CA3-49D0-9359-4DB5CE76491F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.10","versionEndExcluding":"16.6.1","matchCriteriaId":"54546976-4D6A-40EC-B080-5C2CF88B14AA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.4.0","versionEndExcluding":"16.4.3","matchCriteriaId":"E74DD7CD-128A-4584-9A20-0206F3275766"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.4.0","versionEndExcluding":"16.4.3","matchCriteriaId":"9403AA96-9680-4679-9C30-139C05FD328E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.5.0","versionEndExcluding":"16.5.3","matchCriteriaId":"B1AC7763-4EA9-4E9A-8711-FEEA9D111D68"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.5.0","versionEndExcluding":"16.5.3","matchCriteriaId":"6B77E904-2562-4F78-A787-7F51871054BA"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/431201","source":"cve@gitlab.com","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/2236039","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/431201","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]},{"url":"https://hackerone.com/reports/2236039","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2023-5332","sourceIdentifier":"cve@gitlab.com","published":"2023-12-04T07:15:07.120","lastModified":"2026-06-17T06:48:21.767","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Patch in third party library Consul requires 'enable-script-checks' to be set to False. This was required to enable a patch by the vendor. Without this setting the patch could be bypassed. This only affects GitLab-EE."},{"lang":"es","value":"El parche en la librería de terceros Consul requiere que 'enable-script-checks' esté configurado en False. Esto fue necesario para habilitar un parche por parte del proveedor. Sin esta configuración, se podría omitir el parche. Esto sólo afecta a GitLab-EE."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"9.5.0","lessThan":"16.2.8","versionType":"semver","status":"affected"},{"version":"16.3.0","lessThan":"16.3.5","versionType":"semver","status":"affected"},{"version":"16.4","lessThan":"16.4.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":0.7,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.2,"impactScore":5.9}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"9.5.0","versionEndExcluding":"16.2.8","matchCriteriaId":"D2A9F08F-3E67-4BAF-98E5-C211E320BD55"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.3.0","versionEndExcluding":"16.3.5","matchCriteriaId":"CC5696C9-592A-4D50-B5BB-9A250DAB6589"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.4.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"6696C987-61C1-462E-8A73-016F9902BC67"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:hashicorp:consul:*:*:*:*:-:*:*:*","versionEndExcluding":"0.9.4","matchCriteriaId":"59CB68FA-DFE8-4C80-8FB4-A6E86FF4DE19"},{"vulnerable":true,"criteria":"cpe:2.3:a:hashicorp:consul:*:*:*:*:-:*:*:*","versionStartIncluding":"1.0.0","versionEndExcluding":"1.0.8","matchCriteriaId":"58A2918F-9880-4605-8DC2-090513DE6337"},{"vulnerable":true,"criteria":"cpe:2.3:a:hashicorp:consul:*:*:*:*:-:*:*:*","versionStartIncluding":"1.2.0","versionEndExcluding":"1.2.4","matchCriteriaId":"951274EA-0268-4AC9-9561-F47045BE21AE"},{"vulnerable":true,"criteria":"cpe:2.3:a:hashicorp:consul:1.1.0:*:*:*:-:*:*:*","matchCriteriaId":"8D61FF58-9664-400A-9E78-B20132C5E5CF"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/omnibus-gitlab/-/issues/8171","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]},{"url":"https://www.hashicorp.com/blog/protecting-consul-from-rce-risk-in-specific-configurations","source":"cve@gitlab.com","tags":["Patch","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/omnibus-gitlab/-/issues/8171","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking"]},{"url":"https://www.hashicorp.com/blog/protecting-consul-from-rce-risk-in-specific-configurations","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2023-3511","sourceIdentifier":"cve@gitlab.com","published":"2023-12-15T16:15:43.053","lastModified":"2026-06-17T06:14:14.910","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions starting from 8.17 before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. It was possible for auditor users to fork and submit merge requests to private projects they're not a member of."},{"lang":"es","value":"Se descubrió un problema en GitLab EE que afecta a todas las versiones desde 8.17 anteriores a 16.4.4, todas las versiones desde 16.5 anteriores a 16.5.4, todas las versiones desde 16.6 anteriores a 16.6.2. Los usuarios auditores pudieron bifurcar y enviar solicitudes de fusión a proyectos privados de los que no son miembros."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"8.17","lessThan":"16.4.4","versionType":"semver","status":"affected"},{"version":"16.5","lessThan":"16.5.4","versionType":"semver","status":"affected"},{"version":"16.6","lessThan":"16.6.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:N","baseScore":2.0,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":0.5,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N","baseScore":3.5,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":1.4}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.17","versionEndExcluding":"16.4.4","matchCriteriaId":"FF46E870-A12D-45CF-9265-63BEC4068D7D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.5","versionEndExcluding":"16.5.4","matchCriteriaId":"B9D88266-872E-4BD9-B3DF-D1C540E66AFD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.6","versionEndExcluding":"16.6.2","matchCriteriaId":"D5C45787-C8C9-432E-8DAF-6F5264BBE0B3"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/416961","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2046752","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/416961","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2046752","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-3904","sourceIdentifier":"cve@gitlab.com","published":"2023-12-15T16:15:43.387","lastModified":"2026-06-17T06:15:17.870","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions starting before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. It was possible to overflow the time spent on an issue that altered the details shown in the issue boards."},{"lang":"es","value":"Se ha descubierto un problema en GitLab EE que afecta a todas las versiones anteriores a 16.4.4, todas las versiones anteriores a 16.5 anteriores a 16.5.4, todas las versiones anteriores a 16.6 anteriores a 16.6.2. Ha sido posble hacer un desbordamiento del tiempo dedicado a un issue que alteró los detalles mostrados en los tableros de issues."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"0","lessThanOrEqual":"16.4.3","versionType":"semver","status":"affected"},{"version":"16.5","lessThan":"16.5.4","versionType":"semver","status":"affected"},{"version":"16.6","lessThan":"16.6.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1287"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"16.4.4","matchCriteriaId":"8C804A75-C14D-4AD1-8347-3F85B8889C5C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.5","versionEndExcluding":"16.5.4","matchCriteriaId":"B9D88266-872E-4BD9-B3DF-D1C540E66AFD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.6","versionEndExcluding":"16.6.2","matchCriteriaId":"D5C45787-C8C9-432E-8DAF-6F5264BBE0B3"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/418226","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2053154","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/418226","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2053154","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-5061","sourceIdentifier":"cve@gitlab.com","published":"2023-12-15T16:15:45.930","lastModified":"2026-06-17T06:47:27.817","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 9.3 before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. In certain situations, it may have been possible for developers to override predefined CI variables via the REST API."},{"lang":"es","value":"Se ha descubierto un problema en GitLab que afecta a todas las versiones desde 9.3 anteriores a 16.4.4, todas las versiones desde 16.5 anteriores a 16.5.4, todas las versiones desde 16.6 anteriores a 16.6.2. En determinadas situaciones, es posible que los desarrolladores hayan podido anular las variables de CI predefinidas a través de la API REST."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"9.3","lessThan":"16.4.4","versionType":"semver","status":"affected"},{"version":"16.5","lessThan":"16.5.4","versionType":"semver","status":"affected"},{"version":"16.6","lessThan":"16.6.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-08-28T13:18:08.740254Z","id":"CVE-2023-5061","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"9.3.0","versionEndExcluding":"16.4.4","matchCriteriaId":"6343DEF7-EABF-4327-B171-DB8A8F2E46F6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"9.3.0","versionEndExcluding":"16.4.4","matchCriteriaId":"27D94FEC-A537-428F-AEE2-B4E35F6BAADB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.5.0","versionEndExcluding":"16.5.4","matchCriteriaId":"3C213E8A-B47E-4D1F-8253-90CB866744F0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.5.0","versionEndExcluding":"16.5.4","matchCriteriaId":"E6EBFF85-99EE-48D7-8991-02AA59E78374"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.6.0","versionEndExcluding":"16.6.2","matchCriteriaId":"17596227-79F6-439A-89EC-B87F03EF73AC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.6.0","versionEndExcluding":"16.6.2","matchCriteriaId":"53E94AC5-C346-4511-B68C-DC0D86E575FC"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/425521","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2125189","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/425521","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2125189","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-5512","sourceIdentifier":"cve@gitlab.com","published":"2023-12-15T16:15:46.300","lastModified":"2026-06-17T06:48:44.563","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 16.3 before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. File integrity may be compromised when specific HTML encoding is used for file names leading for incorrect representation in the UI."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde 16.3 anteriores a 16.4.4, todas las versiones desde 16.5 anteriores a 16.5.4, todas las versiones desde 16.6 anteriores a 16.6.2. La integridad del archivo puede verse comprometida cuando se utiliza una codificación HTML específica para nombres de archivos que provocan una representación incorrecta en la interfaz de usuario."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.3","lessThan":"16.4.4","versionType":"semver","status":"affected"},{"version":"16.5","lessThan":"16.5.4","versionType":"semver","status":"affected"},{"version":"16.6","lessThan":"16.6.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N","baseScore":4.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N","baseScore":5.7,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":3.6}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-94"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-94"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.3.0","versionEndExcluding":"16.4.4","matchCriteriaId":"FC12E182-B115-419E-B2DF-AC30E3EF5F10"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.3.0","versionEndExcluding":"16.4.4","matchCriteriaId":"E4A325F9-7186-4061-B299-106849B7A5DA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.5.0","versionEndExcluding":"16.5.4","matchCriteriaId":"3C213E8A-B47E-4D1F-8253-90CB866744F0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.5.0","versionEndExcluding":"16.5.4","matchCriteriaId":"E6EBFF85-99EE-48D7-8991-02AA59E78374"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.6.0","versionEndExcluding":"16.6.2","matchCriteriaId":"17596227-79F6-439A-89EC-B87F03EF73AC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.6.0","versionEndExcluding":"16.6.2","matchCriteriaId":"53E94AC5-C346-4511-B68C-DC0D86E575FC"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/427827","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2194607","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/427827","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2194607","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-6051","sourceIdentifier":"cve@gitlab.com","published":"2023-12-15T16:15:46.490","lastModified":"2026-06-17T06:49:56.893","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. File integrity may be compromised when source code or installation packages are pulled from a specific tag."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones anteriores a 16.4.4, todas las versiones desde 15.5 anteriores a 16.5.4, todas las versiones desde 16.6 anteriores a 16.6.2. La integridad del archivo puede verse comprometida cuando el código fuente o los paquetes de instalación se extraen de una etiqueta específica."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"0","lessThan":"16.4.4","versionType":"semver","status":"affected"},{"version":"16.5","lessThan":"16.5.4","versionType":"semver","status":"affected"},{"version":"16.6","lessThan":"16.6.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N","baseScore":5.7,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-94"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-94"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"16.4.4","matchCriteriaId":"7A118925-6ADE-455D-BACF-62FF89F2460D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"16.4.4","matchCriteriaId":"8C804A75-C14D-4AD1-8347-3F85B8889C5C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.5.0","versionEndExcluding":"16.5.4","matchCriteriaId":"3C213E8A-B47E-4D1F-8253-90CB866744F0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.5.0","versionEndExcluding":"16.5.4","matchCriteriaId":"E6EBFF85-99EE-48D7-8991-02AA59E78374"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.6.0","versionEndExcluding":"16.6.2","matchCriteriaId":"17596227-79F6-439A-89EC-B87F03EF73AC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.6.0","versionEndExcluding":"16.6.2","matchCriteriaId":"53E94AC5-C346-4511-B68C-DC0D86E575FC"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/431345","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2237165","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/431345","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2237165","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-6680","sourceIdentifier":"cve@gitlab.com","published":"2023-12-15T16:15:46.737","lastModified":"2026-06-17T06:51:13.837","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An improper certificate validation issue in Smartcard authentication in GitLab EE affecting all versions from 11.6 prior to 16.4.4, 16.5 prior to 16.5.4, and 16.6 prior to 16.6.2 allows an attacker to authenticate as another user given their public key if they use Smartcard authentication. Smartcard authentication is an experimental feature and has to be manually enabled by an administrator."},{"lang":"es","value":"Un problema de validación de certificado incorrecto en la autenticación de tarjeta inteligente en GitLab EE que afecta a todas las versiones desde 11.6 anterior a 16.4.4, 16.5 anterior a 16.5.4 y 16.6 anterior a 16.6.2 permite a un atacante autenticarse como otro usuario dada su clave pública si utilizar la autenticación con tarjeta inteligente. La autenticación con tarjeta inteligente es una función experimental y un administrador debe habilitarla manualmente."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"11.6","lessThan":"16.4.4","versionType":"semver","status":"affected"},{"version":"16.5","lessThan":"16.5.4","versionType":"semver","status":"affected"},{"version":"16.6","lessThan":"16.6.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","baseScore":7.4,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.2,"impactScore":5.9}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-295"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-295"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.6","versionEndExcluding":"16.4.4","matchCriteriaId":"289EDE8D-E3DC-4000-A0BD-71E7389F631F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.5","versionEndExcluding":"16.5.4","matchCriteriaId":"B9D88266-872E-4BD9-B3DF-D1C540E66AFD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.6","versionEndExcluding":"16.6.2","matchCriteriaId":"D5C45787-C8C9-432E-8DAF-6F5264BBE0B3"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/421607","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/421607","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2023-3907","sourceIdentifier":"cve@gitlab.com","published":"2023-12-17T23:15:43.937","lastModified":"2026-06-17T06:15:18.367","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A privilege escalation vulnerability in GitLab EE affecting all versions from 16.0 prior to 16.4.4, 16.5 prior to 16.5.4, and 16.6 prior to 16.6.2 allows a project Maintainer to use a Project Access Token to escalate their role to Owner"},{"lang":"es","value":"Una vulnerabilidad de escalada de privilegios en GitLab EE que afecta a todas las versiones desde 16.0 anterior a 16.4.4, 16.5 anterior a 16.5.4 y 16.6 anterior a 16.6.2 permite que un mantenedor de proyecto use un token de acceso al proyecto para escalar su rol a propietario."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.0","lessThan":"16.4.4","versionType":"semver","status":"affected"},{"version":"16.5","lessThan":"16.5.4","versionType":"semver","status":"affected"},{"version":"16.6","lessThan":"16.6.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-08-27T15:56:10.049753Z","id":"CVE-2023-3907","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-286"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"16.4.4","matchCriteriaId":"00377DD9-D454-4084-9D94-D48C8F1E11C5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.5","versionEndExcluding":"16.5.4","matchCriteriaId":"B9D88266-872E-4BD9-B3DF-D1C540E66AFD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.6","versionEndExcluding":"16.6.2","matchCriteriaId":"D5C45787-C8C9-432E-8DAF-6F5264BBE0B3"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/418878","source":"cve@gitlab.com","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/2058934","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/418878","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/2058934","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-2030","sourceIdentifier":"cve@gitlab.com","published":"2024-01-12T14:15:47.833","lastModified":"2026-06-17T05:51:14.013","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 12.2 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which an attacker could potentially modify the metadata of signed commits."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde 12.2 anterior a 16.5.6, 16.6 anterior a 16.6.4 y 16.7 anterior a 16.7.2 en el que un atacante podría modificar los metadatos de las confirmaciones firmadas."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"12.2","lessThan":"16.5.6","versionType":"semver","status":"affected"},{"version":"16.6","lessThan":"16.6.4","versionType":"semver","status":"affected"},{"version":"16.7","lessThan":"16.7.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N","baseScore":3.5,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-01-31T19:51:56.372943Z","id":"CVE-2023-2030","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-347"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-347"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"16.5.6","matchCriteriaId":"64C111BB-CD2F-42AE-AD4E-2DED5FF34907"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"16.5.6","matchCriteriaId":"C1FCE458-EACF-476C-B0F5-D31373E4457D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.6.0","versionEndExcluding":"16.6.4","matchCriteriaId":"7198B7E4-9928-4B7D-9D00-6B76CCAC3875"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.6.0","versionEndExcluding":"16.6.4","matchCriteriaId":"D294EA47-B2EF-42D6-A92B-93CEA5D209B7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.7.0:*:*:*:community:*:*:*","matchCriteriaId":"150F88EA-DA27-4042-9778-932904C2FD41"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.7.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"29C6355F-1CD3-4E4A-AACA-19B497A631D6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.7.1:*:*:*:community:*:*:*","matchCriteriaId":"D385A20C-BC93-4BB9-A47D-50C89D4DFA95"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.7.1:*:*:*:enterprise:*:*:*","matchCriteriaId":"77D86BC4-D4DD-4848-B0FD-0C16A3D2DF89"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/407252","source":"cve@gitlab.com","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1929929","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/407252","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/1929929","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-4812","sourceIdentifier":"cve@gitlab.com","published":"2024-01-12T14:15:48.510","lastModified":"2026-06-17T06:38:38.350","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions starting from 15.3 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2. The required CODEOWNERS approval could be bypassed by adding changes to a previously approved merge request."},{"lang":"es","value":"Se descubrió un problema en GitLab EE que afecta a todas las versiones desde 15.3 anteriores a 16.5.6, todas las versiones desde 16.6 anteriores a 16.6.4, todas las versiones desde 16.7 anteriores a 16.7.2. La aprobación requerida de CODEOWNERS podría omitirse agregando cambios a una solicitud de fusión previamente aprobada."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.3","lessThan":"16.5.6","versionType":"semver","status":"affected"},{"version":"16.6","lessThan":"16.6.4","versionType":"semver","status":"affected"},{"version":"16.7","lessThan":"16.7.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:N","baseScore":7.6,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":4.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-11-14T14:33:20.930560Z","id":"CVE-2023-4812","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.3.0","versionEndExcluding":"16.5.5","matchCriteriaId":"B4DEAEEE-6DB8-4426-B577-97961307110D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.3.0","versionEndExcluding":"16.5.5","matchCriteriaId":"D547FEBC-A6BC-4057-B23D-1A7F91DFAF47"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.6.0","versionEndExcluding":"16.6.4","matchCriteriaId":"7198B7E4-9928-4B7D-9D00-6B76CCAC3875"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.6.0","versionEndExcluding":"16.6.4","matchCriteriaId":"D294EA47-B2EF-42D6-A92B-93CEA5D209B7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.7.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"29C6355F-1CD3-4E4A-AACA-19B497A631D6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.7.1:*:*:*:enterprise:*:*:*","matchCriteriaId":"77D86BC4-D4DD-4848-B0FD-0C16A3D2DF89"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/424398","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2115574","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/424398","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2115574","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-5356","sourceIdentifier":"cve@gitlab.com","published":"2024-01-12T14:15:48.707","lastModified":"2026-06-17T06:48:24.947","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Incorrect authorization checks in GitLab CE/EE from all versions starting from 8.13 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2, allows a user to abuse slack/mattermost integrations to execute slash commands as another user."},{"lang":"es","value":"Verificaciones de autorización incorrectas en GitLab CE/EE desde todas las versiones desde 8.13 anteriores a 16.5.6, todas las versiones desde 16.6 anteriores a 16.6.4, todas las versiones desde 16.7 anteriores a 16.7.2, permiten que un usuario abuse de las integraciones de slack/mattermost para ejecutar slash commands como otro usuario."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"8.13","lessThan":"16.5.6","versionType":"semver","status":"affected"},{"version":"16.6","lessThan":"16.6.4","versionType":"semver","status":"affected"},{"version":"16.7","lessThan":"16.7.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:N","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.0,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-01-23T21:57:40.489112Z","id":"CVE-2023-5356","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.13.0","versionEndExcluding":"16.5.6","matchCriteriaId":"A0266465-DBD2-4133-90B2-8DAE8D5C8588"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.13.0","versionEndExcluding":"16.5.6","matchCriteriaId":"75FBB40A-5B80-4CCC-81A1-B134B9529A23"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.6.0","versionEndExcluding":"16.6.4","matchCriteriaId":"7198B7E4-9928-4B7D-9D00-6B76CCAC3875"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.6.0","versionEndExcluding":"16.6.4","matchCriteriaId":"D294EA47-B2EF-42D6-A92B-93CEA5D209B7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.7.0:*:*:*:community:*:*:*","matchCriteriaId":"150F88EA-DA27-4042-9778-932904C2FD41"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.7.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"29C6355F-1CD3-4E4A-AACA-19B497A631D6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.7.1:*:*:*:community:*:*:*","matchCriteriaId":"D385A20C-BC93-4BB9-A47D-50C89D4DFA95"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.7.1:*:*:*:enterprise:*:*:*","matchCriteriaId":"77D86BC4-D4DD-4848-B0FD-0C16A3D2DF89"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/427154","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2188868","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/427154","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2188868","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-6955","sourceIdentifier":"cve@gitlab.com","published":"2024-01-12T14:15:49.233","lastModified":"2026-06-17T06:51:45.617","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A missing authorization check vulnerability exists in GitLab Remote Development affecting all versions prior to 16.5.6, 16.6 prior to 16.6.4 and 16.7 prior to 16.7.2. This condition allows an attacker to create a workspace in one group that is associated with an agent from another group."},{"lang":"es","value":"Existe una vulnerabilidad de control de acceso inadecuado en GitLab Remote Development que afecta a todas las versiones anteriores a 16.5.6, 16.6 anterior a 16.6.4 y 16.7 anterior a 16.7.2. Esta condición permite a un atacante crear un workspace en un grupo asociado con un agente de otro grupo."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"0","lessThan":"16.5.6","versionType":"semver","status":"affected"},{"version":"16.6","lessThan":"16.6.4","versionType":"semver","status":"affected"},{"version":"16.7","lessThan":"16.7.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:N","baseScore":6.6,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.3,"impactScore":4.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-01-12T14:36:40.506219Z","id":"CVE-2023-6955","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"16.5.6","matchCriteriaId":"69C82A9A-87DA-4974-94B2-0623B86F482D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"16.5.6","matchCriteriaId":"FC133DE0-541F-4FEE-ADA5-7A2855BDB7EF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.6.0","versionEndExcluding":"16.6.4","matchCriteriaId":"7198B7E4-9928-4B7D-9D00-6B76CCAC3875"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.6.0","versionEndExcluding":"16.6.4","matchCriteriaId":"D294EA47-B2EF-42D6-A92B-93CEA5D209B7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.7.0:*:*:*:community:*:*:*","matchCriteriaId":"150F88EA-DA27-4042-9778-932904C2FD41"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.7.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"29C6355F-1CD3-4E4A-AACA-19B497A631D6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.7.1:*:*:*:community:*:*:*","matchCriteriaId":"D385A20C-BC93-4BB9-A47D-50C89D4DFA95"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.7.1:*:*:*:enterprise:*:*:*","matchCriteriaId":"77D86BC4-D4DD-4848-B0FD-0C16A3D2DF89"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/432188","source":"cve@gitlab.com","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/432188","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2023-7028","sourceIdentifier":"cve@gitlab.com","published":"2024-01-12T14:15:49.420","lastModified":"2026-06-17T06:51:54.410","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could be delivered to an unverified email address."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde 16.1 anterior a 16.1.6, 16.2 anterior a 16.2.9, 16.3 anterior a 16.3.7, 16.4 anterior a 16.4.5, 16.5 anterior a 16.5.6, 16.6 antes de 16.6.4 y 16.7 antes de 16.7.2 en los que los correos electrónicos de restablecimiento de contraseña de cuenta de usuario podían enviarse a una dirección de correo electrónico no verificada."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.1","lessThan":"16.1.6","versionType":"semver","status":"affected"},{"version":"16.2","lessThan":"16.2.9","versionType":"semver","status":"affected"},{"version":"16.3","lessThan":"16.3.7","versionType":"semver","status":"affected"},{"version":"16.4","lessThan":"16.4.5","versionType":"semver","status":"affected"},{"version":"16.5","lessThan":"16.5.6","versionType":"semver","status":"affected"},{"version":"16.6","lessThan":"16.6.4","versionType":"semver","status":"affected"},{"version":"16.7","lessThan":"16.7.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N","baseScore":10.0,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-05-02T17:50:56.921719Z","id":"CVE-2023-7028","options":[{"exploitation":"active"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"cisaExploitAdd":"2024-05-01","cisaActionDue":"2024-05-22","cisaRequiredAction":"Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.","cisaVulnerabilityName":"GitLab Community and Enterprise Editions Improper Access Control Vulnerability","weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-640"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-640"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.1.0","versionEndExcluding":"16.1.6","matchCriteriaId":"4D1D5473-F384-420D-BD91-F2466F2CA278"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.1.0","versionEndExcluding":"16.1.6","matchCriteriaId":"6BEF9E84-75C1-41C0-BE14-7F550E2BE932"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.2.0","versionEndExcluding":"16.2.9","matchCriteriaId":"1D29FF9D-9113-44A9-99C2-074B1B217B7C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.2.0","versionEndExcluding":"16.2.9","matchCriteriaId":"AEA35F1C-5E02-407B-ADC6-4FDEFF885E59"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.3.0","versionEndExcluding":"16.3.7","matchCriteriaId":"B3F039EF-84DD-41B6-AB5D-BF3F44A488C2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.3.0","versionEndExcluding":"16.3.7","matchCriteriaId":"02C5947D-659A-4AE9-B2C8-08287AC03BF2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.4.0","versionEndExcluding":"16.4.5","matchCriteriaId":"C89EFE63-81D9-4964-BE91-BF31AA40C165"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.4.0","versionEndExcluding":"16.4.5","matchCriteriaId":"4B4C9455-DBA2-480B-8C59-898BC9DB8795"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.5.0","versionEndExcluding":"16.5.6","matchCriteriaId":"A1A5DDAD-5B04-4643-8ACD-15D7C6CD76C2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.5.0","versionEndExcluding":"16.5.6","matchCriteriaId":"24A21A70-46F1-4B28-BECB-4266AABBBD57"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.6.0","versionEndExcluding":"16.6.4","matchCriteriaId":"7198B7E4-9928-4B7D-9D00-6B76CCAC3875"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.6.0","versionEndExcluding":"16.6.4","matchCriteriaId":"D294EA47-B2EF-42D6-A92B-93CEA5D209B7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.7.0","versionEndExcluding":"16.7.2","matchCriteriaId":"E66EC8A8-E889-450A-86B4-7D930788FF58"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.7.0","versionEndExcluding":"16.7.2","matchCriteriaId":"DDBB44E5-7ED3-4C9B-9241-2E6DB79A3E27"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/436084","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/2293343","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/436084","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/2293343","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]},{"url":"https://www.vicarius.io/vsociety/posts/critical-gitlab-account-takeover-vulnerability-cve-2023-7028","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-7028","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"]}]}},{"cve":{"id":"CVE-2023-5933","sourceIdentifier":"cve@gitlab.com","published":"2024-01-26T01:15:08.660","lastModified":"2026-06-17T06:49:41.567","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions after 13.7 before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. Improper input sanitization of user name allows arbitrary API PUT requests."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones posteriores a 13.7 anteriores a 16.6.6, 16.7 anteriores a 16.7.4 y 16.8 anteriores a 16.8.1. La sanitización inadecuada de la entrada del nombre de usuario permite solicitudes PUT de API arbitrarias."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"13.7","lessThan":"16.6.6","versionType":"semver","status":"affected"},{"version":"16.7","lessThan":"16.7.4","versionType":"semver","status":"affected"},{"version":"16.8","lessThan":"16.8.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-11-13T15:00:09.174638Z","id":"CVE-2023-5933","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-80"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"16.6.6","matchCriteriaId":"CB08E85C-E128-44D4-B9B7-2A58790D72C5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"16.6.6","matchCriteriaId":"31BFE094-EDFE-447F-AC01-9D18E1375383"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.7.0","versionEndExcluding":"16.7.4","matchCriteriaId":"0F871342-EDE9-49F2-8081-04651A16CD6E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.7.0","versionEndExcluding":"16.7.4","matchCriteriaId":"9A9ED476-FBE7-4022-AE16-18386E73AA59"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.8.0:*:*:*:community:*:*:*","matchCriteriaId":"246D6584-64A7-44AC-A279-ECA58E5ED1FB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.8.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"E591D495-7397-4DA2-A643-477B2E35A915"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2024/01/25/critical-security-release-gitlab-16-8-1-released/","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/430236","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2225710","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://about.gitlab.com/releases/2024/01/25/critical-security-release-gitlab-16-8-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/430236","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2225710","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-0402","sourceIdentifier":"cve@gitlab.com","published":"2024-01-26T01:15:08.920","lastModified":"2026-06-17T06:53:25.503","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 which allows an authenticated user to write files to arbitrary locations on the GitLab server while creating a workspace."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde 16.0 anterior a 16.6.6, 16.7 anterior a 16.7.4 y 16.8 anterior a 16.8.1, lo que permite a un usuario autenticado escribir archivos en ubicaciones arbitrarias en el servidor GitLab mientras crea un workspace."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.0","lessThan":"16.5.8","versionType":"semver","status":"affected"},{"version":"16.6","lessThan":"16.6.6","versionType":"semver","status":"affected"},{"version":"16.7","lessThan":"16.7.4","versionType":"semver","status":"affected"},{"version":"16.8","lessThan":"16.8.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":9.9,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.1,"impactScore":6.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":9.9,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.1,"impactScore":6.0}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-06-03T18:01:24.319017Z","id":"CVE-2024-0402","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-22"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-22"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"16.5.8","matchCriteriaId":"2D6B2329-5500-4D95-8270-2CCB839C226F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"16.5.8","matchCriteriaId":"3732A61E-AFE9-4A84-B3A8-C34F0F79C5A0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.6.0","versionEndExcluding":"16.6.6","matchCriteriaId":"8429A44F-1788-421A-99A9-1E650735BBDD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.6.0","versionEndExcluding":"16.6.6","matchCriteriaId":"3D66D64A-B883-4A2C-B114-3A54F326BA8D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.7.0","versionEndExcluding":"16.7.4","matchCriteriaId":"0F871342-EDE9-49F2-8081-04651A16CD6E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.7.0","versionEndExcluding":"16.7.4","matchCriteriaId":"9A9ED476-FBE7-4022-AE16-18386E73AA59"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.8.0:*:*:*:community:*:*:*","matchCriteriaId":"246D6584-64A7-44AC-A279-ECA58E5ED1FB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.8.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"E591D495-7397-4DA2-A643-477B2E35A915"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2024/01/25/critical-security-release-gitlab-16-8-1-released/","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/437819","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://about.gitlab.com/releases/2024/01/25/critical-security-release-gitlab-16-8-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/437819","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2024-0456","sourceIdentifier":"cve@gitlab.com","published":"2024-01-26T01:15:09.110","lastModified":"2026-06-17T06:53:32.827","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An authorization vulnerability exists in GitLab versions 14.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. An unauthorized attacker is able to assign arbitrary users to MRs that they created within the project"},{"lang":"es","value":"Existe una vulnerabilidad de autorización en las versiones de GitLab 14.0 anteriores a 16.6.6, 16.7 anteriores a 16.7.4 y 16.8 anteriores a 16.8.1. Un atacante no autorizado puede asignar usuarios arbitrarios a los MR que crearon dentro del proyecto."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"14.0","lessThan":"16.6.6","versionType":"semver","status":"affected"},{"version":"16.7","lessThan":"16.7.4","versionType":"semver","status":"affected"},{"version":"16.8","lessThan":"16.8.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-08T15:52:46.854334Z","id":"CVE-2024-0456","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-425"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"16.6.6","matchCriteriaId":"0E703ECB-5DF7-42ED-9137-E2C9706FF40F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"16.6.6","matchCriteriaId":"8A35C143-4E0C-404A-B878-E49557E08698"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.7.0","versionEndExcluding":"16.7.4","matchCriteriaId":"0F871342-EDE9-49F2-8081-04651A16CD6E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.7.0","versionEndExcluding":"16.7.4","matchCriteriaId":"9A9ED476-FBE7-4022-AE16-18386E73AA59"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.8.0:*:*:*:community:*:*:*","matchCriteriaId":"246D6584-64A7-44AC-A279-ECA58E5ED1FB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.8.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"E591D495-7397-4DA2-A643-477B2E35A915"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2024/01/25/critical-security-release-gitlab-16-8-1-released/","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/430726","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://about.gitlab.com/releases/2024/01/25/critical-security-release-gitlab-16-8-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/430726","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2023-5612","sourceIdentifier":"cve@gitlab.com","published":"2024-01-26T02:15:07.357","lastModified":"2026-06-17T06:48:56.490","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. It was possible to read the user email address via tags feed although the visibility in the user profile has been disabled."},{"lang":"es","value":"Se descubrió un problema en GitLab que afecta a todas las versiones anteriores a 16.6.6, 16.7 anteriores a 16.7.4 y 16.8 anteriores a 16.8.1. Era posible leer la dirección de correo electrónico del usuario a través del feed de etiquetas, aunque la visibilidad en el perfil del usuario se ha desactivado."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"0","lessThan":"16.6.6","versionType":"semver","status":"affected"},{"version":"16.7","lessThan":"16.7.4","versionType":"semver","status":"affected"},{"version":"16.8","lessThan":"16.8.1","versionType":"semver","status":"affected"}]}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","affectedData":[{"vendor":"gitlab","product":"gitlab","defaultStatus":"unknown","cpes":["cpe:2.3:a:gitlab:gitlab:-:*:*:*:-:*:*:*"],"versions":[{"version":"0","lessThan":"16.6.6","versionType":"semver","status":"affected"},{"version":"16.7","lessThan":"16.7.4","versionType":"semver","status":"affected"},{"version":"16.8","lessThan":"16.8.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-01-29T18:55:24.572021Z","id":"CVE-2023-5612","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"16.6.6","matchCriteriaId":"E229770B-0BBC-4C62-B8A5-7FF7F7BA60EB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"16.6.6","matchCriteriaId":"E891B4BC-C3CE-4F96-BB11-34BBE0F3A293"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.7.0","versionEndExcluding":"16.7.4","matchCriteriaId":"0F871342-EDE9-49F2-8081-04651A16CD6E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.7.0","versionEndExcluding":"16.7.4","matchCriteriaId":"9A9ED476-FBE7-4022-AE16-18386E73AA59"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.8.0:*:*:*:community:*:*:*","matchCriteriaId":"246D6584-64A7-44AC-A279-ECA58E5ED1FB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.8.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"E591D495-7397-4DA2-A643-477B2E35A915"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2024/01/25/critical-security-release-gitlab-16-8-1-released/","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/428441","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2208790","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://about.gitlab.com/releases/2024/01/25/critical-security-release-gitlab-16-8-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/428441","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2208790","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-6159","sourceIdentifier":"cve@gitlab.com","published":"2024-01-26T02:15:07.567","lastModified":"2026-06-17T06:50:10.430","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 12.7 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 It was possible for an attacker to trigger a Regular Expression Denial of Service via a `Cargo.toml` containing maliciously crafted input."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde 12.7 anterior a 16.6.6, 16.7 anterior a 16.7.4 y 16.8 anterior a 16.8.1. Era posible que un atacante desencadenara una denegación de servicio de expresión regular a través de un `Cargo.toml` que contiene entradas manipuladas con fines malintencionados."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"12.7","lessThan":"16.6.6","versionType":"semver","status":"affected"},{"version":"16.7","lessThan":"16.7.4","versionType":"semver","status":"affected"},{"version":"16.8","lessThan":"16.8.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-02-21T16:56:36.041200Z","id":"CVE-2023-6159","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1333"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-1333"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.7.0","versionEndExcluding":"16.6.6","matchCriteriaId":"A5EBA0AA-A2D8-4F32-B39B-E076027A3F55"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.7.0","versionEndExcluding":"16.6.6","matchCriteriaId":"8ACBAE3E-564F-442F-817E-6284FE60F357"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.7.0","versionEndExcluding":"16.7.4","matchCriteriaId":"0F871342-EDE9-49F2-8081-04651A16CD6E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.7.0","versionEndExcluding":"16.7.4","matchCriteriaId":"9A9ED476-FBE7-4022-AE16-18386E73AA59"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.8.0:*:*:*:community:*:*:*","matchCriteriaId":"246D6584-64A7-44AC-A279-ECA58E5ED1FB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.8.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"E591D495-7397-4DA2-A643-477B2E35A915"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2024/01/25/critical-security-release-gitlab-16-8-1-released/","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/431924","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2251278","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://about.gitlab.com/releases/2024/01/25/critical-security-release-gitlab-16-8-1-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/431924","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2251278","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-6736","sourceIdentifier":"cve@gitlab.com","published":"2024-02-07T22:15:09.043","lastModified":"2026-06-17T06:51:19.627","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions starting from 11.3 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. It was possible for an attacker to cause a client-side denial of service using malicious crafted content in the CODEOWNERS file."},{"lang":"es","value":"Se descubrió un problema en GitLab EE que afecta a todas las versiones desde 11.3 anteriores a 16.6.7, todas las versiones desde 16.7 anteriores a 16.7.5, todas las versiones desde 16.8 anteriores a 16.8.2. Era posible que un atacante provocara una denegación de servicio del lado del cliente utilizando contenido manipulado maliciosamente en el archivo CODEOWNERS."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"11.3","lessThan":"16.7.6","versionType":"semver","status":"affected"},{"version":"16.8","lessThan":"16.8.3","versionType":"semver","status":"affected"},{"version":"16.9","lessThan":"16.9.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-02-08T17:28:36.837955Z","id":"CVE-2023-6736","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1333"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-1333"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"16.7.6","matchCriteriaId":"0A393A71-3927-44F2-B9C6-7E33534F72C7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.8.0","versionEndExcluding":"16.8.3","matchCriteriaId":"1920E538-FE0D-40A6-8EA3-667D9835DA8E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.9.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"1E374890-90FC-4DC5-8C0B-87CC99B4A4D7"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/435036","source":"cve@gitlab.com","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/2269023","source":"cve@gitlab.com","tags":["Permissions Required","Technical Description"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/435036","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/2269023","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Technical Description"]}]}},{"cve":{"id":"CVE-2023-6840","sourceIdentifier":"cve@gitlab.com","published":"2024-02-07T22:15:09.500","lastModified":"2026-06-17T06:51:31.170","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions from 16.4 prior to 16.6.7, 16.7 prior to 16.7.5, and 16.8 prior to 16.8.2 which allows a maintainer to change the name of a protected branch that bypasses the security policy added to block MR."},{"lang":"es","value":"Se ha descubierto un problema en GitLab EE que afecta a todas las versiones desde 16.4 anterior a 16.6.7, 16.7 anterior a 16.7.5 y 16.8 anterior a 16.8.2 lo que permite a un fabricante cambiar el nombre de una rama protegida que omite la política de seguridad agregada para bloquear MR."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.4","lessThan":"16.6.7","versionType":"semver","status":"affected"},{"version":"16.7","lessThan":"16.7.5","versionType":"semver","status":"affected"},{"version":"16.8","lessThan":"16.8.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H","baseScore":6.7,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H","baseScore":6.7,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-12-18T17:54:46.828519Z","id":"CVE-2023-6840","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.4.0","versionEndExcluding":"16.6.7","matchCriteriaId":"5A1A9E0E-DFC2-4567-9218-6F7B9FE56F34"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.7.0","versionEndExcluding":"16.7.5","matchCriteriaId":"8ECA9350-B77B-41F6-B234-72BF47FD50E7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.8.0","versionEndExcluding":"16.8.2","matchCriteriaId":"FDA190F8-0AAA-44DF-8A6B-A9A4380D478C"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/435500","source":"cve@gitlab.com","tags":["Issue Tracking","Permissions Required"]},{"url":"https://hackerone.com/reports/2280292","source":"cve@gitlab.com","tags":["Permissions Required","Technical Description"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/435500","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Permissions Required"]},{"url":"https://hackerone.com/reports/2280292","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Technical Description"]}]}},{"cve":{"id":"CVE-2024-1066","sourceIdentifier":"cve@gitlab.com","published":"2024-02-07T22:15:09.797","lastModified":"2026-06-17T07:03:21.887","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions from 13.3.0 prior to 16.6.7, 16.7 prior to 16.7.5, and 16.8 prior to 16.8.2 which allows an attacker to do a resource exhaustion using GraphQL `vulnerabilitiesCountByDay`"},{"lang":"es","value":"Se ha descubierto un problema en GitLab EE que afecta a todas las versiones desde 13.3.0 anterior a 16.6.7, 16.7 anterior a 16.7.5 y 16.8 anterior a 16.8.2, lo que permite a un atacante agotar los recursos utilizando las `vulnerabilidadesCountByDay` de GraphQL."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"13.3.3","lessThan":"16.6.7","versionType":"semver","status":"affected"},{"version":"16.7","lessThan":"16.7.5","versionType":"semver","status":"affected"},{"version":"16.8","lessThan":"16.8.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-02-08T20:27:04.759252Z","id":"CVE-2024-1066","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"16.6.7","matchCriteriaId":"9050BD58-8285-4043-A5CE-D176B837C006"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"16.7.0","versionEndExcluding":"16.7.5","matchCriteriaId":"6EBC5A56-73F8-43A7-8EC8-B76904367719"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"16.8.0","versionEndExcluding":"16.8.2","matchCriteriaId":"49D0039A-BE00-4F9D-8385-2B81C5AB5CD6"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/420341","source":"cve@gitlab.com","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/420341","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2023-6564","sourceIdentifier":"cve@gitlab.com","published":"2024-02-08T12:15:55.767","lastModified":"2026-06-17T06:50:59.993","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE Premium and Ultimate affecting versions 16.4.3, 16.5.3, and 16.6.1. In projects using subgroups to define who can push and/or merge to protected branches, there may have been instances in which subgroup members with the Developer role were able to push or merge to protected branches."},{"lang":"es","value":"Se descubrió un problema en GitLab EE Premium y Ultimate que afecta las versiones 16.4.3, 16.5.3 y 16.6.1. En proyectos que utilizan subgrupos para definir quién puede enviar o fusionar ramas protegidas, es posible que haya habido casos en los que los miembros del subgrupo con el rol de Desarrollador pudieron enviar o fusionar ramas protegidas."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.4.3","lessThan":"16.4.4","versionType":"semver","status":"affected"},{"version":"16.5.3","lessThan":"16.5.4","versionType":"semver","status":"affected"},{"version":"16.6.1","lessThan":"16.6.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-02-21T19:46:07.212089Z","id":"CVE-2023-6564","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.4.3:*:*:*:enterprise:*:*:*","matchCriteriaId":"6A759830-9D31-4AF5-912F-CA91D6023AD6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.5.3:*:*:*:enterprise:*:*:*","matchCriteriaId":"D2A7EFB5-6D86-4034-99EF-78E95E32D155"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.6.1:*:*:*:enterprise:*:*:*","matchCriteriaId":"598CF5D0-C052-4794-A66D-45BB6E002212"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-com/gl-infra/production/-/issues/17213","source":"cve@gitlab.com","tags":["Issue Tracking","Permissions Required"]},{"url":"https://gitlab.com/gitlab-com/gl-infra/production/-/issues/17213","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Permissions Required"]}]}},{"cve":{"id":"CVE-2024-1250","sourceIdentifier":"cve@gitlab.com","published":"2024-02-12T21:15:08.313","lastModified":"2026-06-17T07:03:48.947","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions starting from 16.8 before 16.8.2. When a user is assigned a custom role with manage_group_access_tokens permission, they may be able to create group access tokens with Owner privileges, which may lead to privilege escalation."},{"lang":"es","value":"Se descubrió un problema en GitLab EE que afecta a todas las versiones desde la 16.8 hasta la 16.8.2. Cuando a un usuario se le asigna una función personalizada con permiso de Manage_group_access_tokens, es posible que pueda crear tokens de acceso de grupo con privilegios de propietario, lo que puede conducir a una escalada de privilegios."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.8","lessThan":"16.8.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-02-13T01:11:42.842268Z","id":"CVE-2024-1250","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-268"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.8.0","versionEndExcluding":"16.8.2","matchCriteriaId":"FDA190F8-0AAA-44DF-8A6B-A9A4380D478C"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/439175","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/439175","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-3509","sourceIdentifier":"cve@gitlab.com","published":"2024-02-21T23:15:08.223","lastModified":"2026-06-17T06:14:14.687","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. It was possible for group members with sub-maintainer role to change the title of privately accessible deploy keys associated with projects in the group."},{"lang":"es","value":"Se descubrió un problema en GitLab que afecta a todas las versiones anteriores a 16.7.6, todas las versiones desde 16.8 anteriores a 16.8.3, todas las versiones desde 16.9 anteriores a 16.9.1. Los miembros del grupo con función de submantenedor podían cambiar el título de las claves de implementación de acceso privado asociadas con los proyectos del grupo."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"0","lessThan":"16.7.6","versionType":"semver","status":"affected"},{"version":"16.8","lessThan":"16.8.3","versionType":"semver","status":"affected"},{"version":"16.9","lessThan":"16.9.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N","baseScore":3.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":2.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-02-22T15:45:32.541540Z","id":"CVE-2023-3509","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionEndIncluding":"16.7.6","matchCriteriaId":"0A04F244-8B1C-451C-9C0F-86885410FBD9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"16.8.0","versionEndIncluding":"16.8.3","matchCriteriaId":"E0A7B883-EFAA-456B-AB89-9FEF5BED60CB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.9.0:*:*:*:*:*:*:*","matchCriteriaId":"06CEE568-A6C1-4C8A-8786-B561643668AB"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/416945","source":"cve@gitlab.com","tags":["Broken Link","Permissions Required"]},{"url":"https://hackerone.com/reports/2037814","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/416945","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Permissions Required"]},{"url":"https://hackerone.com/reports/2037814","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-6477","sourceIdentifier":"cve@gitlab.com","published":"2024-02-22T00:15:51.533","lastModified":"2026-06-17T06:50:49.323","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions starting from 16.5 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. When a user is assigned a custom role with admin_group_member permission, they may be able to make a group, other members or themselves Owners of that group, which may lead to privilege escalation."},{"lang":"es","value":"Se descubrió un problema en GitLab EE que afecta a todas las versiones desde 16.5 anteriores a 16.7.6, todas las versiones desde 16.8 anteriores a 16.8.3, todas las versiones desde 16.9 anteriores a 16.9.1. Cuando a un usuario se le asigna una función personalizada con permiso admin_group_member, es posible que pueda convertir un grupo, otros miembros o ellos mismos en propietarios de ese grupo, lo que puede llevar a una escalada de privilegios."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.5","lessThan":"16.7.6","versionType":"semver","status":"affected"},{"version":"16.8","lessThan":"16.8.3","versionType":"semver","status":"affected"},{"version":"16.9","lessThan":"16.9.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L","baseScore":6.7,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":1.2,"impactScore":5.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L","baseScore":6.7,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":1.2,"impactScore":5.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-02-22T16:24:56.873302Z","id":"CVE-2023-6477","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-266"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.5.0","versionEndExcluding":"16.7.6","matchCriteriaId":"B2558C81-DADC-475C-A06B-DB9048CE85FC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.8.0","versionEndIncluding":"16.8.3","matchCriteriaId":"BF18D8E8-7406-46F4-BDDD-CC743A5C4D80"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.9.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"1E374890-90FC-4DC5-8C0B-87CC99B4A4D7"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/433463","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://hackerone.com/reports/2270898","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/433463","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]},{"url":"https://hackerone.com/reports/2270898","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-0410","sourceIdentifier":"cve@gitlab.com","published":"2024-02-22T00:15:51.723","lastModified":"2026-06-17T06:53:26.837","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An authorization bypass vulnerability was discovered in GitLab affecting versions 15.1 prior to 16.7.6, 16.8 prior to 16.8.3, and 16.9 prior to 16.9.1. A developer could bypass CODEOWNERS approvals by creating a merge conflict."},{"lang":"es","value":"Se descubrió una vulnerabilidad de omisión de autorización en GitLab que afecta a las versiones 15.1 anteriores a 16.7.6, 16.8 anteriores a 16.8.3 y 16.9 anteriores a 16.9.1. Un desarrollador podría eludir las aprobaciones de CODEOWNERS creando un conflicto de fusión."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.1","lessThan":"16.7.6","versionType":"semver","status":"affected"},{"version":"16.8","lessThan":"16.8.3","versionType":"semver","status":"affected"},{"version":"16.9","lessThan":"16.9.1","versionType":"semver","status":"affected"}]}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","affectedData":[{"vendor":"gitlab","product":"gitlab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"versions":[{"version":"15.1","lessThan":"16.7.6","versionType":"semver","status":"affected"},{"version":"16.8","lessThan":"16.8.3","versionType":"semver","status":"affected"},{"version":"16.9","lessThan":"16.9.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":7.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.3,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":7.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.3,"impactScore":5.8}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-02-22T15:01:52.798832Z","id":"CVE-2024-0410","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-841"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"15.1.0","versionEndExcluding":"16.7.6","matchCriteriaId":"B0EDCF56-03C7-48C1-98D4-64564BE5E8C6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"16.8.0","versionEndExcluding":"16.8.3","matchCriteriaId":"32EE52BE-8BFD-40AA-9826-76DB2188E48E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.9.0:*:*:*:*:*:*:*","matchCriteriaId":"06CEE568-A6C1-4C8A-8786-B561643668AB"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/437988","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://hackerone.com/reports/2296778","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/437988","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]},{"url":"https://hackerone.com/reports/2296778","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-0861","sourceIdentifier":"cve@gitlab.com","published":"2024-02-22T00:15:51.973","lastModified":"2026-06-17T06:54:27.227","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions starting from 16.4 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. Users with the `Guest` role can change `Custom dashboard projects` settings contrary to permissions."},{"lang":"es","value":"Se ha descubierto un problema en GitLab EE que afecta a todas las versiones desde 16.4 anteriores a 16.7.6, todas las versiones desde 16.8 anteriores a 16.8.3, todas las versiones desde 16.9 anteriores a 16.9.1. Los usuarios con el rol \"Invitado\" pueden cambiar la configuración de \"Proyectos de panel personalizados\" en contra de los permisos."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.9","lessThan":"16.9.1","versionType":"semver","status":"affected"},{"version":"16.8","lessThan":"16.8.3","versionType":"semver","status":"affected"},{"version":"16.4","lessThan":"16.7.6","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-08-21T14:54:15.333959Z","id":"CVE-2024-0861","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-425"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.4.0","versionEndExcluding":"16.7.6","matchCriteriaId":"E0C6BB02-2255-4DA6-BCEB-36792BF910BC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.8.0","versionEndExcluding":"16.8.3","matchCriteriaId":"1920E538-FE0D-40A6-8EA3-667D9835DA8E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.9.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"1E374890-90FC-4DC5-8C0B-87CC99B4A4D7"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/439240","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://hackerone.com/reports/2316435","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/439240","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]},{"url":"https://hackerone.com/reports/2316435","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-1451","sourceIdentifier":"cve@gitlab.com","published":"2024-02-22T00:15:52.153","lastModified":"2026-06-17T07:04:16.350","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 before 16.9.1. A crafted payload  added to the user profile page could lead to a stored XSS on the client side, allowing attackers to perform arbitrary actions on behalf of victims.\""},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde la 16.9 hasta la 16.9.1. un payload manipulado y agregado a la página de perfil del usuario podría generar un XSS almacenado en el lado del cliente, lo que permitiría a los atacantes realizar acciones arbitrarias en nombre de las víctimas\"."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.9.0","lessThan":"16.9.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":5.8}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-02-22T16:16:14.157838Z","id":"CVE-2024-1451","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.9.0:*:*:*:*:*:*:*","matchCriteriaId":"06CEE568-A6C1-4C8A-8786-B561643668AB"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/441457","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://hackerone.com/reports/2371126","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/441457","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]},{"url":"https://hackerone.com/reports/2371126","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-1525","sourceIdentifier":"cve@gitlab.com","published":"2024-02-22T00:15:52.327","lastModified":"2026-06-17T07:04:25.533","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. Under some specialized conditions, an LDAP user may be able to reset their password using their verified secondary email address and sign-in using direct authentication with the reset password, bypassing LDAP."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde 16.1 anteriores a 16.7.6, todas las versiones desde 16.8 anteriores a 16.8.3, todas las versiones desde 16.9 anteriores a 16.9.1. En algunas condiciones especializadas, un usuario de LDAP puede restablecer su contraseña utilizando su dirección de correo electrónico secundaria verificada e iniciar sesión mediante autenticación directa con la contraseña restablecida, sin pasar por LDAP."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.1","lessThan":"16.7.6","versionType":"semver","status":"affected"},{"version":"16.8","lessThan":"16.8.3","versionType":"semver","status":"affected"},{"version":"16.9","lessThan":"16.9.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-02-22T16:29:18.467492Z","id":"CVE-2024-1525","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-288"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"16.1","versionEndExcluding":"16.7.6","matchCriteriaId":"F78B6F50-69F7-45F5-9541-5F35620206A9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"16.8","versionEndExcluding":"16.8.3","matchCriteriaId":"59BDFC85-244E-41F5-9F55-D4497756954B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.9.0:*:*:*:*:*:*:*","matchCriteriaId":"06CEE568-A6C1-4C8A-8786-B561643668AB"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/438144","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/438144","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-4895","sourceIdentifier":"cve@gitlab.com","published":"2024-02-22T01:15:07.780","lastModified":"2026-06-17T06:38:50.677","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions starting from 12.0 to 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. This vulnerability allows for bypassing the 'group ip restriction' settings to access environment details of projects"},{"lang":"es","value":"Se descubrió un problema en GitLab EE que afecta a todas las versiones desde 12.0 a 16.7.6, todas las versiones desde 16.8 anteriores a 16.8.3, todas las versiones desde 16.9 anteriores a 16.9.1. Esta vulnerabilidad permite omitir la configuración de 'restricción de IP de grupo' para acceder a los detalles del entorno de los proyectos."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"12.0","lessThan":"16.7.6","versionType":"semver","status":"affected"},{"version":"16.8","lessThan":"16.8.3","versionType":"semver","status":"affected"},{"version":"16.9","lessThan":"16.9.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-19T16:19:59.822592Z","id":"CVE-2023-4895","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.0","versionEndIncluding":"16.76","matchCriteriaId":"C33D3245-F0DB-408F-8E54-4CEE331BDF88"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.8","versionEndExcluding":"16.8.3","matchCriteriaId":"C2172309-EFB1-4A6E-A65F-A4286273C09B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.9.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"1E374890-90FC-4DC5-8C0B-87CC99B4A4D7"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/424766","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://hackerone.com/reports/2134787","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/424766","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]},{"url":"https://hackerone.com/reports/2134787","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-0199","sourceIdentifier":"cve@gitlab.com","published":"2024-03-07T01:15:52.233","lastModified":"2026-06-17T06:52:59.160","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An authorization bypass vulnerability was discovered in GitLab affecting versions 11.3 prior to 16.7.7, 16.7.6 prior to 16.8.4, and 16.8.3 prior to 16.9.2. An attacker could bypass CODEOWNERS by utilizing a crafted payload in an old feature branch to perform malicious actions."},{"lang":"es","value":"Se descubrió una vulnerabilidad de omisión de autorización en GitLab que afecta a las versiones 11.3 anteriores a 16.7.7, 16.7.6 anteriores a 16.8.4 y 16.8.3 anteriores a 16.9.2. Un atacante podría eludir a CODEOWNERS utilizando un payload malicioso en una rama de funciones antigua para realizar acciones maliciosas."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"11.3","lessThan":"16.7.7","versionType":"semver","status":"affected"},{"version":"16.8","lessThan":"16.8.4","versionType":"semver","status":"affected"},{"version":"16.9","lessThan":"16.9.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":7.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.3,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","baseScore":8.0,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.1,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-24T14:00:10.558936Z","id":"CVE-2024-0199","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.3","versionEndExcluding":"16.7.7","matchCriteriaId":"B94BEED5-2938-43D0-A97E-8F47CB3A6DBC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.3","versionEndExcluding":"16.7.7","matchCriteriaId":"04AE6840-C038-43C3-B985-205C413C34B7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.8.0","versionEndExcluding":"16.8.4","matchCriteriaId":"C1D7C60A-061E-44F9-AE22-D548DE53B117"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.8.0","versionEndExcluding":"16.8.4","matchCriteriaId":"2F20E088-CE58-4838-B756-612BB8687809"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.9.0","versionEndExcluding":"16.9.2","matchCriteriaId":"D02C567D-8E1A-42C8-83A3-CF368AB3204F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.9.0","versionEndExcluding":"16.9.2","matchCriteriaId":"254A5DA0-23B6-45B2-A91E-F9825E717290"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2024/03/06/security-release-gitlab-16-9-2-released/","source":"cve@gitlab.com","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/436977","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/2295423","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://about.gitlab.com/releases/2024/03/06/security-release-gitlab-16-9-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/436977","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/2295423","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-1299","sourceIdentifier":"cve@gitlab.com","published":"2024-03-07T01:15:52.443","lastModified":"2026-06-17T07:03:55.480","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A privilege escalation vulnerability was discovered in GitLab affecting versions 16.8 prior to 16.8.4 and 16.9 prior to 16.9.2. It was possible for a user with custom role of `manage_group_access_tokens` to rotate group access tokens with owner privileges."},{"lang":"es","value":"Se descubrió una vulnerabilidad de escalada de privilegios en GitLab que afecta a las versiones 16.8 anteriores a 16.8.4 y 16.9 anteriores a 16.9.2. Era posible que un usuario con el rol personalizado `manage_group_access_tokens` rotara tokens de acceso de grupo con privilegios de propietario."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.8","lessThan":"16.8.4","versionType":"semver","status":"affected"},{"version":"16.9","lessThan":"16.9.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-03-12T04:00:39.662499Z","id":"CVE-2024-1299","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-268"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.8.0","versionEndExcluding":"16.8.4","matchCriteriaId":"C1D7C60A-061E-44F9-AE22-D548DE53B117"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.8.0","versionEndExcluding":"16.8.4","matchCriteriaId":"2F20E088-CE58-4838-B756-612BB8687809"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.9.0","versionEndExcluding":"16.9.2","matchCriteriaId":"D02C567D-8E1A-42C8-83A3-CF368AB3204F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.9.0","versionEndExcluding":"16.9.2","matchCriteriaId":"254A5DA0-23B6-45B2-A91E-F9825E717290"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2024/03/06/security-release-gitlab-16-9-2-released/","source":"cve@gitlab.com","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/440745","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/2356976","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://about.gitlab.com/releases/2024/03/06/security-release-gitlab-16-9-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/440745","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/2356976","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-6371","sourceIdentifier":"cve@gitlab.com","published":"2024-03-28T08:15:26.223","lastModified":"2026-06-17T06:50:37.753","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions before 16.8.5, all versions starting from 16.9 before 16.9.3, all versions starting from 16.10 before 16.10.1. A wiki page with a crafted payload may lead to a Stored XSS, allowing attackers to perform arbitrary actions on behalf of victims."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones anteriores a 16.8.5, todas las versiones desde 16.9 anteriores a 16.9.3, todas las versiones desde 16.10 anteriores a 16.10.1. Una página wiki con un payload manipulado puede generar un XSS almacenado, lo que permite a los atacantes realizar acciones arbitrarias en nombre de las víctimas."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"0.0","lessThan":"16.8.5","versionType":"semver","status":"affected"},{"version":"16.9","lessThan":"16.9.3","versionType":"semver","status":"affected"},{"version":"16.10","lessThan":"16.10.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-09-17T15:37:33.371856Z","id":"CVE-2023-6371","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"16.8.5","matchCriteriaId":"4867F1FA-53C2-4AB4-ACF1-257BA2125484"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"16.8.5","matchCriteriaId":"D0918E4A-3AD6-461C-A693-9A7273757AC2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.9.0","versionEndExcluding":"16.9.3","matchCriteriaId":"D8B59378-A2DC-4C3D-A4F8-D3913AFD46D0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.9.0","versionEndExcluding":"16.9.3","matchCriteriaId":"EE028131-A200-472E-8CA5-167A4057DB4A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.10.0:*:*:*:community:*:*:*","matchCriteriaId":"D7864CB7-B9B8-45D3-AD0E-AE9560A23011"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.10.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"81BBF090-0C40-4056-AE87-620051A1A349"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/433021","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/2257080","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/433021","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/2257080","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking"]}]}},{"cve":{"id":"CVE-2024-2818","sourceIdentifier":"cve@gitlab.com","published":"2024-03-28T08:15:26.590","lastModified":"2026-06-17T07:25:36.863","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions before 16.8.5, all versions starting from 16.9 before 16.9.3, all versions starting from 16.10 before 16.10.1. It was possible for an attacker to cause a denial of service using malicious crafted description parameter for labels."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones anteriores a 16.8.5, todas las versiones desde 16.9 anteriores a 16.9.3, todas las versiones desde 16.10 anteriores a 16.10.1. Era posible que un atacante provocara una denegación de servicio utilizando un parámetro de descripción manipulado maliciosamente para las etiquetas."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"0","lessThan":"16.8.5","versionType":"semver","status":"affected"},{"version":"16.9","lessThan":"16.9.3","versionType":"semver","status":"affected"},{"version":"16.10","lessThan":"16.10.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-03-28T15:48:59.745490Z","id":"CVE-2024-2818","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"16.8.5","matchCriteriaId":"4867F1FA-53C2-4AB4-ACF1-257BA2125484"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"16.8.5","matchCriteriaId":"D0918E4A-3AD6-461C-A693-9A7273757AC2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.9.0","versionEndExcluding":"16.9.3","matchCriteriaId":"D8B59378-A2DC-4C3D-A4F8-D3913AFD46D0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.9.0","versionEndExcluding":"16.9.3","matchCriteriaId":"EE028131-A200-472E-8CA5-167A4057DB4A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.10.0:*:*:*:community:*:*:*","matchCriteriaId":"D7864CB7-B9B8-45D3-AD0E-AE9560A23011"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.10.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"81BBF090-0C40-4056-AE87-620051A1A349"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/434803","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/434803","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2023-6489","sourceIdentifier":"cve@gitlab.com","published":"2024-04-12T01:15:57.340","lastModified":"2026-06-17T06:50:50.783","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A denial of service vulnerability was identified in GitLab CE/EE, versions 16.7.7 prior to 16.8.6, 16.9 prior to 16.9.4 and 16.10 prior to 16.10.2 which allows an attacker to spike the GitLab instance resources usage resulting in service degradation via chat integration feature."},{"lang":"es","value":"Se identificó una vulnerabilidad de denegación de servicio en GitLab CE/EE, versiones 16.7.7 anteriores a 16.8.6, 16.9 anteriores a 16.9.4 y 16.10 anteriores a 16.10.2, que permite a un atacante aumentar el uso de recursos de la instancia de GitLab, lo que resulta en servicio. degradación a través de la función de integración de chat."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.7.7","lessThan":"16.8.6","versionType":"semver","status":"affected"},{"version":"16.9","lessThan":"16.9.4","versionType":"semver","status":"affected"},{"version":"16.10","lessThan":"16.10.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-08T18:45:14.622510Z","id":"CVE-2023-6489","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1333"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-1333"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.7.7","versionEndExcluding":"16.8.6","matchCriteriaId":"CEC51D1F-F1B7-44E4-BB00-4C57D0F7988C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.7.7","versionEndExcluding":"16.8.6","matchCriteriaId":"754B2043-9069-40C7-8238-A6C163409EB0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.9.0","versionEndExcluding":"16.9.4","matchCriteriaId":"6C090961-541F-48DB-A98E-B7227E2BEF1E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.9.0","versionEndExcluding":"16.9.4","matchCriteriaId":"CE07887F-4BE5-4269-9C3B-10CF3E2E307E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.10.0","versionEndExcluding":"16.10.2","matchCriteriaId":"F66DCEFD-34BA-48AA-8154-D34480ADEF3B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.10.0","versionEndExcluding":"16.10.2","matchCriteriaId":"5D01A2BB-5343-4AF5-AAD0-9D3AB09C6CBE"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/433520","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2262450","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/433520","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2262450","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-6678","sourceIdentifier":"cve@gitlab.com","published":"2024-04-12T01:15:57.563","lastModified":"2026-06-17T06:51:13.570","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions before 16.8.6, all versions starting from 16.9 before 16.9.4, all versions starting from 16.10 before 16.10.2. It was possible for an attacker to cause a  denial of service using malicious crafted content in a junit test report file."},{"lang":"es","value":"Se descubrió un problema en GitLab EE que afecta a todas las versiones anteriores a 16.8.6, todas las versiones desde 16.9 anteriores a 16.9.4, todas las versiones desde 16.10 anteriores a 16.10.2. Era posible que un atacante provocara una denegación de servicio utilizando contenido diseñado maliciosamente en un archivo de informe de prueba junit."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"0","lessThan":"16.8.6","versionType":"semver","status":"affected"},{"version":"16.9","lessThan":"16.9.4","versionType":"semver","status":"affected"},{"version":"16.10","lessThan":"16.10.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-31T15:49:31.202587Z","id":"CVE-2023-6678","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1333"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-1333"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"16.8.6","matchCriteriaId":"44EA3B4E-8979-4BEC-9CB2-44C78FB1E37F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.9.0","versionEndExcluding":"16.9.4","matchCriteriaId":"CE07887F-4BE5-4269-9C3B-10CF3E2E307E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.10.0","versionEndExcluding":"16.10.2","matchCriteriaId":"5D01A2BB-5343-4AF5-AAD0-9D3AB09C6CBE"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/434689","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2268037","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/434689","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2268037","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-2279","sourceIdentifier":"cve@gitlab.com","published":"2024-04-12T01:15:57.750","lastModified":"2026-06-17T07:24:13.783","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.7 to 16.8.6 all versions starting from 16.9 before 16.9.4, all versions starting from 16.10 before 16.10.2. Using the autocomplete for issues references feature a crafted payload may lead to a stored XSS, allowing attackers to perform arbitrary actions on behalf of victims."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde 16.7 hasta 16.8.6, todas las versiones desde 16.9 anteriores a 16.9.4, todas las versiones desde 16.10 anteriores a 16.10.2. El uso de la función de autocompletar para referencias de problemas, un payload manipulado puede generar un XSS almacenado, lo que permite a los atacantes realizar acciones arbitrarias en nombre de las víctimas."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.7","lessThan":"16.8.6","versionType":"semver","status":"affected"},{"version":"16.9","lessThan":"16.9.4","versionType":"semver","status":"affected"},{"version":"16.10","lessThan":"16.10.2","versionType":"semver","status":"affected"}]}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","affectedData":[{"vendor":"gitlab","product":"gitlab","defaultStatus":"unknown","cpes":["cpe:2.3:a:gitlab:gitlab:16.7.0:*:*:*:community:*:*:*"],"versions":[{"version":"16.7.0","status":"affected"}]},{"vendor":"gitlab","product":"gitlab","defaultStatus":"unknown","cpes":["cpe:2.3:a:gitlab:gitlab:16.7.0:*:*:*:enterprise:*:*:*"],"versions":[{"version":"16.7.0","status":"affected"}]},{"vendor":"gitlab","product":"gitlab","defaultStatus":"unknown","cpes":["cpe:2.3:a:gitlab:gitlab:16.9.0:*:*:*:*:*:*:*"],"versions":[{"version":"16.9.0","status":"affected"}]},{"vendor":"gitlab","product":"gitlab","defaultStatus":"unknown","cpes":["cpe:2.3:a:gitlab:gitlab:-:*:*:*:-:*:*:*"],"versions":[{"version":"16.10","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-12-16T16:07:58.515255Z","id":"CVE-2024-2279","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.7.0","versionEndExcluding":"16.8.6","matchCriteriaId":"E736CD45-142B-4D8F-AAFA-D4CEDA8A9BA4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.7.0","versionEndExcluding":"16.8.6","matchCriteriaId":"37750CD6-1FA5-49CE-91AF-1A503738727D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.9.0","versionEndExcluding":"16.9.4","matchCriteriaId":"6C090961-541F-48DB-A98E-B7227E2BEF1E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.9.0","versionEndExcluding":"16.9.4","matchCriteriaId":"CE07887F-4BE5-4269-9C3B-10CF3E2E307E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.10.0","versionEndExcluding":"16.10.2","matchCriteriaId":"F66DCEFD-34BA-48AA-8154-D34480ADEF3B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.10.0","versionEndExcluding":"16.10.2","matchCriteriaId":"5D01A2BB-5343-4AF5-AAD0-9D3AB09C6CBE"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/448469","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/2404710","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/448469","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/2404710","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-3092","sourceIdentifier":"cve@gitlab.com","published":"2024-04-12T01:15:57.937","lastModified":"2026-06-17T07:43:17.693","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 before 16.9.4, all versions starting from 16.10 before 16.10.2. A payload may lead to a Stored XSS while using the diff viewer, allowing attackers to perform arbitrary actions on behalf of victims."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde 16.9 anteriores a 16.9.4, todas las versiones desde 16.10 anteriores a 16.10.2. Una carga útil puede generar un XSS almacenado mientras se usa el visor de diferencias, lo que permite a los atacantes realizar acciones arbitrarias en nombre de las víctimas."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.9","lessThan":"16.9.4","versionType":"semver","status":"affected"},{"version":"16.10","lessThan":"16.10.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-06-18T19:32:21.359708Z","id":"CVE-2024-3092","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.9.0","versionEndExcluding":"16.9.4","matchCriteriaId":"6C090961-541F-48DB-A98E-B7227E2BEF1E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.9.0","versionEndExcluding":"16.9.4","matchCriteriaId":"CE07887F-4BE5-4269-9C3B-10CF3E2E307E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.10.0","versionEndExcluding":"16.10.2","matchCriteriaId":"F66DCEFD-34BA-48AA-8154-D34480ADEF3B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.10.0","versionEndExcluding":"16.10.2","matchCriteriaId":"5D01A2BB-5343-4AF5-AAD0-9D3AB09C6CBE"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/452510","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/2441257","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/452510","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/2441257","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-1347","sourceIdentifier":"cve@gitlab.com","published":"2024-04-25T11:15:45.637","lastModified":"2026-06-17T07:04:01.923","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions before 16.9.6, all versions starting from 16.10 before 16.10.4, all versions starting from 16.11 before 16.11.1. Under certain conditions, an attacker through a crafted email address may be able to bypass domain based restrictions on an instance or a group."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones anteriores a 16.9.6, todas las versiones desde 16.10 anteriores a 16.10.4, todas las versiones desde 16.11 anteriores a 16.11.1. Bajo ciertas condiciones, un atacante a través de una dirección de correo electrónico manipulada puede eludir las restricciones basadas en el dominio en una instancia o grupo."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"0.0","lessThan":"16.9.6","versionType":"semver","status":"affected"},{"version":"16.10","lessThan":"16.10.4","versionType":"semver","status":"affected"},{"version":"16.11","lessThan":"16.11.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-04-29T18:56:32.766362Z","id":"CVE-2024-1347","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-290"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"16.9.6","matchCriteriaId":"2F0F0583-C3CF-434F-8ECF-5435FFC123FC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"16.9.6","matchCriteriaId":"9D88BF7B-8341-48C7-95B9-570908BC0898"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.10.0","versionEndExcluding":"16.10.4","matchCriteriaId":"A56BDD5E-E19A-4C96-BFA1-0C9C714BC1DF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.10.0","versionEndExcluding":"16.10.4","matchCriteriaId":"4DFA9764-53C9-46A5-904A-109E64CF5942"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.11.0:*:*:*:community:*:*:*","matchCriteriaId":"DBAF6CB8-EEBE-4F61-9B80-165C351748E2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.11.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"BEF58721-8679-4EA5-A353-4ED035241169"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/441093","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2355565","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/441093","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2355565","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-2434","sourceIdentifier":"cve@gitlab.com","published":"2024-04-25T11:15:45.870","lastModified":"2026-06-17T07:24:31.873","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions of GitLab CE/EE  16.9 prior to 16.9.6, 16.10 prior to 16.10.4, and 16.11 prior to 16.11.1 where path traversal could lead to DoS and restricted file read."},{"lang":"es","value":"Se descubrió un problema en GitLab que afecta a todas las versiones de GitLab CE/EE 16.9 anteriores a 16.9.6, 16.10 anteriores a 16.10.4 y 16.11 anteriores a 16.11.1, donde el path traversal podría provocar DoS y lectura restringida de archivos."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.9","lessThan":"16.9.6","versionType":"semver","status":"affected"},{"version":"16.10","lessThan":"16.10.4","versionType":"semver","status":"affected"},{"version":"16.11","lessThan":"16.11.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:H","baseScore":8.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.1,"impactScore":4.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-04-29T15:32:16.915592Z","id":"CVE-2024-2434","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-22"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-22"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.9.0","versionEndExcluding":"16.9.6","matchCriteriaId":"7029AA65-DD2A-4F64-B188-104801D4529F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.9.0","versionEndExcluding":"16.9.6","matchCriteriaId":"BB41F724-FD21-447E-81FC-D7362A759023"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.10.0","versionEndExcluding":"16.10.4","matchCriteriaId":"A56BDD5E-E19A-4C96-BFA1-0C9C714BC1DF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.10.0","versionEndExcluding":"16.10.4","matchCriteriaId":"4DFA9764-53C9-46A5-904A-109E64CF5942"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.11.0:*:*:*:community:*:*:*","matchCriteriaId":"DBAF6CB8-EEBE-4F61-9B80-165C351748E2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.11.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"BEF58721-8679-4EA5-A353-4ED035241169"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/450303","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/2401952","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/450303","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/2401952","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-2829","sourceIdentifier":"cve@gitlab.com","published":"2024-04-25T11:15:46.057","lastModified":"2026-06-17T07:25:38.277","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.5 before 16.9.6, all versions starting from 16.10 before 16.10.4, all versions starting from 16.11 before 16.11.1. A crafted wildcard filter in FileFinder may lead to a denial of service."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde 12.5 anteriores a 16.9.6, todas las versiones desde 16.10 anteriores a 16.10.4, todas las versiones desde 16.11 anteriores a 16.11.1. Un filtro comodín manipulado en FileFinder puede provocar una denegación de servicio."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"12.5","lessThan":"16.9.6","versionType":"semver","status":"affected"},{"version":"16.10","lessThan":"16.10.4","versionType":"semver","status":"affected"},{"version":"16.11","lessThan":"16.11.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-04-30T15:46:53.301518Z","id":"CVE-2024-2829","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1333"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-1333"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.5.0","versionEndExcluding":"16.9.6","matchCriteriaId":"534FACFA-F0A4-4884-B22A-15B720D22673"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.5.0","versionEndExcluding":"16.9.6","matchCriteriaId":"0BF12163-213C-4FAD-BA38-F31C777C3A95"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.10.0","versionEndExcluding":"16.10.4","matchCriteriaId":"A56BDD5E-E19A-4C96-BFA1-0C9C714BC1DF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.10.0","versionEndExcluding":"16.10.4","matchCriteriaId":"4DFA9764-53C9-46A5-904A-109E64CF5942"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.11.0:*:*:*:community:*:*:*","matchCriteriaId":"DBAF6CB8-EEBE-4F61-9B80-165C351748E2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.11.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"BEF58721-8679-4EA5-A353-4ED035241169"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/451456","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2416728","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/451456","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2416728","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-4006","sourceIdentifier":"cve@gitlab.com","published":"2024-04-25T14:15:09.667","lastModified":"2026-06-17T08:00:55.500","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.7 before 16.9.6, all versions starting from 16.10 before 16.10.4, all versions starting from 16.11 before 16.11.1 where personal access scopes were not honored by GraphQL subscriptions"},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde 16.7 anteriores a 16.9.6, todas las versiones desde 16.10 anteriores a 16.10.4, todas las versiones desde 16.11 anteriores a 16.11.1 donde las suscripciones a GraphQL no respetaban los alcances de acceso personal."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.7","lessThan":"16.9.6","versionType":"semver","status":"affected"},{"version":"16.10","lessThan":"16.10.4","versionType":"semver","status":"affected"},{"version":"16.11","lessThan":"16.11.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-04-25T15:49:20.284088Z","id":"CVE-2024-4006","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.7.0","versionEndExcluding":"16.9.6","matchCriteriaId":"C4191F1B-8E54-4667-AEA6-B1D779251966"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.7.0","versionEndExcluding":"16.9.6","matchCriteriaId":"25926890-C356-467C-9478-33FF423207C7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.10.0","versionEndExcluding":"16.10.4","matchCriteriaId":"A56BDD5E-E19A-4C96-BFA1-0C9C714BC1DF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.10.0","versionEndExcluding":"16.10.4","matchCriteriaId":"4DFA9764-53C9-46A5-904A-109E64CF5942"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.11.0:*:*:*:community:*:*:*","matchCriteriaId":"DBAF6CB8-EEBE-4F61-9B80-165C351748E2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.11.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"BEF58721-8679-4EA5-A353-4ED035241169"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/455805","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/455805","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking"]}]}},{"cve":{"id":"CVE-2024-4024","sourceIdentifier":"cve@gitlab.com","published":"2024-04-25T14:15:09.903","lastModified":"2026-06-17T08:00:57.487","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 7.8 before 16.9.6, all versions starting from 16.10 before 16.10.4, all versions starting from 16.11 before 16.11.1. Under certain conditions, an attacker with their Bitbucket account credentials may be able to take over a GitLab account linked to another user's Bitbucket account, if Bitbucket is used as an OAuth 2.0 provider on GitLab."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde 7.8 anteriores a 16.9.6, todas las versiones desde 16.10 anteriores a 16.10.4, todas las versiones desde 16.11 anteriores a 16.11.1. Bajo ciertas condiciones, un atacante con las credenciales de su cuenta Bitbucket puede hacerse cargo de una cuenta GitLab vinculada a la cuenta Bitbucket de otro usuario, si Bitbucket se utiliza como proveedor de OAuth 2.0 en GitLab."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"7.8","lessThan":"16.9.6","versionType":"semver","status":"affected"},{"version":"16.10","lessThan":"16.10.4","versionType":"semver","status":"affected"},{"version":"16.11","lessThan":"16.11.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-09-17T15:39:02.768615Z","id":"CVE-2024-4024","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-302"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-287"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"7.8.0","versionEndExcluding":"16.9.6","matchCriteriaId":"32475C70-91C2-4615-A3C6-B279F6704CD9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"7.8.0","versionEndExcluding":"16.9.6","matchCriteriaId":"6D6034DD-EE5F-4BB2-AF5B-F2CBCE28D7FF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.10.0","versionEndExcluding":"16.10.4","matchCriteriaId":"A56BDD5E-E19A-4C96-BFA1-0C9C714BC1DF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.10.0","versionEndExcluding":"16.10.4","matchCriteriaId":"4DFA9764-53C9-46A5-904A-109E64CF5942"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.11.0:*:*:*:community:*:*:*","matchCriteriaId":"DBAF6CB8-EEBE-4F61-9B80-165C351748E2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.11.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"BEF58721-8679-4EA5-A353-4ED035241169"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/452426","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/452426","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking"]}]}},{"cve":{"id":"CVE-2023-6682","sourceIdentifier":"cve@gitlab.com","published":"2024-05-14T14:35:29.810","lastModified":"2026-06-17T06:51:14.077","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. A problem with the processing logic for Discord Integrations Chat Messages can lead to a regular expression DoS attack on the server."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde la 16.9 anterior a la 16.9.7, desde la 16.10 anterior a la 16.10.5 y desde la 16.11 anterior a la 16.11.2. Un problema con la lógica de procesamiento de los mensajes de chat de Discord Integrations puede provocar un ataque DoS de expresión regular en el servidor."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.9","lessThan":"16.9.7","versionType":"semver","status":"affected"},{"version":"16.10","lessThan":"16.10.5","versionType":"semver","status":"affected"},{"version":"16.11","lessThan":"16.11.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-05-09T18:11:04.571547Z","id":"CVE-2023-6682","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1333"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-1333"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.9.0","versionEndExcluding":"16.9.7","matchCriteriaId":"E00930AE-6064-4933-8939-D31D46F35523"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.9.0","versionEndExcluding":"16.9.7","matchCriteriaId":"F6A4875C-5D97-4E5A-9ED8-3A09721C9ECE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.10.0","versionEndExcluding":"16.10.5","matchCriteriaId":"356482CA-C9DF-418B-BBDF-C6C09CA8C16D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.10.0","versionEndExcluding":"16.10.5","matchCriteriaId":"154184A5-A34D-4DB1-85B4-DE47A3723E6B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.11.0","versionEndExcluding":"16.11.2","matchCriteriaId":"9B50E4E6-602E-470D-BB03-774CFB1461B6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.11.0","versionEndExcluding":"16.11.2","matchCriteriaId":"5ACCB718-2ABE-4F1A-AB57-B2D3B4879FAC"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/434821","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2269012","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/434821","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2269012","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-6688","sourceIdentifier":"cve@gitlab.com","published":"2024-05-14T14:35:33.147","lastModified":"2026-06-17T06:51:14.570","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.11 prior to 16.11.2. A problem with the processing logic for Google Chat Messages integration may lead to a regular expression DoS attack on the server."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde la 16.11 hasta la 16.11.2. Un problema con la lógica de procesamiento para la integración de mensajes de chat de Google puede provocar un ataque DoS de expresión regular en el servidor."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.11","lessThan":"16.11.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-19T12:35:37.594372Z","id":"CVE-2023-6688","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1333"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-1333"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.11.0","versionEndExcluding":"16.11.2","matchCriteriaId":"9B50E4E6-602E-470D-BB03-774CFB1461B6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.11.0","versionEndExcluding":"16.11.2","matchCriteriaId":"5ACCB718-2ABE-4F1A-AB57-B2D3B4879FAC"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/434854","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2270362","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/434854","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2270362","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-2454","sourceIdentifier":"cve@gitlab.com","published":"2024-05-14T15:19:23.420","lastModified":"2026-06-17T07:24:34.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.11 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. The pins endpoint is susceptible to DoS through a crafted request."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde la 15.11 anterior a la 16.9.7, desde la 16.10 anterior a la 16.10.5 y desde la 16.11 anterior a la 16.11.2. El endpoint de los pines es susceptible a DoS a través de una solicitud manipulada."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.11","lessThan":"16.9.7","versionType":"semver","status":"affected"},{"version":"16.10","lessThan":"16.10.5","versionType":"semver","status":"affected"},{"version":"16.11","lessThan":"16.11.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-05-09T16:07:54.688170Z","id":"CVE-2024-2454","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.11.0","versionEndExcluding":"16.9.7","matchCriteriaId":"2F237063-B034-44C6-90DA-DBD19E201B03"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.11.0","versionEndExcluding":"16.9.7","matchCriteriaId":"8A966C42-F55A-489A-8EB7-F17BF9715104"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.10.0","versionEndExcluding":"16.10.5","matchCriteriaId":"356482CA-C9DF-418B-BBDF-C6C09CA8C16D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.10.0","versionEndExcluding":"16.10.5","matchCriteriaId":"154184A5-A34D-4DB1-85B4-DE47A3723E6B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.11.0","versionEndExcluding":"16.11.2","matchCriteriaId":"9B50E4E6-602E-470D-BB03-774CFB1461B6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.11.0","versionEndExcluding":"16.11.2","matchCriteriaId":"5ACCB718-2ABE-4F1A-AB57-B2D3B4879FAC"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/450405","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2408226","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/450405","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2408226","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-2651","sourceIdentifier":"cve@gitlab.com","published":"2024-05-14T15:20:14.557","lastModified":"2026-06-17T07:24:58.297","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions before 16.9.7, all versions starting from 16.10 before 16.10.5, all versions starting from 16.11 before 16.11.2. It was possible for an attacker to cause a denial of service using maliciously crafted markdown content."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones anteriores a 16.9.7, todas las versiones desde 16.10 anteriores a 16.10.5, todas las versiones desde 16.11 anteriores a 16.11.2. Era posible que un atacante provocara una denegación de servicio utilizando contenido de rebajas creado con fines malintencionados."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"0.0","lessThan":"16.9.7","versionType":"semver","status":"affected"},{"version":"16.10","lessThan":"16.10.5","versionType":"semver","status":"affected"},{"version":"16.11","lessThan":"16.11.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-05-20T17:13:42.781717Z","id":"CVE-2024-2651","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1333"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-1333"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"16.9.7","matchCriteriaId":"21470D80-9A00-42E9-B092-2DDFC104ADE3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"16.9.7","matchCriteriaId":"2D9021EA-57C4-4E0C-9365-1B3835EDABB6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.10.0","versionEndExcluding":"16.10.5","matchCriteriaId":"356482CA-C9DF-418B-BBDF-C6C09CA8C16D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.10.0","versionEndExcluding":"16.10.5","matchCriteriaId":"154184A5-A34D-4DB1-85B4-DE47A3723E6B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.11.0","versionEndExcluding":"16.11.2","matchCriteriaId":"9B50E4E6-602E-470D-BB03-774CFB1461B6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.11.0","versionEndExcluding":"16.11.2","matchCriteriaId":"5ACCB718-2ABE-4F1A-AB57-B2D3B4879FAC"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/450830","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2408619","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/450830","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2408619","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-4539","sourceIdentifier":"cve@gitlab.com","published":"2024-05-14T15:44:01.527","lastModified":"2026-06-17T08:02:06.033","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2 where abusing the API to filter branch and tags could lead to Denial of Service."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde la 15.4 anterior a la 16.9.7, desde la 16.10 anterior a la 16.10.5 y desde la 16.11 anterior a la 16.11.2, donde se podría abusar de la API para filtrar ramas y etiquetas. conducir a la denegación del servicio."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.4","lessThan":"16.9.7","versionType":"semver","status":"affected"},{"version":"16.10","lessThan":"16.10.5","versionType":"semver","status":"affected"},{"version":"16.11","lessThan":"16.11.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-05-10T18:35:30.951540Z","id":"CVE-2024-4539","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.4.0","versionEndExcluding":"16.9.7","matchCriteriaId":"3094F55B-4C1D-48D2-ACD8-1BDC951DABE4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.4.0","versionEndExcluding":"16.9.7","matchCriteriaId":"C52FD6D5-F8B9-404D-ACAE-AF440A5579C0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.10.0","versionEndExcluding":"16.10.5","matchCriteriaId":"356482CA-C9DF-418B-BBDF-C6C09CA8C16D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.10.0","versionEndExcluding":"16.10.5","matchCriteriaId":"154184A5-A34D-4DB1-85B4-DE47A3723E6B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.11.0","versionEndExcluding":"16.11.2","matchCriteriaId":"9B50E4E6-602E-470D-BB03-774CFB1461B6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.11.0","versionEndExcluding":"16.11.2","matchCriteriaId":"5ACCB718-2ABE-4F1A-AB57-B2D3B4879FAC"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/454815","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/454815","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2024-4597","sourceIdentifier":"cve@gitlab.com","published":"2024-05-14T15:44:10.553","lastModified":"2026-06-17T08:02:14.137","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions from 16.7 before 16.9.7, all versions starting from 16.10 before 16.10.5, all versions starting from 16.11 before 16.11.2. An attacker could force a user with an active SAML session to approve an MR via CSRF."},{"lang":"es","value":"Se descubrió un problema en GitLab EE que afecta a todas las versiones desde 16.7 anteriores a 16.9.7, todas las versiones desde 16.10 anteriores a 16.10.5, todas las versiones desde 16.11 anteriores a 16.11.2. Un atacante podría obligar a un usuario con una sesión SAML activa a aprobar un MR a través de CSRF."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.7","lessThan":"16.9.7","versionType":"semver","status":"affected"},{"version":"16.10","lessThan":"16.10.5","versionType":"semver","status":"affected"},{"version":"16.11","lessThan":"16.11.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N","baseScore":5.7,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-06-12T19:33:41.245512Z","id":"CVE-2024-4597","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-352"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-352"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.7.0","versionEndExcluding":"16.9.7","matchCriteriaId":"F052A7A7-E530-4789-B8C8-395AFCEE5228"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.7.0","versionEndExcluding":"16.9.7","matchCriteriaId":"85DDC976-6AD3-42F6-BE89-1AD00C37BEDE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.10.0","versionEndExcluding":"16.10.5","matchCriteriaId":"356482CA-C9DF-418B-BBDF-C6C09CA8C16D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.10.0","versionEndExcluding":"16.10.5","matchCriteriaId":"154184A5-A34D-4DB1-85B4-DE47A3723E6B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.11.0","versionEndExcluding":"16.11.2","matchCriteriaId":"9B50E4E6-602E-470D-BB03-774CFB1461B6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.11.0","versionEndExcluding":"16.11.2","matchCriteriaId":"5ACCB718-2ABE-4F1A-AB57-B2D3B4879FAC"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/438686","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/438686","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2024-2874","sourceIdentifier":"cve@gitlab.com","published":"2024-05-23T07:15:08.463","lastModified":"2026-06-17T07:25:43.840","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions before 16.10.6, version 16.11 before 16.11.3, and 17.0 before 17.0.1. A runner registered with a crafted description has the potential to disrupt the loading of targeted GitLab web resources."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones anteriores a 16.10.6, la versión 16.11 anterior a 16.11.3 y la 17.0 anterior a 17.0.1. Un ejecutor registrado con una descripción manipulada tiene el potencial de interrumpir la carga de recursos web de GitLab específicos."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"0","lessThan":"16.10.6","versionType":"semver","status":"affected"},{"version":"16.11","lessThan":"16.11.3","versionType":"semver","status":"affected"},{"version":"17.0","lessThan":"17.0.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-05-23T16:32:54.315166Z","id":"CVE-2024-2874","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"16.10.6","matchCriteriaId":"D32468B2-9ED8-4D66-90E3-DC5F9CAEB1A3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"16.10.6","matchCriteriaId":"75F6F9C5-BA57-4BB3-851E-A771C0562683"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.11.0","versionEndExcluding":"16.11.3","matchCriteriaId":"D2461BDD-0006-45A1-B49B-1761CC52BD04"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.11.0","versionEndExcluding":"16.11.3","matchCriteriaId":"B9E351A7-5B4B-4043-8EC2-D9B58488ACE3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.0.0:*:*:*:community:*:*:*","matchCriteriaId":"4B294023-4020-405B-907C-F7F20DFAD3A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"5881525D-CFD4-43AA-9B1E-8C1221772BC3"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/451911","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/2426166","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/451911","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/2426166","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-4835","sourceIdentifier":"cve@gitlab.com","published":"2024-05-23T07:15:09.683","lastModified":"2026-06-17T08:03:00.957","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A XSS condition exists within GitLab in versions 15.11 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1. By leveraging this condition, an attacker can craft a malicious page to exfiltrate sensitive user information."},{"lang":"es","value":"Existe una condición XSS dentro de GitLab en las versiones 15.11 anteriores a 16.10.6, 16.11 anteriores a 16.11.3 y 17.0 anteriores a 17.0.1. Al aprovechar esta condición, un atacante puede crear una página maliciosa para extraer información confidencial del usuario."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.11","lessThan":"16.10.6","versionType":"semver","status":"affected"},{"version":"16.11","lessThan":"16.11.3","versionType":"semver","status":"affected"},{"version":"17.0","lessThan":"17.0.1","versionType":"semver","status":"affected"}]}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","affectedData":[{"vendor":"gitlab","product":"gitlab","defaultStatus":"affected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"versions":[{"version":"15.11","lessThan":"17.0.1","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N","baseScore":8.0,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N","baseScore":8.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":4.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-06-14T22:44:25.509681Z","id":"CVE-2024-4835","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.11.0","versionEndExcluding":"16.10.6","matchCriteriaId":"43BE75CB-B680-431E-A07E-093558211217"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.11.0","versionEndExcluding":"16.10.6","matchCriteriaId":"4113907A-DF93-4FCF-BA99-57B43952BDE2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.11.0","versionEndExcluding":"16.11.3","matchCriteriaId":"D2461BDD-0006-45A1-B49B-1761CC52BD04"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.11.0","versionEndExcluding":"16.11.3","matchCriteriaId":"B9E351A7-5B4B-4043-8EC2-D9B58488ACE3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.0.0:*:*:*:community:*:*:*","matchCriteriaId":"4B294023-4020-405B-907C-F7F20DFAD3A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"5881525D-CFD4-43AA-9B1E-8C1221772BC3"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/461328","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/2497024","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/461328","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/2497024","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-6502","sourceIdentifier":"cve@gitlab.com","published":"2024-05-23T11:15:22.913","lastModified":"2026-06-17T06:50:52.340","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions before 16.10.6, version 16.11 before 16.11.3, and 17.0 before 17.0.1. It is possible for an attacker to cause a denial of service using a crafted wiki page."},{"lang":"es","value":"Se descubrió una condición de denegación de servicio (DoS) en GitLab CE/EE que afecta a todas las versiones anteriores a 16.10.6, a la versión 16.11 anterior a 16.11.3 y a 17.0 anterior a 17.0.1. Es posible que un atacante provoque una denegación de servicio utilizando una página wiki manipulada."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"0","lessThan":"16.10.6","versionType":"semver","status":"affected"},{"version":"16.11","lessThan":"16.11.3","versionType":"semver","status":"affected"},{"version":"17.0","lessThan":"17.0.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-05-23T15:40:39.910701Z","id":"CVE-2023-6502","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1333"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-1333"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"16.10.6","matchCriteriaId":"D32468B2-9ED8-4D66-90E3-DC5F9CAEB1A3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"16.10.6","matchCriteriaId":"75F6F9C5-BA57-4BB3-851E-A771C0562683"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.11.0","versionEndExcluding":"16.11.3","matchCriteriaId":"D2461BDD-0006-45A1-B49B-1761CC52BD04"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.11.0","versionEndExcluding":"16.11.3","matchCriteriaId":"B9E351A7-5B4B-4043-8EC2-D9B58488ACE3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.0.0:*:*:*:community:*:*:*","matchCriteriaId":"4B294023-4020-405B-907C-F7F20DFAD3A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"5881525D-CFD4-43AA-9B1E-8C1221772BC3"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/433534","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2263638","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/433534","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2263638","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-7045","sourceIdentifier":"cve@gitlab.com","published":"2024-05-23T11:15:23.153","lastModified":"2026-06-17T06:51:56.800","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A CSRF vulnerability exists within GitLab CE/EE from versions 13.11 before 16.10.6, from 16.11 before 16.11.3, from 17.0 before 17.0.1. By leveraging this vulnerability, an attacker could exfiltrate anti-CSRF tokens via the Kubernetes Agent Server (KAS)."},{"lang":"es","value":"Existe una vulnerabilidad CSRF en GitLab CE/EE desde las versiones 13.11 anteriores a 16.10.6, desde 16.11 anteriores a 16.11.3, desde 17.0 anteriores a 17.0.1. Al aprovechar esta vulnerabilidad, un atacante podría filtrar tokens anti-CSRF a través del servidor de agentes de Kubernetes (KAS)."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"13.11","lessThan":"16.10.6","versionType":"semver","status":"affected"},{"version":"16.11","lessThan":"16.11.3","versionType":"semver","status":"affected"},{"version":"17.0","lessThan":"17.0.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-05-23T14:50:21.010294Z","id":"CVE-2023-7045","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-352"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-352"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.11.0","versionEndExcluding":"16.10.6","matchCriteriaId":"7C109B28-2948-472D-85D9-968E938DFA2C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.11.0","versionEndExcluding":"16.10.6","matchCriteriaId":"0B1A9998-BC62-4E8E-B1A9-4BC43650FC3C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.11.0","versionEndExcluding":"16.11.3","matchCriteriaId":"D2461BDD-0006-45A1-B49B-1761CC52BD04"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.11.0","versionEndExcluding":"16.11.3","matchCriteriaId":"B9E351A7-5B4B-4043-8EC2-D9B58488ACE3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.0.0:*:*:*:community:*:*:*","matchCriteriaId":"4B294023-4020-405B-907C-F7F20DFAD3A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"5881525D-CFD4-43AA-9B1E-8C1221772BC3"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/436358","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/2286823","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/436358","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/2286823","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-1947","sourceIdentifier":"cve@gitlab.com","published":"2024-05-23T11:15:23.817","lastModified":"2026-06-17T07:05:28.700","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A denial of service (DoS) condition was discovered in GitLab CE/EE affecting all versions from 13.2.4 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1. By leveraging this vulnerability an attacker could create a DoS condition by sending crafted API calls."},{"lang":"es","value":"Se descubrió una condición de denegación de servicio (DoS) en GitLab CE/EE que afecta a todas las versiones desde 13.2.4 anterior a 16.10.6, 16.11 anterior a 16.11.3 y 17.0 anterior a 17.0.1. Al aprovechar esta vulnerabilidad, un atacante podría crear una condición DoS enviando llamadas API manipuladas."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"13.2.4","lessThan":"16.10.6","versionType":"semver","status":"affected"},{"version":"16.11","lessThan":"16.11.3","versionType":"semver","status":"affected"},{"version":"17.0","lessThan":"17.0.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-05-23T15:41:47.064897Z","id":"CVE-2024-1947","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-409"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.2.4","versionEndExcluding":"16.10.6","matchCriteriaId":"59891429-A033-4D0E-85D2-95F22913E580"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.2.4","versionEndExcluding":"16.10.6","matchCriteriaId":"5DAF8695-E61A-4427-BFC4-CA055DB18F55"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.11.0","versionEndExcluding":"16.11.3","matchCriteriaId":"D2461BDD-0006-45A1-B49B-1761CC52BD04"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.11.0","versionEndExcluding":"16.11.3","matchCriteriaId":"B9E351A7-5B4B-4043-8EC2-D9B58488ACE3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.0.0:*:*:*:community:*:*:*","matchCriteriaId":"4B294023-4020-405B-907C-F7F20DFAD3A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"5881525D-CFD4-43AA-9B1E-8C1221772BC3"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/443559","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2380264","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/443559","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2380264","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-5258","sourceIdentifier":"cve@gitlab.com","published":"2024-05-23T11:15:24.640","lastModified":"2026-06-17T08:15:33.343","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An authorization vulnerability exists within GitLab from versions 16.10 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1 where an authenticated attacker could utilize a crafted naming convention to bypass pipeline authorization logic."},{"lang":"es","value":"Existe una vulnerabilidad de autorización dentro de GitLab desde las versiones 16.10 anteriores a 16.10.6, 16.11 anteriores a 16.11.3 y 17.0 anteriores a 17.0.1 donde un atacante autenticado podría utilizar una convención de nomenclatura manipulada para evitar la lógica de autorización de canalización."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.10","lessThan":"16.10.6","versionType":"semver","status":"affected"},{"version":"16.11","lessThan":"16.11.3","versionType":"semver","status":"affected"},{"version":"17.0","lessThan":"17.0.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":4.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.3,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-05-23T15:44:35.324534Z","id":"CVE-2024-5258","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-639"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.10.0","versionEndExcluding":"16.10.6","matchCriteriaId":"EAAA2890-973F-4EC9-B9D2-AB3F9B028582"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.10.0","versionEndExcluding":"16.10.6","matchCriteriaId":"CAE5E3DC-30AC-4DE2-B173-9326C372126D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.11.0","versionEndExcluding":"16.11.3","matchCriteriaId":"D2461BDD-0006-45A1-B49B-1761CC52BD04"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.11.0","versionEndExcluding":"16.11.3","matchCriteriaId":"B9E351A7-5B4B-4043-8EC2-D9B58488ACE3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.0.0:*:*:*:community:*:*:*","matchCriteriaId":"4B294023-4020-405B-907C-F7F20DFAD3A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"5881525D-CFD4-43AA-9B1E-8C1221772BC3"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/443254","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/443254","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking"]}]}},{"cve":{"id":"CVE-2024-5318","sourceIdentifier":"cve@gitlab.com","published":"2024-05-24T13:15:09.717","lastModified":"2026-06-17T08:15:41.470","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.11 prior to 16.10.6, starting from 16.11 prior to 16.11.3, and starting from 17.0 prior to 17.0.1. A Guest user can view dependency lists of private projects through job artifacts."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde la 11.11 anterior a la 16.10.6, desde la 16.11 anterior a la 16.11.3 y desde la 17.0 anterior a la 17.0.1. Un usuario invitado puede ver listas de dependencias de proyectos privados a través de artefactos de trabajo."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"11.11","lessThan":"16.10.6","versionType":"semver","status":"affected"},{"version":"16.11","lessThan":"16.11.3","versionType":"semver","status":"affected"},{"version":"17.0","lessThan":"17.0.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":4.0,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.5,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-05-24T19:20:30.633108Z","id":"CVE-2024-5318","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.11.0","versionEndExcluding":"16.10.6","matchCriteriaId":"4B910C1D-71E0-46EA-9C15-4C017A0B9237"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.11.0","versionEndExcluding":"16.10.6","matchCriteriaId":"B638E37D-3D57-4A32-B839-3C9F6A23A701"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.11.0","versionEndExcluding":"16.11.3","matchCriteriaId":"D2461BDD-0006-45A1-B49B-1761CC52BD04"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.11.0","versionEndExcluding":"16.11.3","matchCriteriaId":"B9E351A7-5B4B-4043-8EC2-D9B58488ACE3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.0.0:*:*:*:community:*:*:*","matchCriteriaId":"4B294023-4020-405B-907C-F7F20DFAD3A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"5881525D-CFD4-43AA-9B1E-8C1221772BC3"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/427526","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/2189464","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/427526","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/2189464","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-1495","sourceIdentifier":"cve@gitlab.com","published":"2024-06-12T23:15:49.130","lastModified":"2026-06-17T07:04:22.110","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.1 prior to 16.10.7, starting from 16.11 prior to 16.11.4, and starting from 17.0 prior to 17.0.2. It was possible for an attacker to cause a denial of service using maliciously crafted file."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde 13.1 anterior a 16.10.7, desde 16.11 anterior a 16.11.4 y desde 17.0 anterior a 17.0.2. Era posible que un atacante provocara una denegación de servicio utilizando un archivo creado con fines malintencionados."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"13.1","lessThan":"16.10.7","versionType":"semver","status":"affected"},{"version":"16.11","lessThan":"16.11.4","versionType":"semver","status":"affected"},{"version":"17.0","lessThan":"17.0.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-06-13T17:17:33.695191Z","id":"CVE-2024-1495","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1333"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-1333"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.1","versionEndExcluding":"16.10.7","matchCriteriaId":"7485B3C5-13AF-4E47-80A0-7202B47897B7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.1","versionEndExcluding":"16.10.7","matchCriteriaId":"91B5A81A-D0F7-4E7D-89F8-F0AE663AEB94"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.11.0","versionEndExcluding":"16.11.4","matchCriteriaId":"A15CE466-B5D8-459C-A22F-77939534C887"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.11.0","versionEndExcluding":"16.11.4","matchCriteriaId":"060AB697-23A0-4EE8-9D7E-D44A2B1D8FC3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"17.0.2","matchCriteriaId":"A0182874-BBFB-467F-9850-C29C4890AB4D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"17.0.2","matchCriteriaId":"D9165657-47FB-42AB-8D7D-0556F342C296"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2024/06/12/patch-release-gitlab-17-0-2-released/#redos-in-gomod-dependency-linker","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/441807","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://hackerone.com/reports/2359528","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://about.gitlab.com/releases/2024/06/12/patch-release-gitlab-17-0-2-released/#redos-in-gomod-dependency-linker","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/441807","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://hackerone.com/reports/2359528","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2024-1736","sourceIdentifier":"cve@gitlab.com","published":"2024-06-12T23:15:49.440","lastModified":"2026-06-17T07:04:53.870","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions prior to 16.10.7, starting from 16.11 prior to 16.11.4, and starting from 17.0 prior to 17.0.2. A vulnerability in GitLab's CI/CD pipeline editor could allow for denial of service attacks through maliciously crafted configuration files."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones anteriores a 16.10.7, desde 16.11 anterior a 16.11.4 y desde 17.0 anterior a 17.0.2. Una vulnerabilidad en el editor de canalización CI/CD de GitLab podría permitir ataques de denegación de servicio a través de archivos de configuración creados con fines malintencionados."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.8","lessThan":"16.10.7","versionType":"semver","status":"affected"},{"version":"16.11","lessThan":"16.11.4","versionType":"semver","status":"affected"},{"version":"17.0","lessThan":"17.0.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-06-13T18:13:46.693717Z","id":"CVE-2024-1736","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1333"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-1333"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"16.10.7","matchCriteriaId":"77D058AE-3526-47AC-91F7-A183328674E8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"16.10.7","matchCriteriaId":"51DA248E-6E16-4895-A173-C56F16731C84"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.11.0","versionEndExcluding":"16.11.4","matchCriteriaId":"A15CE466-B5D8-459C-A22F-77939534C887"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.11.0","versionEndExcluding":"16.11.4","matchCriteriaId":"060AB697-23A0-4EE8-9D7E-D44A2B1D8FC3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"17.0.2","matchCriteriaId":"A0182874-BBFB-467F-9850-C29C4890AB4D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"17.0.2","matchCriteriaId":"D9165657-47FB-42AB-8D7D-0556F342C296"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2024/06/12/patch-release-gitlab-17-0-2-released/#redos-in-ci-interpolation-fix-bypass","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/442695","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://hackerone.com/reports/2358689","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://about.gitlab.com/releases/2024/06/12/patch-release-gitlab-17-0-2-released/#redos-in-ci-interpolation-fix-bypass","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/442695","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://hackerone.com/reports/2358689","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2024-1963","sourceIdentifier":"cve@gitlab.com","published":"2024-06-12T23:15:49.670","lastModified":"2026-06-17T07:05:30.883","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.4 prior to 16.10.7, starting from 16.11 prior to 16.11.4, and starting from 17.0 prior to 17.0.2. A vulnerability in GitLab's Asana integration allowed an attacker to potentially cause a regular expression denial of service by sending specially crafted requests."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde 8.4 anterior a 16.10.7, desde 16.11 anterior a 16.11.4 y desde 17.0 anterior a 17.0.2. Una vulnerabilidad en la integración de Asana de GitLab permitió a un atacante causar potencialmente una denegación de servicio de expresión regular mediante el envío de solicitudes especialmente manipuladas."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"8.4","lessThan":"16.10.7","versionType":"semver","status":"affected"},{"version":"16.11","lessThan":"16.11.4","versionType":"semver","status":"affected"},{"version":"17.0","lessThan":"17.0.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-10T15:05:59.136358Z","id":"CVE-2024-1963","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1333"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-1333"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.4","versionEndExcluding":"16.10.7","matchCriteriaId":"21BD332B-735B-4EF5-A0C9-539E0CBF75EF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.4","versionEndExcluding":"16.10.7","matchCriteriaId":"78EB3431-4047-4B0F-A956-965645EE5B6C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.11.0","versionEndExcluding":"16.11.4","matchCriteriaId":"A15CE466-B5D8-459C-A22F-77939534C887"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.11.0","versionEndExcluding":"16.11.4","matchCriteriaId":"060AB697-23A0-4EE8-9D7E-D44A2B1D8FC3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.0","versionEndIncluding":"17.0.2","matchCriteriaId":"66A698AD-9FA9-47A8-BDF1-DA99626BDE64"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.0","versionEndExcluding":"17.0.2","matchCriteriaId":"CB78DC03-D9FD-4D08-9D8C-3E992CF246F5"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2024/06/12/patch-release-gitlab-17-0-2-released/#redos-in-asana-integration-issue-mapping-when-webhook-is-called","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/443577","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://hackerone.com/reports/2376482","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://about.gitlab.com/releases/2024/06/12/patch-release-gitlab-17-0-2-released/#redos-in-asana-integration-issue-mapping-when-webhook-is-called","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/443577","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://hackerone.com/reports/2376482","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2024-4201","sourceIdentifier":"cve@gitlab.com","published":"2024-06-12T23:15:49.887","lastModified":"2026-06-17T08:01:19.180","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 before 16.10.7, all versions starting from 16.11 before 16.111.4, all versions starting from 17.0 before 17.0.2. When viewing an XML file in a repository in raw mode, it can be made to render as HTML if viewed under specific circumstances."},{"lang":"es","value":"Se descubrió un problema de cross-site scripting en GitLab que afecta a todas las versiones desde 5.1 anteriores a 16.10.7, todas las versiones desde 16.11 anteriores a 16.111.4, todas las versiones desde 17.0 anteriores a 17.0.2. Al visualizar un archivo XML en un repositorio en modo sin formato, se puede hacer que se represente como HTML si se ve en circunstancias específicas."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"5.1","lessThan":"16.10.7","versionType":"semver","status":"affected"},{"version":"16.11","lessThan":"16.11.4","versionType":"semver","status":"affected"},{"version":"17.0","lessThan":"17.0.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":4.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.3,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":4.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-06-14T19:18:43.100514Z","id":"CVE-2024-4201","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"5.1","versionEndExcluding":"16.10.7","matchCriteriaId":"A3B5490D-4A8C-4F9F-810A-59979BE2D892"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"5.1","versionEndExcluding":"16.10.7","matchCriteriaId":"2E166198-556D-4D69-B39E-DDCF2849BEC9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.11.0","versionEndExcluding":"16.111.4","matchCriteriaId":"541F26D8-667C-4826-AC9D-334A76B4C9F2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.11.0","versionEndExcluding":"16.111.4","matchCriteriaId":"6DF27F17-916C-44ED-A038-5199A875F163"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"17.0.2","matchCriteriaId":"A0182874-BBFB-467F-9850-C29C4890AB4D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"17.0.2","matchCriteriaId":"D9165657-47FB-42AB-8D7D-0556F342C296"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2024/06/12/patch-release-gitlab-17-0-2-released/#xss-and-content-injection-when-viewing-raw-xhtml-files-on-ios-devices","source":"cve@gitlab.com","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/458229","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://hackerone.com/reports/2473886","source":"cve@gitlab.com","tags":["Third Party Advisory"]},{"url":"https://about.gitlab.com/releases/2024/06/12/patch-release-gitlab-17-0-2-released/#xss-and-content-injection-when-viewing-raw-xhtml-files-on-ios-devices","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/458229","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://hackerone.com/reports/2473886","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2024-5469","sourceIdentifier":"cve@gitlab.com","published":"2024-06-14T04:15:43.120","lastModified":"2026-06-17T08:16:00.707","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"DoS in KAS in GitLab CE/EE affecting all versions from 16.10.0 prior to 16.10.6 and 16.11.0 prior to 16.11.3 allows an attacker to crash KAS via crafted gRPC requests."},{"lang":"es","value":"DoS en KAS en GitLab CE/EE que afecta a todas las versiones desde 16.10.0 anteriores a 16.10.6 y 16.11.0 anteriores a 16.11.3 permite a un atacante bloquear KAS mediante solicitudes gRPC manipuladas."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.10.0","lessThan":"16.10.6","versionType":"semver","status":"affected"},{"version":"16.11.0","lessThan":"16.11.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":3.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":1.6,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-06-15T20:48:54.336447Z","id":"CVE-2024-5469","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-754"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-754"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"16.10.0","versionEndExcluding":"16.10.6","matchCriteriaId":"9C0B2362-F126-44C0-B049-8A40522FC949"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"16.11.0","versionEndExcluding":"16.11.3","matchCriteriaId":"95B514BD-6B3E-4654-85FE-162DC4E07121"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/464143","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/464143","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2024-1493","sourceIdentifier":"cve@gitlab.com","published":"2024-06-27T00:15:10.283","lastModified":"2026-06-17T07:04:21.980","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab CE/EE affecting all versions starting from 9.2 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, with the processing logic for generating link in dependency files can lead to a regular  expression DoS attack on the server"},{"lang":"es","value":" Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde la 9.2 anterior a la 16.11.5, desde la 17.0 anterior a la 17.0.3 y desde la 17.1 anterior a la 17.1.1, con la lógica de procesamiento para generar enlaces en archivos de dependencia puede provocar un ataque DoS de expresión regular en el servidor"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"9.2","lessThan":"16.11.5","versionType":"semver","status":"affected"},{"version":"17.0","lessThan":"17.0.3","versionType":"semver","status":"affected"},{"version":"17.1","lessThan":"17.1.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-06-27T18:20:24.801000Z","id":"CVE-2024-1493","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1333"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-1333"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"9.2.0","versionEndExcluding":"16.11.5","matchCriteriaId":"094ACB9D-124C-49F8-A3D6-4DBFCC962BB9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"9.2.0","versionEndExcluding":"16.11.5","matchCriteriaId":"3A3396AE-9030-4C02-955F-62A6AF04702A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"17.0.3","matchCriteriaId":"541958DE-CB05-43D9-921B-4ADD2E436BF7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"17.0.3","matchCriteriaId":"C987EC42-A56B-462A-A0CE-7417CC0FD414"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.1.0:*:*:*:community:*:*:*","matchCriteriaId":"D2461A15-EA5F-43D1-B359-0F24713A713B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"9AA7835D-35E6-44D6-9194-2AC4C38961CE"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/441806","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2370084","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/441806","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2370084","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-1816","sourceIdentifier":"cve@gitlab.com","published":"2024-06-27T00:15:10.523","lastModified":"2026-06-17T07:05:04.407","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab CE/EE affecting all versions starting from 12.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows for an attacker to cause a denial of service using a crafted OpenAPI file."},{"lang":"es","value":" Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde 12.0 anterior a 16.11.5, desde 17.0 anterior a 17.0.3 y desde 17.1 anterior a 17.1.1, lo que permite que un atacante provoque una denegación de servicio utilizando un archivo OpenAPI manipulado."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"12.0","lessThan":"16.11.5","versionType":"semver","status":"affected"},{"version":"17.0","lessThan":"17.0.3","versionType":"semver","status":"affected"},{"version":"17.1","lessThan":"17.1.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":1.6,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-05T14:13:08.668819Z","id":"CVE-2024-1816","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-400"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.0","versionEndExcluding":"16.11.5","matchCriteriaId":"1A737EB9-758A-469C-B9DF-6B77CA39118A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.0","versionEndExcluding":"16.11.5","matchCriteriaId":"928DC788-6A7F-4EE9-B57D-25C4806D9BA3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"17.0.3","matchCriteriaId":"541958DE-CB05-43D9-921B-4ADD2E436BF7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"17.0.3","matchCriteriaId":"C987EC42-A56B-462A-A0CE-7417CC0FD414"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.1.0:*:*:*:community:*:*:*","matchCriteriaId":"D2461A15-EA5F-43D1-B359-0F24713A713B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"9AA7835D-35E6-44D6-9194-2AC4C38961CE"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/442852","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2370737","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/442852","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2370737","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-2191","sourceIdentifier":"cve@gitlab.com","published":"2024-06-27T00:15:10.790","lastModified":"2026-06-17T07:23:54.283","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows merge request title to be visible publicly despite being set as project members only."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde la 16.9 anterior a la 16.11.5, desde la 17.0 anterior a la 17.0.3 y desde la 17.1 anterior a la 17.1.1, lo que permite que el título de la solicitud de fusión sea visible públicamente a pesar de estar establecido solo para miembros del proyecto."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.9","lessThan":"16.11.5","versionType":"semver","status":"affected"},{"version":"17.0","lessThan":"17.0.3","versionType":"semver","status":"affected"},{"version":"17.1","lessThan":"17.1.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-05T14:06:04.722904Z","id":"CVE-2024-2191","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.9.0","versionEndExcluding":"16.11.5","matchCriteriaId":"1061CF50-3E72-4FEF-BCD4-9683B5AC2893"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.9.0","versionEndExcluding":"16.11.5","matchCriteriaId":"A7C994DA-6CAF-4013-8FE6-C2FDD80071ED"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"17.0.3","matchCriteriaId":"541958DE-CB05-43D9-921B-4ADD2E436BF7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"17.0.3","matchCriteriaId":"C987EC42-A56B-462A-A0CE-7417CC0FD414"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.1.0:*:*:*:community:*:*:*","matchCriteriaId":"D2461A15-EA5F-43D1-B359-0F24713A713B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"9AA7835D-35E6-44D6-9194-2AC4C38961CE"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/444655","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2357370","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/444655","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2357370","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-3115","sourceIdentifier":"cve@gitlab.com","published":"2024-06-27T00:15:11.190","lastModified":"2026-06-17T07:43:20.323","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows an attacker to access issues and epics without having an SSO session using Duo Chat."},{"lang":"es","value":" Se descubrió un problema en GitLab EE que afecta a todas las versiones desde 16.0 anterior a 16.11.5, desde 17.0 anterior a 17.0.3 y desde 17.1 anterior a 17.1.1, lo que permite a un atacante acceder a problemas y epics sin tener una Sesión SSO mediante Duo Chat."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.0","lessThan":"16.11.5","versionType":"semver","status":"affected"},{"version":"17.0","lessThan":"17.0.3","versionType":"semver","status":"affected"},{"version":"17.1","lessThan":"17.1.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-15T18:33:42.584485Z","id":"CVE-2024-3115","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"16.11.5","matchCriteriaId":"F8DBE1E2-2B13-46C1-B72F-EEF32FFBF0B6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"16.11.5","matchCriteriaId":"26302281-02B6-4066-847C-643B4A30602B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"17.0.3","matchCriteriaId":"541958DE-CB05-43D9-921B-4ADD2E436BF7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"17.0.3","matchCriteriaId":"C987EC42-A56B-462A-A0CE-7417CC0FD414"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.1.0:*:*:*:community:*:*:*","matchCriteriaId":"D2461A15-EA5F-43D1-B359-0F24713A713B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"9AA7835D-35E6-44D6-9194-2AC4C38961CE"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/452548","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2417868","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/452548","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2417868","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-3959","sourceIdentifier":"cve@gitlab.com","published":"2024-06-27T00:15:11.420","lastModified":"2026-06-17T07:45:33.227","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab CE/EE affecting all versions starting from 16.7 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows private job artifacts can be accessed by any user."},{"lang":"es","value":" Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde 16.7 anterior a 16.11.5, desde 17.0 anterior a 17.0.3 y desde 17.1 anterior a 17.1.1, lo que permite que cualquier usuario pueda acceder a artefactos de trabajo privados."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.7","lessThan":"16.11.5","versionType":"semver","status":"affected"},{"version":"17.0","lessThan":"17.0.3","versionType":"semver","status":"affected"},{"version":"17.1","lessThan":"17.1.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-06-27T17:37:09.323632Z","id":"CVE-2024-3959","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-285"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.7.0","versionEndExcluding":"16.11.5","matchCriteriaId":"0CD089FD-D42B-4F0E-A2D6-FE17E11B825B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.7.0","versionEndExcluding":"16.11.5","matchCriteriaId":"6E74ABAD-3FC5-44B9-88DF-1EBE0C569C33"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"17.0.3","matchCriteriaId":"541958DE-CB05-43D9-921B-4ADD2E436BF7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"17.0.3","matchCriteriaId":"C987EC42-A56B-462A-A0CE-7417CC0FD414"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.1.0:*:*:*:community:*:*:*","matchCriteriaId":"D2461A15-EA5F-43D1-B359-0F24713A713B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"9AA7835D-35E6-44D6-9194-2AC4C38961CE"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/456989","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2456845","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/456989","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2456845","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-4011","sourceIdentifier":"cve@gitlab.com","published":"2024-06-27T00:15:11.643","lastModified":"2026-06-17T08:00:56.227","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows non-project member to promote key results to objectives."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde 16.1 anterior a 16.11.5, desde 17.0 anterior a 17.0.3 y desde 17.1 anterior a 17.1.1, lo que permite que quienes no son miembros del proyecto promuevan resultados clave a los objetivos."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.1","lessThan":"16.11.5","versionType":"semver","status":"affected"},{"version":"17.0","lessThan":"17.0.3","versionType":"semver","status":"affected"},{"version":"17.1","lessThan":"17.1.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":3.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-06-27T17:40:53.043342Z","id":"CVE-2024-4011","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.1.0","versionEndExcluding":"16.11.5","matchCriteriaId":"8467259D-8274-43C7-AF90-8036AACC1B0C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.1.0","versionEndExcluding":"16.11.5","matchCriteriaId":"64A0D7B6-27D3-4E5C-83ED-C72FBB84B5D5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"17.0.3","matchCriteriaId":"541958DE-CB05-43D9-921B-4ADD2E436BF7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"17.0.3","matchCriteriaId":"C987EC42-A56B-462A-A0CE-7417CC0FD414"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.1.0:*:*:*:community:*:*:*","matchCriteriaId":"D2461A15-EA5F-43D1-B359-0F24713A713B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"9AA7835D-35E6-44D6-9194-2AC4C38961CE"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/457235","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2456186","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/457235","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2456186","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-4557","sourceIdentifier":"cve@gitlab.com","published":"2024-06-27T00:15:11.863","lastModified":"2026-06-17T08:02:08.007","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE affecting all versions starting from 1.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1 which allowed an attacker to cause resource exhaustion via banzai pipeline."},{"lang":"es","value":" Se han descubierto múltiples condiciones de denegación de servicio (DoS) en GitLab CE/EE que afectan a todas las versiones desde 1.0 anterior a 16.11.5, desde 17.0 anterior a 17.0.3 y desde 17.1 anterior a 17.1.1, lo que permitió a un atacante para causar el agotamiento de los recursos a través de la canalización banzai."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"1.0","lessThan":"16.11.5","versionType":"semver","status":"affected"},{"version":"17.0","lessThan":"17.0.3","versionType":"semver","status":"affected"},{"version":"17.1","lessThan":"17.1.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-06-27T17:26:22.371824Z","id":"CVE-2024-4557","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-400"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-400"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"1.0.0","versionEndExcluding":"16.11.5","matchCriteriaId":"D8A9AB42-01E3-403F-B25B-94B5F80FAD33"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"1.0.0","versionEndExcluding":"16.11.5","matchCriteriaId":"643E8F12-B786-40F5-B089-0823AD57CC29"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"17.0.3","matchCriteriaId":"541958DE-CB05-43D9-921B-4ADD2E436BF7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"17.0.3","matchCriteriaId":"C987EC42-A56B-462A-A0CE-7417CC0FD414"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.1.0:*:*:*:community:*:*:*","matchCriteriaId":"D2461A15-EA5F-43D1-B359-0F24713A713B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"9AA7835D-35E6-44D6-9194-2AC4C38961CE"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/460517","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2485172","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/460517","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2485172","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-4901","sourceIdentifier":"cve@gitlab.com","published":"2024-06-27T00:15:12.263","lastModified":"2026-06-17T08:03:08.227","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, where a stored XSS vulnerability could be imported from a project with malicious commit notes."},{"lang":"es","value":" Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde la 16.9 anterior a la 16.11.5, desde la 17.0 anterior a la 17.0.3 y desde la 17.1 anterior a la 17.1.1, donde una vulnerabilidad de XSS almacenado se podía importar desde un proyecto con notas de confirmación maliciosas."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.9","lessThan":"16.11.5","versionType":"semver","status":"affected"},{"version":"17.0","lessThan":"17.0.3","versionType":"semver","status":"affected"},{"version":"17.1","lessThan":"17.1.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-06-28T03:55:15.710247Z","id":"CVE-2024-4901","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.9.0","versionEndExcluding":"16.11.5","matchCriteriaId":"1061CF50-3E72-4FEF-BCD4-9683B5AC2893"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.9.0","versionEndExcluding":"16.11.5","matchCriteriaId":"A7C994DA-6CAF-4013-8FE6-C2FDD80071ED"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"17.0.3","matchCriteriaId":"541958DE-CB05-43D9-921B-4ADD2E436BF7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"17.0.3","matchCriteriaId":"C987EC42-A56B-462A-A0CE-7417CC0FD414"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.1.0:*:*:*:community:*:*:*","matchCriteriaId":"D2461A15-EA5F-43D1-B359-0F24713A713B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"9AA7835D-35E6-44D6-9194-2AC4C38961CE"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/461773","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2500163","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/461773","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2500163","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-5430","sourceIdentifier":"cve@gitlab.com","published":"2024-06-27T00:15:12.650","lastModified":"2026-06-17T08:15:56.107","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab CE/EE affecting all versions starting from 16.10 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows a project maintainer can delete the merge request approval policy via graphQL."},{"lang":"es","value":" Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde la 16.10 anterior a la 16.11.5, desde la 17.0 anterior a la 17.0.3 y desde la 17.1 anterior a la 17.1.1, lo que permite que el mantenedor del proyecto pueda eliminar la política de aprobación de solicitud de fusión a través de GraphQL."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.10","lessThan":"16.11.5","versionType":"semver","status":"affected"},{"version":"17.0","lessThan":"17.0.3","versionType":"semver","status":"affected"},{"version":"17.1","lessThan":"17.1.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N","baseScore":6.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":4.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-06-27T19:05:28.892453Z","id":"CVE-2024-5430","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.10.0","versionEndExcluding":"16.11.5","matchCriteriaId":"E23493BC-7E07-4790-B52E-CA71B7A6467A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.10.0","versionEndExcluding":"16.11.5","matchCriteriaId":"85300561-C131-4906-8FCA-001B1B3C5A4C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"17.0.3","matchCriteriaId":"541958DE-CB05-43D9-921B-4ADD2E436BF7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"17.0.3","matchCriteriaId":"C987EC42-A56B-462A-A0CE-7417CC0FD414"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.1.0:*:*:*:community:*:*:*","matchCriteriaId":"D2461A15-EA5F-43D1-B359-0F24713A713B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"9AA7835D-35E6-44D6-9194-2AC4C38961CE"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/464017","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2520947","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/464017","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2520947","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-5655","sourceIdentifier":"cve@gitlab.com","published":"2024-06-27T00:15:12.887","lastModified":"2026-06-17T08:16:22.410","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows an attacker to trigger a pipeline as another user under certain circumstances."},{"lang":"es","value":" Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde la 15.8 anterior a la 16.11.5, desde la 17.0 anterior a la 17.0.3 y desde la 17.1 anterior a la 17.1.1, lo que permite a un atacante activar una canalización como otro usuario en determinadas circunstancias."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.8","lessThan":"16.11.5","versionType":"semver","status":"affected"},{"version":"17.0","lessThan":"17.0.3","versionType":"semver","status":"affected"},{"version":"17.1","lessThan":"17.1.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N","baseScore":9.6,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-06-28T03:55:14.670384Z","id":"CVE-2024-5655","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.8.0","versionEndExcluding":"16.11.5","matchCriteriaId":"553F7F98-3958-4433-A8A7-C15DECDCFCE6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.8.0","versionEndExcluding":"16.11.5","matchCriteriaId":"40968EC9-BB19-4A6F-8D6D-A4847FEF6167"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"17.0.3","matchCriteriaId":"541958DE-CB05-43D9-921B-4ADD2E436BF7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"17.0.3","matchCriteriaId":"C987EC42-A56B-462A-A0CE-7417CC0FD414"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.1.0:*:*:*:community:*:*:*","matchCriteriaId":"D2461A15-EA5F-43D1-B359-0F24713A713B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"9AA7835D-35E6-44D6-9194-2AC4C38961CE"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/465862","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2536320","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/465862","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2536320","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-6323","sourceIdentifier":"cve@gitlab.com","published":"2024-06-27T00:15:13.130","lastModified":"2026-06-17T08:17:46.700","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Improper authorization in global search in GitLab EE affecting all versions from 16.11 prior to 16.11.5 and 17.0 prior to 17.0.3 and 17.1 prior to 17.1.1 allows an attacker leak content of a private repository in a public project."},{"lang":"es","value":" La autorización inadecuada en la búsqueda global en GitLab EE que afecta a todas las versiones desde 16.11 anteriores a 16.11.5 y 17.0 anteriores a 17.0.3 y 17.1 anteriores a 17.1.1 permite que un atacante filtre el contenido de un repositorio privado en un proyecto público."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.11.0","lessThan":"16.11.5","versionType":"semver","status":"affected"},{"version":"17.0.0","lessThan":"17.0.3","versionType":"semver","status":"affected"},{"version":"17.1.0","lessThan":"17.1.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-02T15:49:24.654987Z","id":"CVE-2024-6323","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.11.0","versionEndExcluding":"16.11.5","matchCriteriaId":"5396A016-FF8D-4525-A35A-3E9512C73AE6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"17.0.3","matchCriteriaId":"C987EC42-A56B-462A-A0CE-7417CC0FD414"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"9AA7835D-35E6-44D6-9194-2AC4C38961CE"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/457912","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/457912","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2024-2177","sourceIdentifier":"cve@gitlab.com","published":"2024-07-09T14:15:03.953","lastModified":"2026-06-17T07:23:52.547","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A Cross Window Forgery vulnerability exists within GitLab CE/EE affecting all versions from 16.3 prior to 16.11.5, 17.0 prior to 17.0.3, and 17.1 prior to 17.1.1. This condition allows for an attacker to abuse the OAuth authentication flow via a crafted payload."},{"lang":"es","value":"Existe una vulnerabilidad de falsificación de ventanas cruzadas dentro de GitLab CE/EE que afecta a todas las versiones desde 16.3 anteriores a 16.11.5, 17.0 anteriores a 17.0.3 y 17.1 anteriores a 17.1.1. Esta condición permite que un atacante abuse del flujo de autenticación OAuth mediante un payload manipulado."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.3","lessThan":"16.11.5","versionType":"semver","status":"affected"},{"version":"17.0","lessThan":"17.0.3","versionType":"semver","status":"affected"},{"version":"17.1","lessThan":"17.1.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N","baseScore":6.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N","baseScore":6.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-09T14:56:59.302785Z","id":"CVE-2024-2177","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1021"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-1021"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.3.0","versionEndExcluding":"16.11.5","matchCriteriaId":"4EA01EF7-2BA1-4A2B-AF14-313348195FB5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.3.0","versionEndExcluding":"16.11.5","matchCriteriaId":"508D8B27-E31B-47F4-A692-B73E69F199E2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"17.0.3","matchCriteriaId":"541958DE-CB05-43D9-921B-4ADD2E436BF7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"17.0.3","matchCriteriaId":"C987EC42-A56B-462A-A0CE-7417CC0FD414"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.1.0:*:*:*:community:*:*:*","matchCriteriaId":"D2461A15-EA5F-43D1-B359-0F24713A713B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"9AA7835D-35E6-44D6-9194-2AC4C38961CE"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/444467","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/2383443","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/444467","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/2383443","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-2880","sourceIdentifier":"cve@gitlab.com","published":"2024-07-11T07:15:02.840","lastModified":"2026-06-17T07:25:44.417","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab CE/EE affecting all versions starting from 16.5 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2 in which a user with `admin_group_member` custom role permission could ban group members."},{"lang":"es","value":" Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde 16.5 anterior a 16.11.6, desde 17.0 anterior a 17.0.4 y desde 17.1 anterior a 17.1.2 en el que un usuario con permiso de rol personalizado `admin_group_member` podría banear a los miembros del grupo."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.5","lessThan":"16.11.6","versionType":"semver","status":"affected"},{"version":"17.0","lessThan":"17.0.4","versionType":"semver","status":"affected"},{"version":"17.1","lessThan":"17.1.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N","baseScore":2.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N","baseScore":2.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-11T13:51:14.660283Z","id":"CVE-2024-2880","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.5.0","versionEndExcluding":"16.11.6","matchCriteriaId":"A7295414-D861-4A9C-99AB-9CEF4CCBF9E6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.5.0","versionEndExcluding":"16.11.6","matchCriteriaId":"A8A41D96-9ED4-43BB-9DA0-46A6EDFD1AA8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"17.0.4","matchCriteriaId":"C7412902-D4C7-4172-BE56-8D4677226D96"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"17.0.4","matchCriteriaId":"12CB9371-7540-4483-A3EE-061ACAF47067"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"17.1.2","matchCriteriaId":"45878C42-2DC4-4A09-ADA6-80BCCCF35DDA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"17.1.2","matchCriteriaId":"19C3FE9A-BACE-4750-A2C9-E43B7E824711"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/451921","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2431597","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/451921","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2431597","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-5257","sourceIdentifier":"cve@gitlab.com","published":"2024-07-11T07:15:04.257","lastModified":"2026-06-17T08:15:33.227","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to 17.1.2 where a Developer user with `admin_compliance_framework` custom role may have been able to modify the URL for a group namespace."},{"lang":"es","value":" Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde la 17.0 anterior a la 17.0.4 y desde la 17.1 anterior a la 17.1.2, donde un usuario desarrollador con el rol personalizado `admin_compliance_framework` pudo haber podido modificar la URL de un espacio de nombres de grupo. ."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.0","lessThan":"17.0.4","versionType":"semver","status":"affected"},{"version":"17.1","lessThan":"17.1.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N","baseScore":2.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-23T18:30:14.386629Z","id":"CVE-2024-5257","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"17.0.4","matchCriteriaId":"C7412902-D4C7-4172-BE56-8D4677226D96"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"17.0.4","matchCriteriaId":"12CB9371-7540-4483-A3EE-061ACAF47067"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"17.1.2","matchCriteriaId":"45878C42-2DC4-4A09-ADA6-80BCCCF35DDA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"17.1.2","matchCriteriaId":"19C3FE9A-BACE-4750-A2C9-E43B7E824711"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/463149","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2513934","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/463149","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2513934","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-5470","sourceIdentifier":"cve@gitlab.com","published":"2024-07-11T07:15:04.833","lastModified":"2026-06-17T08:16:00.823","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to 17.1.2 where a Guest user with `admin_push_rules` permission may have been able to create project-level deploy tokens."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde 17.0 anterior a 17.0.4 y desde 17.1 anterior a 17.1.2 donde un usuario invitado con permiso `admin_push_rules` puede haber podido crear tokens de implementación a nivel de proyecto."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.0","lessThan":"17.0.4","versionType":"semver","status":"affected"},{"version":"17.1","lessThan":"17.1.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N","baseScore":3.8,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":2.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N","baseScore":2.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-11T15:07:35.690681Z","id":"CVE-2024-5470","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"17.0.4","matchCriteriaId":"C7412902-D4C7-4172-BE56-8D4677226D96"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"17.0.4","matchCriteriaId":"12CB9371-7540-4483-A3EE-061ACAF47067"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"17.1.2","matchCriteriaId":"45878C42-2DC4-4A09-ADA6-80BCCCF35DDA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"17.1.2","matchCriteriaId":"19C3FE9A-BACE-4750-A2C9-E43B7E824711"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/464312","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2521480","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/464312","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2521480","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-6385","sourceIdentifier":"cve@gitlab.com","published":"2024-07-11T07:15:06.123","lastModified":"2026-06-17T08:17:54.443","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2, which allows an attacker to trigger a pipeline as another user under certain circumstances."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde la 15.8 anterior a la 16.11.6, desde la 17.0 anterior a la 17.0.4 y desde la 17.1 anterior a la 17.1.2, lo que permite a un atacante activar una pipeline como otro usuario en determinadas circunstancias."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.8","lessThan":"16.11.6","versionType":"semver","status":"affected"},{"version":"17.0","lessThan":"17.0.4","versionType":"semver","status":"affected"},{"version":"17.1","lessThan":"17.1.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N","baseScore":9.6,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-12T03:55:21.176726Z","id":"CVE-2024-6385","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.8.0","versionEndExcluding":"16.11.6","matchCriteriaId":"0561F4EF-E05C-46F8-AFD7-83F4D80186DD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.8.0","versionEndExcluding":"16.11.6","matchCriteriaId":"732BCD4E-FF95-4E3D-8F52-BF9981535DB0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"17.0.4","matchCriteriaId":"C7412902-D4C7-4172-BE56-8D4677226D96"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"17.0.4","matchCriteriaId":"12CB9371-7540-4483-A3EE-061ACAF47067"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"17.1.2","matchCriteriaId":"45878C42-2DC4-4A09-ADA6-80BCCCF35DDA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"17.1.2","matchCriteriaId":"19C3FE9A-BACE-4750-A2C9-E43B7E824711"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/469217","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2578672","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/469217","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2578672","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-6595","sourceIdentifier":"cve@gitlab.com","published":"2024-07-17T02:15:10.130","lastModified":"2026-06-17T08:18:18.657","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab CE/EE affecting all versions starting from 11.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2 where it was possible to upload an NPM package with conflicting package data."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde la 11.8 anterior a la 16.11.6, desde la 17.0 anterior a la 17.0.4 y desde la 17.1 anterior a la 17.1.2 donde era posible cargar un paquete NPM con conflictos datos del paquete."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"11.8","lessThan":"16.11.6","versionType":"semver","status":"affected"},{"version":"17.0","lessThan":"17.0.4","versionType":"semver","status":"affected"},{"version":"17.1","lessThan":"17.1.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:N","baseScore":3.0,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.3,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-17T19:46:12.444412Z","id":"CVE-2024-6595","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-451"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-434"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"16.11.6","matchCriteriaId":"67B15D59-0B7C-46F9-80D8-CBD123B54E1D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"16.11.6","matchCriteriaId":"BABDAF38-D90B-42A5-BACC-5565A4ADBEF6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"17.0.4","matchCriteriaId":"C7412902-D4C7-4172-BE56-8D4677226D96"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"17.0.4","matchCriteriaId":"12CB9371-7540-4483-A3EE-061ACAF47067"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"17.1.2","matchCriteriaId":"45878C42-2DC4-4A09-ADA6-80BCCCF35DDA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"17.1.2","matchCriteriaId":"19C3FE9A-BACE-4750-A2C9-E43B7E824711"}]}]}],"references":[{"url":"https://blog.vlt.sh/blog/the-massive-hole-in-the-npm-ecosystem","source":"cve@gitlab.com","tags":["Exploit","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/417975","source":"cve@gitlab.com","tags":["Issue Tracking"]},{"url":"https://blog.vlt.sh/blog/the-massive-hole-in-the-npm-ecosystem","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/417975","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking"]}]}},{"cve":{"id":"CVE-2024-0231","sourceIdentifier":"cve@gitlab.com","published":"2024-07-24T23:15:09.340","lastModified":"2026-06-17T06:53:02.860","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A resource misdirection vulnerability in GitLab CE/EE versions 12.0 prior to 17.0.5, 17.1 prior to 17.1.3, and 17.2 prior to 17.2.1 allows an attacker to craft a repository import in such a way as to misdirect commits."},{"lang":"es","value":"Una vulnerabilidad de desvío de recursos en GitLab CE/EE versiones 12.0 anteriores a 17.0.5, 17.1 anterior a 17.1.3 y 17.2 anterior a 17.2.1 permite a un atacante diseñar una importación de repositorio de tal manera que desvíe las confirmaciones."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"12.0","lessThan":"17.0.5","versionType":"semver","status":"affected"},{"version":"17.1","lessThan":"17.1.3","versionType":"semver","status":"affected"},{"version":"17.2","lessThan":"17.2.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N","baseScore":2.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N","baseScore":2.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-25T13:39:21.388561Z","id":"CVE-2024-0231","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-99"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-74"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.0.0","versionEndExcluding":"17.0.5","matchCriteriaId":"6C8628A0-047F-4108-B908-7DA6EFA1A918"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.0.0","versionEndExcluding":"17.0.5","matchCriteriaId":"33DF53D1-A375-445D-A2FE-0098DF44B66F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"17.1.3","matchCriteriaId":"E68B5BB3-0D86-4D3C-98A2-5717B267C2E3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"17.1.3","matchCriteriaId":"D50D43C6-72E7-4FE7-91E3-87ED5A2934A3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.2.0:*:*:*:community:*:*:*","matchCriteriaId":"B0E770CB-C97B-4D0D-8D87-9B3D422CB73D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.2.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"284FD63C-6480-41AE-AAA0-17A9879DB44B"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/437103","source":"cve@gitlab.com","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/2299337","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/437103","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/2299337","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-5067","sourceIdentifier":"cve@gitlab.com","published":"2024-07-24T23:15:09.610","lastModified":"2026-06-17T08:15:01.410","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab EE affecting all versions starting from 16.11 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from 17.2 prior to 17.2.1 where certain project-level analytics settings could be leaked in DOM to group members with Developer or higher roles."},{"lang":"es","value":"Se descubrió un problema en GitLab EE que afecta a todas las versiones desde la 16.11 anterior a la 17.0.5, desde la 17.1 anterior a la 17.1.3 y desde la 17.2 anterior a la 17.2.1, donde ciertas configuraciones de análisis a nivel de proyecto podrían filtrarse en DOM a miembros del grupo con roles de desarrollador o superiores."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.11","lessThan":"17.0.5","versionType":"semver","status":"affected"},{"version":"17.1","lessThan":"17.1.3","versionType":"semver","status":"affected"},{"version":"17.2","lessThan":"17.2.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N","baseScore":4.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":0.7,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-26T15:32:48.918789Z","id":"CVE-2024-5067","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-200"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.11","versionEndExcluding":"17.0.5","matchCriteriaId":"2BF8BC38-C7F7-4123-A27A-0E77FBC9709E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.1","versionEndExcluding":"17.1.3","matchCriteriaId":"08FB7225-89F0-46D7-81AB-003D5D3BE137"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.2","versionEndExcluding":"17.2.1","matchCriteriaId":"579D177F-35DB-4988-82DD-0A5AA1AEDBA1"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/458504","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/462427","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/2462303","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://hackerone.com/reports/2502047","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/458504","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/462427","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/2462303","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]},{"url":"https://hackerone.com/reports/2502047","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-7060","sourceIdentifier":"cve@gitlab.com","published":"2024-07-24T23:15:09.817","lastModified":"2026-06-17T08:19:17.177","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An information disclosure vulnerability in GitLab CE/EE in project/group exports affecting all versions from 15.4 prior to 17.0.5, 17.1 prior to 17.1.3, and 17.2 prior to 17.2.1 allows unauthorized users to view the resultant export."},{"lang":"es","value":"Una vulnerabilidad de divulgación de información en GitLab CE/EE en exportaciones de proyectos/grupos que afecta a todas las versiones desde 15.4 anterior a 17.0.5, 17.1 anterior a 17.1.3 y 17.2 anterior a 17.2.1 permite a usuarios no autorizados ver la exportación resultante."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.4","lessThan":"17.0.5","versionType":"semver","status":"affected"},{"version":"17.1","lessThan":"17.1.3","versionType":"semver","status":"affected"},{"version":"17.2","lessThan":"17.2.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N","baseScore":2.6,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-25T13:38:37.891628Z","id":"CVE-2024-7060","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-200"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.4","versionEndExcluding":"17.0.5","matchCriteriaId":"7B522ADA-8F6C-4824-8FE9-502D1DB8073A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.4","versionEndExcluding":"17.0.5","matchCriteriaId":"D429C82D-08BB-4729-B81E-9694960DA273"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.1","versionEndExcluding":"17.1.3","matchCriteriaId":"2AAB2105-E23B-4B5B-B1FB-63E2B406C15D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.1","versionEndExcluding":"17.1.3","matchCriteriaId":"08FB7225-89F0-46D7-81AB-003D5D3BE137"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.2","versionEndExcluding":"17.2.1","matchCriteriaId":"BDEB6BD0-A0F9-4ECD-8BB1-DAD86FDB23DE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.2","versionEndExcluding":"17.2.1","matchCriteriaId":"579D177F-35DB-4988-82DD-0A5AA1AEDBA1"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/437894","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/437894","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2024-7091","sourceIdentifier":"cve@gitlab.com","published":"2024-07-24T23:15:10.013","lastModified":"2026-06-17T08:19:20.403","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab CE/EE affecting all versions starting from 15.6 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from 17.2 prior to 17.2.1 where it was possible to disclose limited information of an exported group or project to another user."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde la 15.6 anterior a la 17.0.5, desde la 17.1 anterior a la 17.1.3 y desde la 17.2 anterior a la 17.2.1, donde era posible revelar información limitada de un grupo exportado o proyecto a otro usuario."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.6","lessThan":"17.0.5","versionType":"semver","status":"affected"},{"version":"17.1","lessThan":"17.1.3","versionType":"semver","status":"affected"},{"version":"17.2","lessThan":"17.2.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N","baseScore":4.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N","baseScore":5.0,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-25T15:03:12.786412Z","id":"CVE-2024-7091","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-200"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.6","versionEndExcluding":"17.0.5","matchCriteriaId":"54882984-51EE-4D34-85F3-95446D04F86B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.6","versionEndExcluding":"17.0.5","matchCriteriaId":"7714A7CC-0AB7-4381-8F8F-A80685E39DC0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.1","versionEndExcluding":"17.1.3","matchCriteriaId":"2AAB2105-E23B-4B5B-B1FB-63E2B406C15D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.1","versionEndExcluding":"17.1.3","matchCriteriaId":"08FB7225-89F0-46D7-81AB-003D5D3BE137"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.2","versionEndExcluding":"17.2.1","matchCriteriaId":"BDEB6BD0-A0F9-4ECD-8BB1-DAD86FDB23DE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.2","versionEndExcluding":"17.2.1","matchCriteriaId":"579D177F-35DB-4988-82DD-0A5AA1AEDBA1"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/408469","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/408469","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2024-7047","sourceIdentifier":"cve@gitlab.com","published":"2024-07-25T01:15:09.830","lastModified":"2026-06-17T08:19:15.683","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A cross site scripting vulnerability exists in GitLab CE/EE affecting all versions from 16.6 prior to 17.0.5, 17.1 prior to 17.1.3, 17.2 prior to 17.2.1 allowing an attacker to execute arbitrary scripts under the context of the current logged in user."},{"lang":"es","value":"Existe una vulnerabilidad de Cross Site Scripting en GitLab CE/EE que afecta a todas las versiones desde 16.6 anterior a 17.0.5, 17.1 anterior a 17.1.3, 17.2 anterior a 17.2.1, lo que permite a un atacante ejecutar scripts arbitrarios en el contexto del usuario con sesión iniciada actual."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.6","lessThan":"17.0.5","versionType":"semver","status":"affected"},{"version":"17.1","lessThan":"17.1.3","versionType":"semver","status":"affected"},{"version":"17.2","lessThan":"17.2.1","versionType":"semver","status":"affected"}]}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","affectedData":[{"vendor":"gitlab","product":"gitlab","defaultStatus":"unknown","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"versions":[{"version":"16.6","lessThan":"17.0.5","versionType":"semver","status":"affected"},{"version":"17.1","lessThan":"17.1.3","versionType":"semver","status":"affected"},{"version":"17.2","lessThan":"17.2.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":7.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.3,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-26T19:21:10.790408Z","id":"CVE-2024-7047","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.6.0","versionEndExcluding":"17.0.5","matchCriteriaId":"0745E87F-1991-423E-A7C7-2874AEBFD622"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.6.0","versionEndExcluding":"17.0.5","matchCriteriaId":"E1F94D0B-5295-43EC-A3D7-283AB66AB6CC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"17.1.3","matchCriteriaId":"E68B5BB3-0D86-4D3C-98A2-5717B267C2E3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"17.1.3","matchCriteriaId":"D50D43C6-72E7-4FE7-91E3-87ED5A2934A3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:7.2.0:*:*:*:community:*:*:*","matchCriteriaId":"A6CDEF18-F9B8-428A-AAE4-13D571E5E9F7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:7.2.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"687E9E4C-B2DD-48EE-A079-02638D40CBEF"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/455318","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/455318","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2024-7057","sourceIdentifier":"cve@gitlab.com","published":"2024-07-25T01:15:10.040","lastModified":"2026-06-17T08:19:16.820","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An information disclosure vulnerability in GitLab CE/EE affecting all versions starting from 16.7 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from 17.2 prior to 17.2.1 where job artifacts can be inappropriately exposed to users lacking the proper authorization level."},{"lang":"es","value":"Una vulnerabilidad de divulgación de información en GitLab CE/EE que afecta a todas las versiones desde la 16.7 anterior a la 17.0.5, desde la 17.1 anterior a la 17.1.3 y desde la 17.2 anterior a la 17.2.1, donde los artefactos del trabajo pueden exponerse de manera inapropiada a usuarios que carecen de la nivel de autorización adecuado."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.7","lessThan":"17.0.5","versionType":"semver","status":"affected"},{"version":"17.1","lessThan":"17.1.3","versionType":"semver","status":"affected"},{"version":"17.2","lessThan":"17.2.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-25T13:30:20.587981Z","id":"CVE-2024-7057","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.7","versionEndExcluding":"17.0.5","matchCriteriaId":"7D2AF178-30AD-4287-A7BE-881FBF897438"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.7","versionEndExcluding":"17.0.5","matchCriteriaId":"B7B134A8-6F60-4450-A98C-857ED5AD5BFF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.1","versionEndExcluding":"17.1.3","matchCriteriaId":"2AAB2105-E23B-4B5B-B1FB-63E2B406C15D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.1","versionEndExcluding":"17.1.3","matchCriteriaId":"08FB7225-89F0-46D7-81AB-003D5D3BE137"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.2","versionEndExcluding":"17.2.1","matchCriteriaId":"BDEB6BD0-A0F9-4ECD-8BB1-DAD86FDB23DE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.2","versionEndExcluding":"17.2.1","matchCriteriaId":"579D177F-35DB-4988-82DD-0A5AA1AEDBA1"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/458501","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2475135","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/458501","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2475135","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-4210","sourceIdentifier":"cve@gitlab.com","published":"2024-08-08T10:15:09.040","lastModified":"2026-06-17T08:01:20.137","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions starting with 12.6 before 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2. It is possible for an attacker to cause a denial of service using crafted adoc files."},{"lang":"es","value":"Se descubrió una condición de denegación de servicio (DoS) en GitLab CE/EE que afecta a todas las versiones comenzando con 12.6 anterior a 17.0.6, 17.1 anterior a 17.1.4 y 17.2 anterior a 17.2.2. Es posible que un atacante provoque una denegación de servicio utilizando archivos adoc manipulados."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"12.6","lessThan":"17.0.6","versionType":"semver","status":"affected"},{"version":"17.1","lessThan":"17.1.4","versionType":"semver","status":"affected"},{"version":"17.2","lessThan":"17.2.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-08-08T13:04:57.194389Z","id":"CVE-2024-4210","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-400"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.6.0","versionEndExcluding":"17.0.6","matchCriteriaId":"41442EAB-760D-4621-8FCD-CC1E5E177589"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.6.0","versionEndExcluding":"17.0.6","matchCriteriaId":"2A30CCB8-5728-42E8-8A5E-A326E37293D9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"17.1.4","matchCriteriaId":"6CA14692-9997-4A11-8B3D-29199A3498D4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"17.1.4","matchCriteriaId":"39754D78-BBE0-41D9-B2AB-5402B32C8ECF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.2","matchCriteriaId":"153C136B-FF14-43EC-AE67-68273DF7D9ED"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.2","matchCriteriaId":"2BE7EFA9-D9B4-4E7E-81B2-597D3DC5756E"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/458245","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2431562","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-4784","sourceIdentifier":"cve@gitlab.com","published":"2024-08-08T10:15:09.390","lastModified":"2026-06-17T08:02:54.133","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab EE starting from version 16.7 before 17.0.6, version 17.1 before 17.1.4 and 17.2 before 17.2.2 that allowed bypassing the password re-entry requirement to approve a policy."},{"lang":"es","value":"Se descubrió un problema en GitLab EE a partir de la versión 16.7 anterior a 17.0.6, la versión 17.1 anterior a 17.1.4 y la 17.2 anterior a 17.2.2 que permitía omitir el requisito de reingreso de contraseña para aprobar una política."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.7","lessThan":"17.0.6","versionType":"semver","status":"affected"},{"version":"17.1","lessThan":"17.1.4","versionType":"semver","status":"affected"},{"version":"17.2","lessThan":"17.2.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","baseScore":4.2,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":2.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-08-08T14:12:19.684074Z","id":"CVE-2024-4784","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-305"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-287"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.7.0","versionEndExcluding":"17.0.6","matchCriteriaId":"88D2145D-48F3-40F6-8E31-80DED84A4AA7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"17.1.4","matchCriteriaId":"39754D78-BBE0-41D9-B2AB-5402B32C8ECF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.2","matchCriteriaId":"2BE7EFA9-D9B4-4E7E-81B2-597D3DC5756E"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/461248","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2486223","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-6329","sourceIdentifier":"cve@gitlab.com","published":"2024-08-08T10:15:09.857","lastModified":"2026-06-17T08:17:47.430","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab CE/EE affecting all versions starting from 8.16 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2, which causes the web interface to fail to render the diff correctly when the path is encoded."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde 8.16 anterior a 17.0.6, desde 17.1 anterior a 17.1.4 y desde 17.2 anterior a 17.2.2, lo que provoca que la interfaz web no pueda representar el diff correctamente cuando la ruta está codificada."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"8.16","lessThan":"17.0.6","versionType":"semver","status":"affected"},{"version":"17.1","lessThan":"17.1.4","versionType":"semver","status":"affected"},{"version":"17.2","lessThan":"17.2.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N","baseScore":5.7,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-08-08T13:07:06.617024Z","id":"CVE-2024-6329","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-116"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-116"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.16.0","versionEndExcluding":"17.0.6","matchCriteriaId":"1B1A6D16-725F-4070-9C2A-C7105AEB8968"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.16.0","versionEndExcluding":"17.0.6","matchCriteriaId":"5ADAB032-70C0-4121-9160-97700DA4F348"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"17.1.4","matchCriteriaId":"6CA14692-9997-4A11-8B3D-29199A3498D4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"17.1.4","matchCriteriaId":"39754D78-BBE0-41D9-B2AB-5402B32C8ECF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.2","matchCriteriaId":"153C136B-FF14-43EC-AE67-68273DF7D9ED"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.2","matchCriteriaId":"2BE7EFA9-D9B4-4E7E-81B2-597D3DC5756E"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/468937","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2542483","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-2800","sourceIdentifier":"cve@gitlab.com","published":"2024-08-08T11:15:12.210","lastModified":"2026-06-17T07:25:34.630","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"ReDoS flaw in RefMatcher when matching branch names using wildcards in GitLab EE/CE affecting all versions from 11.3 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2 allows denial of service via Regex backtracking."},{"lang":"es","value":"La falla de ReDoS en RefMatcher al hacer coincidir nombres de ramas usando comodines en GitLab EE/CE que afecta a todas las versiones desde 11.3 antes de 17.0.6, 17.1 antes de 17.1.4 y 17.2 antes de 17.2.2 permite la denegación de servicio a través del retroceso de Regex."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"11.3","lessThan":"17.0.6","versionType":"semver","status":"affected"},{"version":"17.1","lessThan":"17.1.4","versionType":"semver","status":"affected"},{"version":"17.2","lessThan":"17.2.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-08-08T12:52:53.013776Z","id":"CVE-2024-2800","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1333"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-1333"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"17.0.6","matchCriteriaId":"67CEACA3-6F7E-4004-9D7B-0CA3E6C55D29"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"17.0.6","matchCriteriaId":"BE9FA482-7DD8-4471-AB55-3DCAEA709557"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"17.1.4","matchCriteriaId":"6CA14692-9997-4A11-8B3D-29199A3498D4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"17.1.4","matchCriteriaId":"39754D78-BBE0-41D9-B2AB-5402B32C8ECF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.2","matchCriteriaId":"153C136B-FF14-43EC-AE67-68273DF7D9ED"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.2","matchCriteriaId":"2BE7EFA9-D9B4-4E7E-81B2-597D3DC5756E"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/451293","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2416332","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-3035","sourceIdentifier":"cve@gitlab.com","published":"2024-08-08T11:15:12.503","lastModified":"2026-06-17T07:43:10.637","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A permission check vulnerability in GitLab CE/EE affecting all versions starting from 8.12 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2  allowed for LFS tokens to read and write to the user owned repositories."},{"lang":"es","value":"Una vulnerabilidad de verificación de permisos en GitLab CE/EE que afecta a todas las versiones desde 8.12 anterior a 17.0.6, 17.1 anterior a 17.1.4 y 17.2 anterior a 17.2.2 permitió que los tokens LFS leyeran y escribieran en los repositorios propiedad del usuario."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"8.12","lessThan":"17.0.6","versionType":"semver","status":"affected"},{"version":"17.1","lessThan":"17.1.4","versionType":"semver","status":"affected"},{"version":"17.2","lessThan":"17.2.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","baseScore":6.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-08-08T14:03:15.598855Z","id":"CVE-2024-3035","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-639"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-639"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.12.0","versionEndExcluding":"17.0.6","matchCriteriaId":"B54ED79A-C1EA-4296-9553-595C2FED98D8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.12.0","versionEndExcluding":"17.0.6","matchCriteriaId":"551EDDC6-ADAF-48D9-AFF6-246BD23EF79D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.1","versionEndExcluding":"17.1.4","matchCriteriaId":"1D5FC3BB-8A05-491A-8AB1-8D41CAF39AFB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"17.1.4","matchCriteriaId":"6CA14692-9997-4A11-8B3D-29199A3498D4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.2","matchCriteriaId":"153C136B-FF14-43EC-AE67-68273DF7D9ED"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.2","matchCriteriaId":"2BE7EFA9-D9B4-4E7E-81B2-597D3DC5756E"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/452297","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2424715","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-3114","sourceIdentifier":"cve@gitlab.com","published":"2024-08-08T11:15:12.733","lastModified":"2026-06-17T07:43:20.210","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab CE/EE affecting all versions starting from 11.10 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2, with the processing logic for parsing invalid commits can lead to a regular expression DoS attack on the server."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde la 11.10 anterior a la 17.0.6, la 17.1 anterior a la 17.1.4 y la 17.2 anterior a la 17.2.2, y la lógica de procesamiento para analizar confirmaciones no válidas puede provocar un ataque DoS de expresión regular en el servidor."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"11.10","lessThan":"17.0.6","versionType":"semver","status":"affected"},{"version":"17.1","lessThan":"17.1.4","versionType":"semver","status":"affected"},{"version":"17.2","lessThan":"17.2.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-08-09T18:05:29.915174Z","id":"CVE-2024-3114","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1333"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-1333"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.10.0","versionEndExcluding":"17.0.6","matchCriteriaId":"03B0A1CC-12FD-4FA4-A818-357F63A5C95A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.10.0","versionEndExcluding":"17.0.6","matchCriteriaId":"BA68FBDF-DCEE-45E0-8A5B-34E128474D88"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"17.1.4","matchCriteriaId":"6CA14692-9997-4A11-8B3D-29199A3498D4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"17.1.4","matchCriteriaId":"39754D78-BBE0-41D9-B2AB-5402B32C8ECF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.2","matchCriteriaId":"153C136B-FF14-43EC-AE67-68273DF7D9ED"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.2","matchCriteriaId":"2BE7EFA9-D9B4-4E7E-81B2-597D3DC5756E"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/452547","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2416630","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-3958","sourceIdentifier":"cve@gitlab.com","published":"2024-08-08T11:15:12.967","lastModified":"2026-06-17T07:45:33.113","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions before 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2. An issue was found that allows someone  to abuse a discrepancy between the Web application display and the git command line interface to social engineer victims into cloning non-trusted code."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones anteriores a 17.0.6, 17.1 anterior a 17.1.4 y 17.2 anterior a 17.2.2. Se encontró un problema que permite a alguien abusar de una discrepancia entre la visualización de la aplicación web y la interfaz de línea de comando de git para realizar ingeniería social a las víctimas para clonar código no confiable."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"0","lessThan":"17.0.6","versionType":"semver","status":"affected"},{"version":"17.1","lessThan":"17.1.4","versionType":"semver","status":"affected"},{"version":"17.2","lessThan":"17.2.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-08-08T14:16:46.296880Z","id":"CVE-2024-3958","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-94"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-94"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"17.0.6","matchCriteriaId":"082D69B3-CFAD-4D5E-A48D-6AEA7F20FD5A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"17.0.6","matchCriteriaId":"146AD6E5-BA11-4A3D-9713-04659991D812"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"17.1.4","matchCriteriaId":"6CA14692-9997-4A11-8B3D-29199A3498D4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"17.1.4","matchCriteriaId":"39754D78-BBE0-41D9-B2AB-5402B32C8ECF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.2","matchCriteriaId":"153C136B-FF14-43EC-AE67-68273DF7D9ED"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.2","matchCriteriaId":"2BE7EFA9-D9B4-4E7E-81B2-597D3DC5756E"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/456988","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2437784","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-4207","sourceIdentifier":"cve@gitlab.com","published":"2024-08-08T11:15:13.183","lastModified":"2026-06-17T08:01:19.770","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 prior 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2. When viewing an XML file in a repository in raw mode, it can be made to render as HTML if viewed under specific circumstances."},{"lang":"es","value":"Se descubrió un problema de cross-site scripting en GitLab que afecta a todas las versiones a partir de 5.1 anteriores a 17.0.6, a partir de 17.1 anteriores a 17.1.4 y a partir de 17.2 anteriores a 17.2.2. Al visualizar un archivo XML en un repositorio en modo sin formato, se puede hacer que se represente como HTML si se ve en circunstancias específicas."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"5.1","lessThan":"17.0.6","versionType":"semver","status":"affected"},{"version":"17.1","lessThan":"17.1.4","versionType":"semver","status":"affected"},{"version":"17.2","lessThan":"17.2.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":4.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.3,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-08-08T13:04:36.972849Z","id":"CVE-2024-4207","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"5.1.0","versionEndExcluding":"17.0.6","matchCriteriaId":"A95AD010-CC40-43F0-9D7B-E16E331AD6C0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"17.1.4","matchCriteriaId":"C2461644-1CDB-4D7B-BC54-5685B5788D99"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.2","matchCriteriaId":"1F86D55A-2D41-41AB-A9CC-0C997151D1B4"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/458236","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2473917","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-5423","sourceIdentifier":"cve@gitlab.com","published":"2024-08-08T11:15:13.410","lastModified":"2026-06-17T08:15:55.220","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE affecting all versions starting from 1.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2 which allowed an attacker to cause resource exhaustion via banzai pipeline."},{"lang":"es","value":"Se descubrieron múltiples condiciones de denegación de servicio (DoS) en GitLab CE/EE que afectan a todas las versiones desde 1.0 anterior a 17.0.6, desde 17.1 anterior a 17.1.4 y desde 17.2 anterior a 17.2.2, lo que permitió a un atacante para causar el agotamiento de los recursos a través del oleoducto banzai."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"1","lessThan":"17.0.6","versionType":"semver","status":"affected"},{"version":"17.1","lessThan":"17.1.4","versionType":"semver","status":"affected"},{"version":"17.2","lessThan":"17.2.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-08-08T14:12:47.309092Z","id":"CVE-2024-5423","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-400"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"1.0","versionEndExcluding":"17.0.6","matchCriteriaId":"D52C923A-0C23-4020-A383-EBEB936E0CD0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"1.0","versionEndExcluding":"17.0.6","matchCriteriaId":"73844CD0-FDE4-471B-8BE3-835BC50ECC97"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"17.1.4","matchCriteriaId":"6CA14692-9997-4A11-8B3D-29199A3498D4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"17.1.4","matchCriteriaId":"39754D78-BBE0-41D9-B2AB-5402B32C8ECF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.2","matchCriteriaId":"153C136B-FF14-43EC-AE67-68273DF7D9ED"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.2","matchCriteriaId":"2BE7EFA9-D9B4-4E7E-81B2-597D3DC5756E"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/463807","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2518563","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-7554","sourceIdentifier":"cve@gitlab.com","published":"2024-08-08T11:15:13.633","lastModified":"2026-06-17T08:20:26.523","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.9 before 17.0.6, all versions starting from 17.1 before 17.1.4, all versions starting from 17.2 before 17.2.2. Under certain conditions, access tokens may have been logged when an API request was made in a specific manner."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde 13.9 anteriores a 17.0.6, todas las versiones desde 17.1 anteriores a 17.1.4, todas las versiones desde 17.2 anteriores a 17.2.2. Bajo ciertas condiciones, es posible que se hayan registrado tokens de acceso cuando se realizó una solicitud de API de una manera específica."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"13.9","lessThan":"17.0.6","versionType":"semver","status":"affected"},{"version":"17.1","lessThan":"17.1.4","versionType":"semver","status":"affected"},{"version":"17.2","lessThan":"17.2.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-08-08T13:05:39.543771Z","id":"CVE-2024-7554","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-200"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.9","versionEndExcluding":"17.0.6","matchCriteriaId":"CF490E54-A3A0-475D-B964-CA44E14D9332"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.9","versionEndExcluding":"17.0.6","matchCriteriaId":"41EEB749-1E2B-4005-AC13-5609886CF182"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"17.1.4","matchCriteriaId":"6CA14692-9997-4A11-8B3D-29199A3498D4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"17.1.4","matchCriteriaId":"39754D78-BBE0-41D9-B2AB-5402B32C8ECF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.2","matchCriteriaId":"153C136B-FF14-43EC-AE67-68273DF7D9ED"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.2","matchCriteriaId":"2BE7EFA9-D9B4-4E7E-81B2-597D3DC5756E"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/471555","source":"cve@gitlab.com","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2024-7610","sourceIdentifier":"cve@gitlab.com","published":"2024-08-08T11:15:13.857","lastModified":"2026-06-17T08:20:32.793","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions starting with 15.9 before 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2. It is possible for an attacker to cause catastrophic backtracking while parsing results from Elasticsearch."},{"lang":"es","value":"Se descubrió una condición de denegación de servicio (DoS) en GitLab CE/EE que afecta a todas las versiones comenzando con 15.9 anterior a 17.0.6, 17.1 anterior a 17.1.4 y 17.2 anterior a 17.2.2. Es posible que un atacante provoque un retroceso catastrófico mientras analiza los resultados de Elasticsearch."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.9","lessThan":"17.0.6","versionType":"semver","status":"affected"},{"version":"17.1","lessThan":"17.1.4","versionType":"semver","status":"affected"},{"version":"17.2","lessThan":"17.2.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-08-08T12:53:54.759743Z","id":"CVE-2024-7610","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-400"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.9.0","versionEndExcluding":"17.0.6","matchCriteriaId":"684A0BB7-D809-4BD0-BEC2-4D9F25094978"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.9.0","versionEndExcluding":"17.0.6","matchCriteriaId":"A6E0DBD3-010A-405C-9EFB-FB98058CA5A7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"17.1.4","matchCriteriaId":"6CA14692-9997-4A11-8B3D-29199A3498D4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"17.1.4","matchCriteriaId":"39754D78-BBE0-41D9-B2AB-5402B32C8ECF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.2","matchCriteriaId":"153C136B-FF14-43EC-AE67-68273DF7D9ED"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.2","matchCriteriaId":"2BE7EFA9-D9B4-4E7E-81B2-597D3DC5756E"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/468917","source":"cve@gitlab.com","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2024-3127","sourceIdentifier":"cve@gitlab.com","published":"2024-08-22T16:15:08.590","lastModified":"2026-06-17T07:43:21.897","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions starting from 12.5 before 17.1.6, all versions starting from 17.2 before 17.2.4, all versions starting from 17.3 before 17.3.1. Under certain conditions it may be possible to bypass the IP restriction for groups through GraphQL allowing unauthorised users to perform some actions at the group level."},{"lang":"es","value":"Se descubrió un problema en GitLab EE que afecta a todas las versiones desde 12.5 anteriores a 17.1.6, todas las versiones desde 17.2 anteriores a 17.2.4, todas las versiones desde 17.3 anteriores a 17.3.1. Bajo ciertas condiciones, es posible evitar la restricción de IP para grupos a través de GraphQL, permitiendo a usuarios no autorizados realizar algunas acciones a nivel de grupo."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"12.5","lessThan":"17.1.6","versionType":"semver","status":"affected"},{"version":"17.2","lessThan":"17.2.4","versionType":"semver","status":"affected"},{"version":"17.3","lessThan":"17.3.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-08-22T16:35:21.803026Z","id":"CVE-2024-3127","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.5.0","versionEndExcluding":"17.1.6","matchCriteriaId":"A95A5F22-1F63-4B1C-A944-071029025DD9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.5.0","versionEndExcluding":"17.1.6","matchCriteriaId":"E5792830-3AF0-4CEA-8762-7DFCE6212654"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.4","matchCriteriaId":"77973797-7C54-4BBA-9BB7-A0E71BC6AB94"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.4","matchCriteriaId":"E1DB1E17-ECEF-4040-BDA8-2E55F75BA266"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.3.0:*:*:*:community:*:*:*","matchCriteriaId":"9DCEFA55-C0E2-4772-AAB0-F5DBA77DAF18"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.3.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"87D7C5B2-CDC0-4090-A7FD-45C6E9E1C3E8"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/452640","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/2395169","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-6502","sourceIdentifier":"cve@gitlab.com","published":"2024-08-22T16:15:10.377","lastModified":"2026-06-17T08:18:08.300","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab CE/EE affecting all versions starting from 8.2 prior to 17.1.6 starting from 17.2 prior to 17.2.4, and starting from 17.3 prior to 17.3.1, which allows an attacker to create a branch with the same name as a deleted tag."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde 8.2 anterior a 17.1.6, desde 17.2 anterior a 17.2.4 y desde 17.3 anterior a 17.3.1, lo que permite a un atacante crear una rama con la misma nombre como una etiqueta eliminada."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"8.2","lessThan":"17.1.6","versionType":"semver","status":"affected"},{"version":"17.2","lessThan":"17.2.4","versionType":"semver","status":"affected"},{"version":"17.3","lessThan":"17.3.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N","baseScore":5.7,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-08-22T19:54:04.083201Z","id":"CVE-2024-6502","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-684"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.2.0","versionEndExcluding":"17.1.6","matchCriteriaId":"7A232C67-E643-439E-9C18-40E784E044D1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.4","matchCriteriaId":"77973797-7C54-4BBA-9BB7-A0E71BC6AB94"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.3.1","matchCriteriaId":"C2925C28-DB06-4BAC-B765-CF3226A555BA"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.2.0","versionEndExcluding":"17.1.6","matchCriteriaId":"71B48894-8CE6-4A72-8030-59D2F4330681"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.4","matchCriteriaId":"E1DB1E17-ECEF-4040-BDA8-2E55F75BA266"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.3.1","matchCriteriaId":"0A8C02DB-1D57-4F63-B472-E7D5BC958EDB"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/470647","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2574561","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-7110","sourceIdentifier":"cve@gitlab.com","published":"2024-08-22T16:15:10.627","lastModified":"2026-06-17T08:19:22.853","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab EE affecting all versions starting 17.0 to 17.1.6, 17.2 prior to 17.2.4, and 17.3 prior to 17.3.1 allows an attacker to execute arbitrary command in a victim's pipeline through prompt injection."},{"lang":"es","value":"Se descubrió un problema en GitLab EE que afecta a todas las versiones desde 17.0 a 17.1.6, 17.2 anterior a 17.2.4 y 17.3 anterior a 17.3.1, y permite a un atacante ejecutar comandos arbitrarios en la canalización de una víctima mediante inyección rápida."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.1","lessThan":"17.1.6","versionType":"semver","status":"affected"},{"version":"17.2","lessThan":"17.2.4","versionType":"semver","status":"affected"},{"version":"17.3","lessThan":"17.3.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-08-22T17:32:38.600598Z","id":"CVE-2024-7110","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-77"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-77"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"17.1.6","matchCriteriaId":"AB3177CA-651B-437F-9E68-5FB2015A5702"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.4","matchCriteriaId":"77973797-7C54-4BBA-9BB7-A0E71BC6AB94"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.3.1","matchCriteriaId":"C2925C28-DB06-4BAC-B765-CF3226A555BA"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"17.1.6","matchCriteriaId":"0ABAEB09-BEB2-4035-9041-DA84B8C331E5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.4","matchCriteriaId":"E1DB1E17-ECEF-4040-BDA8-2E55F75BA266"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.3.1","matchCriteriaId":"0A8C02DB-1D57-4F63-B472-E7D5BC958EDB"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/472603","source":"cve@gitlab.com","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2024-8041","sourceIdentifier":"cve@gitlab.com","published":"2024-08-22T16:15:10.880","lastModified":"2026-06-17T08:21:44.847","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all versions prior to 17.1.6, 17.2 prior to 17.2.4, and 17.3 prior to 17.3.1. A denial of service could occur upon importing a maliciously crafted repository using the GitHub importer."},{"lang":"es","value":"Se descubrió un problema de denegación de servicio (DoS) en GitLab CE/EE que afecta a todas las versiones anteriores a 17.1.6, 17.2 anterior a 17.2.4 y 17.3 anterior a 17.3.1. Podría ocurrir una denegación de servicio al importar un repositorio creado con fines malintencionados mediante el importador de GitHub."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"0","lessThan":"17.1.6","versionType":"semver","status":"affected"},{"version":"17.2","lessThan":"17.2.4","versionType":"semver","status":"affected"},{"version":"17.3","lessThan":"17.3.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-08-22T16:05:10.898443Z","id":"CVE-2024-8041","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-400"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"17.1.6","matchCriteriaId":"76FB69CE-076D-474E-BC1C-652ABA66ABE7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.4","matchCriteriaId":"77973797-7C54-4BBA-9BB7-A0E71BC6AB94"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.3.1","matchCriteriaId":"C2925C28-DB06-4BAC-B765-CF3226A555BA"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"17.1.6","matchCriteriaId":"8A34FF5F-75BF-4CDD-9E82-96BF23FCF6F7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.4","matchCriteriaId":"E1DB1E17-ECEF-4040-BDA8-2E55F75BA266"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.3.1","matchCriteriaId":"0A8C02DB-1D57-4F63-B472-E7D5BC958EDB"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/463092","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2499070","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-45409","sourceIdentifier":"security-advisories@github.com","published":"2024-09-10T19:15:22.030","lastModified":"2026-06-17T07:54:09.650","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"The Ruby SAML library is for implementing the client side of a SAML authorization. Ruby-SAML in <= 12.2 and 1.13.0 <= 1.16.0 does not properly verify the signature of the SAML Response. An unauthenticated attacker with access to any signed saml document (by the IdP) can thus forge a SAML Response/Assertion with arbitrary contents. This would allow the attacker to log in as arbitrary user within the vulnerable system. This vulnerability is fixed in 1.17.0 and 1.12.3."},{"lang":"es","value":"La librería Ruby SAML sirve para implementar el lado del cliente de una autorización SAML. Ruby-SAML en &lt;= 12.2 y 1.13.0 &lt;= 1.16.0 no verifica correctamente la firma de la respuesta SAML. Un atacante no autenticado con acceso a cualquier documento SAML firmado (por el IdP) puede falsificar una respuesta/afirmación SAML con contenido arbitrario. Esto le permitiría al atacante iniciar sesión como un usuario arbitrario dentro del sistema vulnerable. Esta vulnerabilidad se solucionó en 1.17.0 y 1.12.3."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"SAML-Toolkits","product":"ruby-saml","versions":[{"version":"< 1.12.3","status":"affected"},{"version":">= 1.13.0, < 1.17.0","status":"affected"}]}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","affectedData":[{"vendor":"onelogin","product":"ruby-saml","defaultStatus":"unknown","cpes":["cpe:2.3:a:onelogin:ruby-saml:*:*:*:*:*:*:*:*"],"versions":[{"version":"0","lessThan":"1.12.3","versionType":"custom","status":"affected"},{"version":"1.13.0","lessThan":"1.17.0","versionType":"custom","status":"affected"}]},{"vendor":"omniauth","product":"omniauth-saml","defaultStatus":"unknown","cpes":["cpe:2.3:a:omniauth:omniauth-saml:*:*:*:*:*:*:*:*"],"versions":[{"version":"0","lessThanOrEqual":"2.1.0","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N","baseScore":10.0,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-09-23T00:00:00+00:00","id":"CVE-2024-45409","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-347"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:onelogin:ruby-saml:*:*:*:*:*:*:*:*","versionEndExcluding":"1.12.3","matchCriteriaId":"DF41BEEE-FC5B-4728-B9BE-0B58C04F547E"},{"vulnerable":true,"criteria":"cpe:2.3:a:onelogin:ruby-saml:*:*:*:*:*:*:*:*","versionStartIncluding":"1.13.0","versionEndExcluding":"1.17.0","matchCriteriaId":"ADBA67BE-BC31-48C0-A36F-9431814178C0"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:omniauth:omniauth_saml:*:*:*:*:*:ruby:*:*","versionEndIncluding":"1.10.3","matchCriteriaId":"6D978907-97A8-4EF4-BF81-FE8702C24745"},{"vulnerable":true,"criteria":"cpe:2.3:a:omniauth:omniauth_saml:2.0.0:*:*:*:*:ruby:*:*","matchCriteriaId":"527AEDE3-F8EB-4C38-AF51-3B679AC4E336"},{"vulnerable":true,"criteria":"cpe:2.3:a:omniauth:omniauth_saml:2.1.0:*:*:*:*:ruby:*:*","matchCriteriaId":"3F307538-4D4D-4DD1-A9A0-F4D06E20163E"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionEndExcluding":"16.11.10","matchCriteriaId":"7000556E-4EBB-4B99-84B1-A2EEA709311C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"17.0.8","matchCriteriaId":"3B47FDB0-B642-4E50-B0B6-1D71545FE917"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"17.1.8","matchCriteriaId":"86B327A7-22C7-488F-ABA6-3AC90EF07D04"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.7","matchCriteriaId":"E831CA83-DDA9-4F47-BCF8-2CBB7E74C9DC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.3.3","matchCriteriaId":"60003658-012F-4DB8-9D8F-8E48C14CA0C4"}]}]}],"references":[{"url":"https://github.com/SAML-Toolkits/ruby-saml/commit/1ec5392bc506fe43a02dbb66b68741051c5ffeae","source":"security-advisories@github.com","tags":["Patch"]},{"url":"https://github.com/SAML-Toolkits/ruby-saml/commit/4865d030cae9705ee5cdb12415c654c634093ae7","source":"security-advisories@github.com","tags":["Patch"]},{"url":"https://github.com/SAML-Toolkits/ruby-saml/security/advisories/GHSA-jw9c-mfg7-9rx2","source":"security-advisories@github.com","tags":["Vendor Advisory"]},{"url":"https://github.com/omniauth/omniauth-saml/security/advisories/GHSA-cvp8-5r8g-fhvq","source":"security-advisories@github.com","tags":["Vendor Advisory"]},{"url":"https://lists.debian.org/debian-lts-announce/2024/11/msg00006.html","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://news.ycombinator.com/item?id=41586031","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20240926-0008/","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://ssoready.com/blog/engineering/ruby-saml-pwned-by-xml-signature-wrapping-attacks/","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2024-2743","sourceIdentifier":"cve@gitlab.com","published":"2024-09-12T17:15:04.177","lastModified":"2026-06-17T07:25:27.550","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab-EE starting with version 13.3 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2 that would allow an attacker to modify an on-demand DAST scan without permissions and leak variables."},{"lang":"es","value":"Se descubrió un problema en GitLab-EE a partir de la versión 13.3 anterior a la 17.1.7, 17.2 anterior a la 17.2.5 y 17.3 anterior a la 17.3.2 que permitiría a un atacante modificar un escaneo DAST a pedido sin permisos y filtrar variables."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"13.3","lessThan":"17.1.7","versionType":"semver","status":"affected"},{"version":"17.2","lessThan":"17.2.5","versionType":"semver","status":"affected"},{"version":"17.3","lessThan":"17.3.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-09-12T17:21:58.095068Z","id":"CVE-2024-2743","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"17.1.7","matchCriteriaId":"593EF08B-1A59-46F2-8593-BC8A65840D3C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.5","matchCriteriaId":"1F428DA1-FB1C-4B14-A1E1-65177E7F4B10"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.3.2","matchCriteriaId":"145E52CC-F503-446E-A760-1C01753DA938"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/451014","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2411756","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://about.gitlab.com/releases/2024/09/11/patch-release-gitlab-17-3-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2024-4612","sourceIdentifier":"cve@gitlab.com","published":"2024-09-12T17:15:04.740","lastModified":"2026-06-17T08:02:16.037","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions starting from 12.9 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2. Under certain conditions an open redirect vulnerability could allow for an account takeover by breaking the OAuth flow."},{"lang":"es","value":"Se ha descubierto un problema en GitLab EE que afecta a todas las versiones a partir de la 12.9 anterior a la 17.1.7, la 17.2 anterior a la 17.2.5 y la 17.3 anterior a la 17.3.2. En determinadas condiciones, una vulnerabilidad de redirección abierta podría permitir la apropiación de una cuenta interrumpiendo el flujo de OAuth."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"12.9","lessThan":"17.1.7","versionType":"semver","status":"affected"},{"version":"17.2","lessThan":"17.2.5","versionType":"semver","status":"affected"},{"version":"17.3","lessThan":"17.3.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-09-12T17:22:22.140912Z","id":"CVE-2024-4612","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-601"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-601"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.9.0","versionEndExcluding":"17.1.7","matchCriteriaId":"2F4D084D-A6A3-4BA3-BA59-C8B20D0F814E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.5","matchCriteriaId":"1F428DA1-FB1C-4B14-A1E1-65177E7F4B10"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.3.2","matchCriteriaId":"145E52CC-F503-446E-A760-1C01753DA938"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/460707","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2479857","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://about.gitlab.com/releases/2024/09/11/patch-release-gitlab-17-3-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2024-4660","sourceIdentifier":"cve@gitlab.com","published":"2024-09-12T17:15:04.937","lastModified":"2026-06-17T08:02:21.240","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions starting from 11.2 before 17.1.7, all versions starting from 17.2 before 17.2.5, all versions starting from 17.3 before 17.3.2. It was possible for a guest to read the source code of a private project by using group templates."},{"lang":"es","value":"Se ha descubierto un problema en GitLab EE que afecta a todas las versiones a partir de la 11.2 hasta la 17.1.7, a todas las versiones a partir de la 17.2 hasta la 17.2.5 y a todas las versiones a partir de la 17.3 hasta la 17.3.2. Un invitado podía leer el código fuente de un proyecto privado mediante plantillas de grupo."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"11.2","lessThan":"17.1.7","versionType":"semver","status":"affected"},{"version":"17.2","lessThan":"17.2.5","versionType":"semver","status":"affected"},{"version":"17.3","lessThan":"17.3.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-09-12T17:22:54.382056Z","id":"CVE-2024-4660","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.2.0","versionEndExcluding":"17.1.7","matchCriteriaId":"4F6975C5-F519-4A85-8E4B-1C8067F7B0CB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.5","matchCriteriaId":"1F428DA1-FB1C-4B14-A1E1-65177E7F4B10"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.3.2","matchCriteriaId":"145E52CC-F503-446E-A760-1C01753DA938"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/460892","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2480126","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://about.gitlab.com/releases/2024/09/11/patch-release-gitlab-17-3-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2024-5435","sourceIdentifier":"cve@gitlab.com","published":"2024-09-12T17:15:05.147","lastModified":"2026-06-17T08:15:56.707","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered discovered in GitLab EE/CE affecting all versions starting from 15.10 before 17.1.7, all versions starting from 17.2 before 17.2.5, all versions starting from 17.3 before 17.3.2 will disclose user password from repository mirror configuration."},{"lang":"es","value":"Se ha descubierto un problema en GitLab EE/CE que afecta a todas las versiones desde la 15.10 hasta la 17.1.7, todas las versiones desde la 17.2 hasta la 17.2.5 y todas las versiones desde la 17.3 hasta la 17.3.2, que revelarán la contraseña del usuario desde la configuración del espejo del repositorio."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.10","lessThan":"17.1.7","versionType":"semver","status":"affected"},{"version":"17.2","lessThan":"17.2.5","versionType":"semver","status":"affected"},{"version":"17.3","lessThan":"17.3.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N","baseScore":4.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":0.9,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-09-12T17:25:05.825878Z","id":"CVE-2024-5435","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-209"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-209"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.10.0","versionEndExcluding":"17.1.7","matchCriteriaId":"ABF7770C-12E5-496B-8D5F-F6E55E610AA8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.10.0","versionEndExcluding":"17.1.7","matchCriteriaId":"A9EB56F1-6DB6-45C7-BD1B-B7B28A15B291"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.5","matchCriteriaId":"9DE9BFF3-C056-4146-A762-E34D60E10EDE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.5","matchCriteriaId":"1F428DA1-FB1C-4B14-A1E1-65177E7F4B10"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.3.2","matchCriteriaId":"D2F29B41-64CF-4CEF-8EDF-BBDBA2FFE8C1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.3.2","matchCriteriaId":"145E52CC-F503-446E-A760-1C01753DA938"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/464044","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2520722","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://about.gitlab.com/releases/2024/09/11/patch-release-gitlab-17-3-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2024-6389","sourceIdentifier":"cve@gitlab.com","published":"2024-09-12T17:15:05.340","lastModified":"2026-06-17T08:17:55.123","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab-CE/EE affecting all versions starting with 17.0 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2. An attacker as a guest user was able to access commit information via the release Atom endpoint, contrary to permissions."},{"lang":"es","value":"Se descubrió un problema en GitLab-CE/EE que afectaba a todas las versiones a partir de la 17.0 anterior a la 17.1.7, la 17.2 anterior a la 17.2.5 y la 17.3 anterior a la 17.3.2. Un atacante como usuario invitado pudo acceder a la información de confirmación a través del endpoint Atom de la versión, contrariamente a los permisos establecidos."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.1","lessThan":"17.1.7","versionType":"semver","status":"affected"},{"version":"17.2","lessThan":"17.2.5","versionType":"semver","status":"affected"},{"version":"17.3","lessThan":"17.3.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-09-12T17:27:09.811383Z","id":"CVE-2024-6389","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-497"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"17.1.7","matchCriteriaId":"624E699C-D0A7-419F-88FD-AABFA4A49E5D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"17.1.7","matchCriteriaId":"79D35B6F-7F74-408A-83BF-8C4464744AEB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.5","matchCriteriaId":"9DE9BFF3-C056-4146-A762-E34D60E10EDE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.5","matchCriteriaId":"1F428DA1-FB1C-4B14-A1E1-65177E7F4B10"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.3.2","matchCriteriaId":"D2F29B41-64CF-4CEF-8EDF-BBDBA2FFE8C1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.3.2","matchCriteriaId":"145E52CC-F503-446E-A760-1C01753DA938"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/469367","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2573397","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://about.gitlab.com/releases/2024/09/11/patch-release-gitlab-17-3-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2024-6446","sourceIdentifier":"cve@gitlab.com","published":"2024-09-12T17:15:05.557","lastModified":"2026-06-17T08:18:02.117","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions starting from 17.1 to 17.1.7, 17.2 prior to 17.2.5 and 17.3 prior to 17.3.2. A crafted URL could be used to trick a victim to trust an attacker controlled application."},{"lang":"es","value":"Se ha descubierto un problema en GitLab que afecta a todas las versiones desde la 17.1 hasta la 17.1.7, desde la 17.2 hasta la 17.2.5 y desde la 17.3 hasta la 17.3.2. Se podría utilizar una URL manipulada para engañar a una víctima y hacer que confíe en una aplicación controlada por un atacante."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.1","lessThan":"17.1.7","versionType":"semver","status":"affected"},{"version":"17.2","lessThan":"17.2.5","versionType":"semver","status":"affected"},{"version":"17.3","lessThan":"17.3.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N","baseScore":3.5,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N","baseScore":3.5,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-09-12T17:26:38.131802Z","id":"CVE-2024-6446","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-840"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"17.1.7","matchCriteriaId":"AC6C8C93-43DE-4B88-81F4-6DEB61EBC5E2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"17.1.7","matchCriteriaId":"EE908F1B-A4D2-4CC6-A26F-F0D6CDC6411A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.5","matchCriteriaId":"9DE9BFF3-C056-4146-A762-E34D60E10EDE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.5","matchCriteriaId":"1F428DA1-FB1C-4B14-A1E1-65177E7F4B10"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.3.2","matchCriteriaId":"D2F29B41-64CF-4CEF-8EDF-BBDBA2FFE8C1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.3.2","matchCriteriaId":"145E52CC-F503-446E-A760-1C01753DA938"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/470144","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2573481","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://about.gitlab.com/releases/2024/09/11/patch-release-gitlab-17-3-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2024-8124","sourceIdentifier":"cve@gitlab.com","published":"2024-09-12T17:15:06.007","lastModified":"2026-06-17T08:21:56.027","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.1.7, starting from 17.2 prior to 17.2.5, starting from 17.3 prior to 17.3.2  which could cause Denial of Service via sending a specific POST request."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde la 16.4 hasta la 17.1.7, desde la 17.2 hasta la 17.2.5, desde la 17.3 hasta la 17.3.2, lo que podría provocar una denegación de servicio mediante el envío de un parámetro `glm_source` grande."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.4","lessThan":"17.1.7","versionType":"semver","status":"affected"},{"version":"17.2","lessThan":"17.2.5","versionType":"semver","status":"affected"},{"version":"17.3","lessThan":"17.3.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-09-12T17:28:37.268844Z","id":"CVE-2024-8124","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1333"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-1333"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.4.0","versionEndExcluding":"17.1.7","matchCriteriaId":"C67622CA-831C-4C04-832E-2894B625EAC4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.4.0","versionEndExcluding":"17.1.7","matchCriteriaId":"856F2E51-CDD0-4E52-9127-FC7FD2DA53D1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.5","matchCriteriaId":"9DE9BFF3-C056-4146-A762-E34D60E10EDE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.5","matchCriteriaId":"1F428DA1-FB1C-4B14-A1E1-65177E7F4B10"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.3.2","matchCriteriaId":"D2F29B41-64CF-4CEF-8EDF-BBDBA2FFE8C1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.3.2","matchCriteriaId":"145E52CC-F503-446E-A760-1C01753DA938"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/480533","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2634880","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://about.gitlab.com/releases/2024/09/11/patch-release-gitlab-17-3-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2024-8631","sourceIdentifier":"cve@gitlab.com","published":"2024-09-12T17:15:06.230","lastModified":"2026-06-17T08:23:01.017","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A privilege escalation issue has been discovered in GitLab EE affecting all versions starting from 16.6 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. A user assigned the Admin Group Member custom role could have escalated their privileges to include other custom roles."},{"lang":"es","value":"Se ha descubierto un problema de escalada de privilegios en GitLab EE que afecta a todas las versiones a partir de la 16.6 anterior a la 17.1.7, de la 17.2 anterior a la 17.2.5 y de la 17.3 anterior a la 17.3.2. Un usuario al que se le haya asignado el rol personalizado de Miembro del grupo de administradores podría haber escalado sus privilegios para incluir otros roles personalizados."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.6","lessThan":"17.1.7","versionType":"semver","status":"affected"},{"version":"17.2","lessThan":"17.2.5","versionType":"semver","status":"affected"},{"version":"17.3","lessThan":"17.3.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":4.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-09-12T17:36:15.830099Z","id":"CVE-2024-8631","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-267"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.6.0","versionEndExcluding":"17.1.7","matchCriteriaId":"A82F9F0C-280A-4147-9B5E-D3AA1C3A8EA0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.6.0","versionEndExcluding":"17.1.7","matchCriteriaId":"ADF116ED-B1CD-4A59-92ED-9DF1C047C10F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.5","matchCriteriaId":"9DE9BFF3-C056-4146-A762-E34D60E10EDE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.5","matchCriteriaId":"1F428DA1-FB1C-4B14-A1E1-65177E7F4B10"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.3.2","matchCriteriaId":"D2F29B41-64CF-4CEF-8EDF-BBDBA2FFE8C1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.3.2","matchCriteriaId":"145E52CC-F503-446E-A760-1C01753DA938"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/462665","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2478469","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://about.gitlab.com/releases/2024/09/11/patch-release-gitlab-17-3-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2024-8635","sourceIdentifier":"cve@gitlab.com","published":"2024-09-12T17:15:06.437","lastModified":"2026-06-17T08:23:01.347","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A server-side request forgery issue has been discovered in GitLab EE affecting all versions starting from 16.8 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. It was possible for an attacker to make requests to internal resources using a custom Maven Dependency Proxy URL"},{"lang":"es","value":"Se ha descubierto un problema de server-side request forgery en GitLab EE que afecta a todas las versiones a partir de la 16.8 anterior a la 17.1.7, de la 17.2 anterior a la 17.2.5 y de la 17.3 anterior a la 17.3.2. Un atacante podía realizar solicitudes a recursos internos mediante una URL de proxy de dependencia de Maven personalizada"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.8","lessThan":"17.1.7","versionType":"semver","status":"affected"},{"version":"17.2","lessThan":"17.2.5","versionType":"semver","status":"affected"},{"version":"17.3","lessThan":"17.3.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","baseScore":7.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":4.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-09-12T17:20:26.116234Z","id":"CVE-2024-8635","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-918"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.8.0","versionEndExcluding":"17.1.7","matchCriteriaId":"D98A3E94-FD1A-4109-8A90-FD19A40CF007"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.8.0","versionEndExcluding":"17.1.7","matchCriteriaId":"FEA9798C-C168-4E92-AD2B-966A9F940A4D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.5","matchCriteriaId":"9DE9BFF3-C056-4146-A762-E34D60E10EDE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.5","matchCriteriaId":"1F428DA1-FB1C-4B14-A1E1-65177E7F4B10"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.3.2","matchCriteriaId":"D2F29B41-64CF-4CEF-8EDF-BBDBA2FFE8C1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.3.2","matchCriteriaId":"145E52CC-F503-446E-A760-1C01753DA938"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/455273","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://about.gitlab.com/releases/2024/09/11/patch-release-gitlab-17-3-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2024-8640","sourceIdentifier":"cve@gitlab.com","published":"2024-09-12T17:15:06.647","lastModified":"2026-06-17T08:23:02.037","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions starting from 16.11 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. Due to incomplete input filtering, it was possible to inject commands into a connected Cube server."},{"lang":"es","value":"Se ha descubierto un problema en GitLab EE que afecta a todas las versiones a partir de la 16.11 anterior a la 17.1.7, de la 17.2 anterior a la 17.2.5 y de la 17.3 anterior a la 17.3.2. Debido a un filtrado de entrada incompleto, era posible inyectar comandos en un servidor Cube conectado."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.11","lessThan":"17.1.7","versionType":"semver","status":"affected"},{"version":"17.2","lessThan":"17.2.5","versionType":"semver","status":"affected"},{"version":"17.3","lessThan":"17.3.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":8.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":6.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-09-12T17:29:55.753120Z","id":"CVE-2024-8640","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-77"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-77"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.11.0","versionEndExcluding":"17.1.7","matchCriteriaId":"149E71F2-8B52-435C-9DFC-9C1D1E889899"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.5","matchCriteriaId":"1F428DA1-FB1C-4B14-A1E1-65177E7F4B10"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.3.2","matchCriteriaId":"145E52CC-F503-446E-A760-1C01753DA938"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/486213","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2687770","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://about.gitlab.com/releases/2024/09/11/patch-release-gitlab-17-3-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2024-8754","sourceIdentifier":"cve@gitlab.com","published":"2024-09-12T17:15:06.917","lastModified":"2026-06-17T08:23:14.473","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE/CE affecting all versions from 16.9.7 prior to 17.1.7, 17.2 prior to 17.2.5, and 17.3 prior to 17.3.2. An improper input validation error allows attacker to squat on accounts via linking arbitrary unclaimed provider identities when JWT authentication is configured."},{"lang":"es","value":"Se ha descubierto un problema en GitLab EE/CE que afecta a todas las versiones desde la 16.9.7 hasta la 17.1.7, la 17.2 hasta la 17.2.5 y la 17.3 hasta la 17.3.2. Un error de validación de entrada incorrecto permite a un atacante apropiarse de cuentas mediante la vinculación de identidades de proveedores arbitrarias no reclamadas cuando se configura la autenticación JWT."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.9.7","lessThan":"17.1.7","versionType":"semver","status":"affected"},{"version":"17.2","lessThan":"17.2.5","versionType":"semver","status":"affected"},{"version":"17.3","lessThan":"17.3.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-09-12T17:19:51.513919Z","id":"CVE-2024-8754","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-642"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.9.7","versionEndExcluding":"17.1.7","matchCriteriaId":"CA47B0F3-2D32-4410-AC44-3635F290933C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.9.7","versionEndExcluding":"17.1.7","matchCriteriaId":"B2FAFF4E-0A2B-48DB-A49B-E13694603AB6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.5","matchCriteriaId":"9DE9BFF3-C056-4146-A762-E34D60E10EDE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.5","matchCriteriaId":"1F428DA1-FB1C-4B14-A1E1-65177E7F4B10"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.3.2","matchCriteriaId":"D2F29B41-64CF-4CEF-8EDF-BBDBA2FFE8C1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.3.2","matchCriteriaId":"145E52CC-F503-446E-A760-1C01753DA938"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/464062","source":"cve@gitlab.com","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2024-4472","sourceIdentifier":"cve@gitlab.com","published":"2024-09-12T19:15:04.233","lastModified":"2026-06-17T08:01:56.750","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab CE/EE affecting all versions starting from 16.5 prior to 17.1.7, starting from 17.2 prior to 17.2.5, and starting from 17.3 prior to 17.3.2, where dependency proxy credentials are retained in graphql Logs."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde la 16.5 anterior a la 17.1.7, desde la 17.2 anterior a la 17.2.5 y desde la 17.3 anterior a la 17.3.2, donde las credenciales del proxy de dependencia se conservan en los registros de graphql."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.5","lessThan":"17.1.7","versionType":"semver","status":"affected"},{"version":"17.3","lessThan":"17.3.2","versionType":"semver","status":"affected"},{"version":"17.2","lessThan":"17.2.5","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":4.0,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.5,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-09-12T18:56:49.348769Z","id":"CVE-2024-4472","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-532"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-532"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.5.0","versionEndExcluding":"17.1.7","matchCriteriaId":"B17D27F3-8232-494B-93F7-C90CD00B5DA4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.5.0","versionEndExcluding":"17.1.7","matchCriteriaId":"D05C0358-FAB5-49D6-8C19-4EC5B143F015"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.5","matchCriteriaId":"9DE9BFF3-C056-4146-A762-E34D60E10EDE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.5","matchCriteriaId":"1F428DA1-FB1C-4B14-A1E1-65177E7F4B10"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.3.2","matchCriteriaId":"D2F29B41-64CF-4CEF-8EDF-BBDBA2FFE8C1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.3.2","matchCriteriaId":"145E52CC-F503-446E-A760-1C01753DA938"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/460289","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2477062","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://about.gitlab.com/releases/2024/09/11/patch-release-gitlab-17-3-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2024-6678","sourceIdentifier":"cve@gitlab.com","published":"2024-09-12T19:15:04.453","lastModified":"2026-06-17T08:18:28.123","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab CE/EE affecting all versions starting from 8.14 prior to 17.1.7, starting from 17.2 prior to 17.2.5, and starting from 17.3 prior to 17.3.2, which allows an attacker to trigger a pipeline as an arbitrary user under certain circumstances."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde la 8.14 anterior a la 17.1.7, desde la 17.2 anterior a la 17.2.5 y desde la 17.3 anterior a la 17.3.2, que permite a un atacante activar una canalización como un usuario arbitrario en determinadas circunstancias."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"8.14","lessThan":"17.1.7","versionType":"semver","status":"affected"},{"version":"17.2","lessThan":"17.2.5","versionType":"semver","status":"affected"},{"version":"17.3","lessThan":"17.3.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":9.9,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.1,"impactScore":6.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-09-12T00:00:00+00:00","id":"CVE-2024-6678","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-290"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-290"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.14.0","versionEndExcluding":"17.1.7","matchCriteriaId":"24A0DD44-0B65-4BD6-9C61-A9E1AD3626CD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.14.0","versionEndExcluding":"17.1.7","matchCriteriaId":"DE92E4E8-63E0-481B-8826-B8E853C99BA8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.5","matchCriteriaId":"9DE9BFF3-C056-4146-A762-E34D60E10EDE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.5","matchCriteriaId":"1F428DA1-FB1C-4B14-A1E1-65177E7F4B10"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.3.2","matchCriteriaId":"D2F29B41-64CF-4CEF-8EDF-BBDBA2FFE8C1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.3.2","matchCriteriaId":"145E52CC-F503-446E-A760-1C01753DA938"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/471923","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2595495","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://about.gitlab.com/releases/2024/09/11/patch-release-gitlab-17-3-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2024-8311","sourceIdentifier":"cve@gitlab.com","published":"2024-09-12T19:15:04.683","lastModified":"2026-06-17T08:22:20.250","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered with pipeline execution policies in GitLab EE affecting all versions from 17.2 prior to 17.2.5, 17.3 prior to 17.3.2 which allows authenticated users to bypass variable overwrite protection via inclusion of a CI/CD template."},{"lang":"es","value":"Se descubrió un problema con las políticas de ejecución de canalización en GitLab EE que afecta a todas las versiones desde la 17.2 anterior a la 17.2.5 y desde la 17.3 anterior a la 17.3.2, lo que permite a los usuarios autenticados eludir la protección de sobrescritura de variables mediante la inclusión de una plantilla CI/CD."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.2","lessThan":"17.2.5","versionType":"semver","status":"affected"},{"version":"17.3","lessThan":"17.3.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-09-12T18:45:43.633943Z","id":"CVE-2024-8311","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-424"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.5","matchCriteriaId":"1F428DA1-FB1C-4B14-A1E1-65177E7F4B10"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.3.2","matchCriteriaId":"145E52CC-F503-446E-A760-1C01753DA938"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/479315","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://about.gitlab.com/releases/2024/09/11/patch-release-gitlab-17-3-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2024-8641","sourceIdentifier":"cve@gitlab.com","published":"2024-09-12T19:15:04.887","lastModified":"2026-06-17T08:23:02.147","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. It may have been possible for an attacker with a victim's CI_JOB_TOKEN to obtain a GitLab session token belonging to the victim."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones a partir de la 13.7 anterior a la 17.1.7, de la 17.2 anterior a la 17.2.5 y de la 17.3 anterior a la 17.3.2. Es posible que un atacante con el CI_JOB_TOKEN de una víctima haya podido obtener un token de sesión de GitLab perteneciente a la víctima."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"13.7","lessThan":"17.1.7","versionType":"semver","status":"affected"},{"version":"17.2","lessThan":"17.2.5","versionType":"semver","status":"affected"},{"version":"17.3","lessThan":"17.3.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L","baseScore":6.7,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":1.2,"impactScore":5.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-09-12T18:49:49.073195Z","id":"CVE-2024-8641","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-270"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"17.1.7","matchCriteriaId":"3A6EEE69-C698-4188-A6A8-E0382DC7E40D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"17.1.7","matchCriteriaId":"D28AADDC-2FAE-45AA-93D0-037EE1DF33E9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.5","matchCriteriaId":"9DE9BFF3-C056-4146-A762-E34D60E10EDE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.5","matchCriteriaId":"1F428DA1-FB1C-4B14-A1E1-65177E7F4B10"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.3.2","matchCriteriaId":"D2F29B41-64CF-4CEF-8EDF-BBDBA2FFE8C1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.3.2","matchCriteriaId":"145E52CC-F503-446E-A760-1C01753DA938"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/471954","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2595495","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://about.gitlab.com/releases/2024/09/11/patch-release-gitlab-17-3-2-released/","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2024-4283","sourceIdentifier":"cve@gitlab.com","published":"2024-09-16T22:15:20.650","lastModified":"2026-06-17T08:01:35.760","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions starting from 11.1 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2. Under certain conditions an open redirect vulnerability could allow for an account takeover by breaking the OAuth flow."},{"lang":"es","value":"Se ha descubierto un problema en GitLab EE que afecta a todas las versiones a partir de la 11.1 anterior a la 17.1.7, la 17.2 anterior a la 17.2.5 y la 17.3 anterior a la 17.3.2. En determinadas condiciones, una vulnerabilidad de redirección abierta podría permitir la apropiación de una cuenta interrumpiendo el flujo de OAuth."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"11.1","lessThan":"17.1.7","versionType":"semver","status":"affected"},{"version":"17.2","lessThan":"17.2.5","versionType":"semver","status":"affected"},{"version":"17.3","lessThan":"17.3.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-09-18T13:07:37.688258Z","id":"CVE-2024-4283","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-601"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-601"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.1.0","versionEndExcluding":"17.1.7","matchCriteriaId":"8D6519A2-EF66-4695-8CF6-420A17212C8D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.5","matchCriteriaId":"1F428DA1-FB1C-4B14-A1E1-65177E7F4B10"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.3.2","matchCriteriaId":"145E52CC-F503-446E-A760-1C01753DA938"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/458502","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2474286","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-6685","sourceIdentifier":"cve@gitlab.com","published":"2024-09-16T22:15:20.917","lastModified":"2026-06-17T08:18:28.773","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab CE/EE affecting all versions starting from 16.7 prior to 17.1.7, 17.2 prior to 17.2.5, and 17.3 prior to 17.3.2,  where group runners information was disclosed to unauthorised group members."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afectaba a todas las versiones desde la 16.7 anterior a la 17.1.7, la 17.2 anterior a la 17.2.5 y la 17.3 anterior a la 17.3.2, donde la información de los ejecutores del grupo se divulgaba a miembros del grupo no autorizados."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.7","lessThan":"17.1.7","versionType":"semver","status":"affected"},{"version":"17.3","lessThan":"17.2.5","versionType":"semver","status":"affected"},{"version":"17.3","lessThan":"17.3.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":3.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-09-17T15:25:49.220974Z","id":"CVE-2024-6685","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-639"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.7.0","versionEndExcluding":"17.1.7","matchCriteriaId":"EEE132B3-A511-4CF3-A9DD-C7C58ED02C9E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.7.0","versionEndExcluding":"17.1.7","matchCriteriaId":"ABCE2970-422F-49FA-ABA8-0FC00ECCE1FD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.5","matchCriteriaId":"9DE9BFF3-C056-4146-A762-E34D60E10EDE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.5","matchCriteriaId":"1F428DA1-FB1C-4B14-A1E1-65177E7F4B10"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.3.2","matchCriteriaId":"D2F29B41-64CF-4CEF-8EDF-BBDBA2FFE8C1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.3.2","matchCriteriaId":"145E52CC-F503-446E-A760-1C01753DA938"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/472012","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2584372","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-4278","sourceIdentifier":"cve@gitlab.com","published":"2024-09-26T07:15:02.603","lastModified":"2026-06-17T08:01:35.190","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An information disclosure issue has been discovered in GitLab EE affecting all versions starting from 16.5 prior to 17.2.8, from 17.3 prior to 17.3.4, and from 17.4 prior to 17.4.1. A maintainer could obtain a Dependency Proxy password by editing a certain Dependency Proxy setting."},{"lang":"es","value":"Se ha descubierto un problema de divulgación de información en GitLab EE que afecta a todas las versiones a partir de la 16.5 anterior a la 17.2.8, de la 17.3 anterior a la 17.3.4 y de la 17.4 anterior a la 17.4.1. Un mantenedor podría obtener una contraseña de proxy de dependencia editando una determinada configuración de proxy de dependencia."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.5","lessThan":"17.2.8","versionType":"semver","status":"affected"},{"version":"17.3","lessThan":"17.3.4","versionType":"semver","status":"affected"},{"version":"17.4","lessThan":"17.4.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N","baseScore":2.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-09-26T13:39:52.347038Z","id":"CVE-2024-4278","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-821"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.5.0","versionEndExcluding":"17.2.8","matchCriteriaId":"33ABDFC4-58F2-4F3E-B04C-CA977443E5ED"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.3.4","matchCriteriaId":"27CB6247-D7EE-40BB-BF4A-8CE5350E31BF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.4.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"3AC3130C-A3AA-403A-85D9-92FD2B8BC091"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/458484","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2466205","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-4099","sourceIdentifier":"cve@gitlab.com","published":"2024-09-26T23:15:02.873","lastModified":"2026-06-17T08:01:07.430","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.2.8, from 17.3 prior to 17.3.4, and from 17.4 prior to 17.4.1. An AI feature was found to read unsanitized content in a way that could have allowed an attacker to hide prompt injection."},{"lang":"es","value":"Se ha descubierto un problema en GitLab EE que afecta a todas las versiones a partir de la 16.0 anterior a la 17.2.8, de la 17.3 anterior a la 17.3.4 y de la 17.4 anterior a la 17.4.1. Se descubrió que una función de IA leía contenido no desinfectado de una manera que podría haber permitido a un atacante ocultar la inyección de mensajes."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.0","lessThan":"17.2.8","versionType":"semver","status":"affected"},{"version":"17.3","lessThan":"17.3.4","versionType":"semver","status":"affected"},{"version":"17.4","lessThan":"17.4.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N","baseScore":3.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-09-27T15:48:40.453873Z","id":"CVE-2024-4099","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-116"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-116"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"17.2.8","matchCriteriaId":"CA2EE5DB-7A88-4C5D-A2F0-60AC99FC0F19"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.3.4","matchCriteriaId":"27CB6247-D7EE-40BB-BF4A-8CE5350E31BF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.4.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"3AC3130C-A3AA-403A-85D9-92FD2B8BC091"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/457798","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2459597","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-8974","sourceIdentifier":"cve@gitlab.com","published":"2024-09-26T23:15:03.083","lastModified":"2026-06-17T08:23:39.717","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Information disclosure in Gitlab EE/CE affecting all versions from 15.6 prior to 17.2.8, 17.3 prior to 17.3.4, and 17.4 prior to 17.4.1 in specific conditions it was possible to disclose to an unauthorised user the path of a private project.\""},{"lang":"es","value":"Divulgación de información en Gitlab EE/CE que afecta a todas las versiones desde la 15.6 anterior a la 17.2.8, la 17.3 anterior a la 17.3.4 y la 17.4 anterior a la 17.4.1: en condiciones específicas era posible revelar a un usuario no autorizado la ruta de un proyecto privado."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.6","lessThan":"17.2.8","versionType":"semver","status":"affected"},{"version":"17.3","lessThan":"17.3.4","versionType":"semver","status":"affected"},{"version":"17.4","lessThan":"17.4.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N","baseScore":2.6,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-09-27T15:46:36.689310Z","id":"CVE-2024-8974","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-684"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.6.0","versionEndExcluding":"17.2.8","matchCriteriaId":"CF1537ED-2DE1-4781-ABD4-64816E5CE8D4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.6.0","versionEndExcluding":"17.2.8","matchCriteriaId":"84ADBC3D-7A98-453A-8F34-FF810842EDCA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.3.4","matchCriteriaId":"FBB47BC0-FE38-4628-B4C2-DA89EC467CF8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.3.4","matchCriteriaId":"27CB6247-D7EE-40BB-BF4A-8CE5350E31BF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.4.0:*:*:*:community:*:*:*","matchCriteriaId":"4FEBC1F7-0AAA-4CA2-B099-3F4218900FB3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.4.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"3AC3130C-A3AA-403A-85D9-92FD2B8BC091"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/482843","source":"cve@gitlab.com","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2023-3441","sourceIdentifier":"cve@gitlab.com","published":"2024-10-01T10:15:02.997","lastModified":"2026-06-17T06:14:04.787","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE/CE affecting all versions starting from 8.0 before 16.4. The product did not sufficiently warn about security implications of granting merge rights to protected branches."},{"lang":"es","value":"Se ha descubierto un problema en GitLab EE/CE que afecta a todas las versiones a partir de la 8.0 hasta la 16.4. El producto no advertía lo suficiente sobre las implicaciones de seguridad de otorgar derechos de fusión a ramas protegidas."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"8.0","lessThan":"16.4","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:N","baseScore":6.6,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.3,"impactScore":4.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.3,"impactScore":6.0}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-10-01T13:27:42.900394Z","id":"CVE-2023-3441","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-213"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.0.0","versionEndExcluding":"16.4.0","matchCriteriaId":"694EEF46-A2C8-4B06-B451-5CC42BF92AE9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.0.0","versionEndExcluding":"16.4.0","matchCriteriaId":"3B030C13-3602-40BD-954E-722280A2F12D"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/416482","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/417284","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/2033561","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://hackerone.com/reports/2041385","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-8977","sourceIdentifier":"cve@gitlab.com","published":"2024-10-10T10:15:08.367","lastModified":"2026-06-17T08:23:40.040","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions starting from 15.10 prior to 17.2.9, from 17.3 prior to 17.3.5, and from 17.4 prior to 17.4.2. Instances with Product Analytics Dashboard configured and enabled could be vulnerable to SSRF attacks."},{"lang":"es","value":"Se ha descubierto un problema en GitLab EE que afecta a todas las versiones desde la 15.10 hasta la 17.2.9, desde la 17.3 hasta la 17.3.5 y desde la 17.4 hasta la 17.4.2. Las instancias con el Panel de análisis de productos configurado y habilitado podrían ser vulnerables a ataques SSRF."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.10","lessThan":"17.2.9","versionType":"semver","status":"affected"},{"version":"17.3","lessThan":"17.3.5","versionType":"semver","status":"affected"},{"version":"17.4","lessThan":"17.4.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N","baseScore":8.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.8,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-10-10T13:53:25.861161Z","id":"CVE-2024-8977","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-918"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.10","versionEndExcluding":"17.2.9","matchCriteriaId":"0B274D57-4F72-44C1-97A2-EBC63B6ED92F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.3.5","matchCriteriaId":"9A005AE5-1C1A-4515-9695-A502092BB75A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.4.0","versionEndExcluding":"17.4.2","matchCriteriaId":"08991976-707A-4A7B-863D-766928E74FF7"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/491060","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2697456","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-9596","sourceIdentifier":"cve@gitlab.com","published":"2024-10-10T10:15:08.563","lastModified":"2026-06-17T08:24:53.567","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions starting from 16.6 prior to 17.2.9, from 17.3 prior to 17.3.5, and from 17.4 prior to 17.4.2. It was possible for an unauthenticated attacker to determine the GitLab version number for a GitLab instance."},{"lang":"es","value":"Se ha descubierto un problema en GitLab EE que afecta a todas las versiones desde la 16.6 hasta la 17.2.9, desde la 17.3 hasta la 17.3.5 y desde la 17.4 hasta la 17.4.2. Un atacante no autenticado podía determinar el número de versión de GitLab para una instancia de GitLab."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.6","lessThan":"17.2.9","versionType":"semver","status":"affected"},{"version":"17.3","lessThan":"17.3.5","versionType":"semver","status":"affected"},{"version":"17.4","lessThan":"17.4.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":3.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-10-10T13:54:54.807097Z","id":"CVE-2024-9596","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-540"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.6.0","versionEndExcluding":"17.2.9","matchCriteriaId":"397C435D-5C6A-4670-ACE8-EE601D6E124C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.3.5","matchCriteriaId":"9A005AE5-1C1A-4515-9695-A502092BB75A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.4.0","versionEndExcluding":"17.4.2","matchCriteriaId":"08991976-707A-4A7B-863D-766928E74FF7"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/493355","source":"cve@gitlab.com","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2024-9623","sourceIdentifier":"cve@gitlab.com","published":"2024-10-10T10:15:08.770","lastModified":"2026-06-17T08:24:56.317","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab CE/EE affecting all versions starting from 8.16 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2, which allows deploy keys to push to an archived repository."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde la 8.16 anterior a la 17.2.9, desde la 17.3 anterior a la 17.3.5 y desde la 17.4 anterior a la 17.4.2, que permite que las claves de implementación se envíen a un repositorio archivado."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"8.16","lessThan":"17.2.9","versionType":"semver","status":"affected"},{"version":"17.3","lessThan":"17.3.5","versionType":"semver","status":"affected"},{"version":"17.4","lessThan":"17.4.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-10-10T12:52:29.418044Z","id":"CVE-2024-9623","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.16.0","versionEndExcluding":"17.2.9","matchCriteriaId":"15F65C4A-4615-4781-BCA0-398A945E97B6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.16.0","versionEndExcluding":"17.2.9","matchCriteriaId":"1B30FF3D-4A27-4426-935B-6752663943A7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.3.5","matchCriteriaId":"EE7140D0-5D8A-4EDA-91AF-5F14BC4F6307"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.3.5","matchCriteriaId":"9A005AE5-1C1A-4515-9695-A502092BB75A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.4.0","versionEndExcluding":"17.4.2","matchCriteriaId":"7132410B-A160-4C18-8BB6-E53C6A0F35D7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.4.0","versionEndExcluding":"17.4.2","matchCriteriaId":"08991976-707A-4A7B-863D-766928E74FF7"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/459995","source":"cve@gitlab.com","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2024-6530","sourceIdentifier":"cve@gitlab.com","published":"2024-10-10T12:15:04.500","lastModified":"2026-06-17T08:18:11.777","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 17.1 prior 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2. When adding a authorizing an application, it can be made to render as HTML under specific circumstances."},{"lang":"es","value":"Se ha descubierto un problema de cross site scripting en GitLab que afecta a todas las versiones a partir de la 17.1 anterior a la 17.2.9, a partir de la 17.3 anterior a la 17.3.5 y a partir de la 17.4 anterior a la 17.4.2. Al agregar una autorización a una aplicación, se puede hacer que se represente como HTML en circunstancias específicas."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.1","lessThan":"17.2.9","versionType":"semver","status":"affected"},{"version":"17.3","lessThan":"17.3.5","versionType":"semver","status":"affected"},{"version":"17.4","lessThan":"17.4.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-10-10T13:32:17.329029Z","id":"CVE-2024-6530","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"17.2.9","matchCriteriaId":"F652CF2C-F8B1-4A43-8180-64F317F3E495"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"17.2.9","matchCriteriaId":"904CD375-0E97-4697-9B81-6C21E180B5B6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.3.5","matchCriteriaId":"EE7140D0-5D8A-4EDA-91AF-5F14BC4F6307"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.3.5","matchCriteriaId":"9A005AE5-1C1A-4515-9695-A502092BB75A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.4.0","versionEndExcluding":"17.4.2","matchCriteriaId":"7132410B-A160-4C18-8BB6-E53C6A0F35D7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.4.0","versionEndExcluding":"17.4.2","matchCriteriaId":"08991976-707A-4A7B-863D-766928E74FF7"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/471049","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2567533","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-5005","sourceIdentifier":"cve@gitlab.com","published":"2024-10-11T13:15:16.317","lastModified":"2026-06-17T08:14:53.543","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered discovered in GitLab EE/CE affecting all versions starting from 11.4 before 17.2.9, all versions starting from 17.3 before 17.3.5, all versions starting from 17.4 before 17.4.2 It was possible for guest users to disclose project templates using the API."},{"lang":"es","value":"Se descubrió un problema en GitLab EE/CE que afectaba a todas las versiones desde la 11.4 hasta la 17.2.9, todas las versiones desde la 17.3 hasta la 17.3.5 y todas las versiones desde la 17.4 hasta la 17.4.2. Los usuarios invitados podían divulgar plantillas de proyecto mediante la API."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"11.4","lessThan":"17.2.9","versionType":"semver","status":"affected"},{"version":"17.3","lessThan":"17.3.5","versionType":"semver","status":"affected"},{"version":"17.4","lessThan":"17.4.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-10-11T13:41:47.000870Z","id":"CVE-2024-5005","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-684"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"17.2.9","matchCriteriaId":"11077447-D01B-410A-9B49-C712B2B4A57B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"17.2.9","matchCriteriaId":"57B101F2-4669-4EC7-BE80-2F1515B188DE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.3.5","matchCriteriaId":"EE7140D0-5D8A-4EDA-91AF-5F14BC4F6307"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.3.5","matchCriteriaId":"9A005AE5-1C1A-4515-9695-A502092BB75A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.4.0","versionEndExcluding":"17.4.2","matchCriteriaId":"7132410B-A160-4C18-8BB6-E53C6A0F35D7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.4.0","versionEndExcluding":"17.4.2","matchCriteriaId":"08991976-707A-4A7B-863D-766928E74FF7"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/462108","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/2501461","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-8970","sourceIdentifier":"cve@gitlab.com","published":"2024-10-11T13:15:17.270","lastModified":"2026-06-17T08:23:39.393","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab CE/EE affecting all versions starting from 11.6 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2, which allows an attacker to trigger a pipeline as another user under certain circumstances."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde la 11.6 anterior a la 17.2.9, desde la 17.3 anterior a la 17.3.5 y desde la 17.4 anterior a la 17.4.2, que permite a un atacante activar una canalización como otro usuario en determinadas circunstancias."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"11.6","lessThan":"17.2.9","versionType":"semver","status":"affected"},{"version":"17.3","lessThan":"17.3.5","versionType":"semver","status":"affected"},{"version":"17.4","lessThan":"17.4.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N","baseScore":8.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.8,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-10-11T13:37:30.722354Z","id":"CVE-2024-8970","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"17.2.9","matchCriteriaId":"CAA24882-E6F4-4A5D-9EA9-08F574BC53C7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"17.2.9","matchCriteriaId":"ED238AD1-F7B6-4A3F-87AB-87B3FDE35181"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.3.5","matchCriteriaId":"EE7140D0-5D8A-4EDA-91AF-5F14BC4F6307"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.3.5","matchCriteriaId":"9A005AE5-1C1A-4515-9695-A502092BB75A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.4.0","versionEndExcluding":"17.4.2","matchCriteriaId":"7132410B-A160-4C18-8BB6-E53C6A0F35D7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.4.0","versionEndExcluding":"17.4.2","matchCriteriaId":"08991976-707A-4A7B-863D-766928E74FF7"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/490916","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2724948","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-9164","sourceIdentifier":"cve@gitlab.com","published":"2024-10-11T13:15:17.700","lastModified":"2026-06-17T08:24:04.557","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab EE affecting all versions starting from 12.5 prior to 17.2.9, starting from 17.3, prior to 17.3.5, and starting from 17.4 prior to 17.4.2, which allows running pipelines on arbitrary branches."},{"lang":"es","value":"Se descubrió un problema en GitLab EE que afecta a todas las versiones desde la 12.5 anterior a la 17.2.9, desde la 17.3, anterior a la 17.3.5 y desde la 17.4 anterior a la 17.4.2, lo que permite ejecutar pipelines en ramas arbitrarias."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"12.5","lessThan":"17.2.9","versionType":"semver","status":"affected"},{"version":"17.3","lessThan":"17.3.5","versionType":"semver","status":"affected"},{"version":"17.4","lessThan":"17.4.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N","baseScore":9.6,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-10-11T13:42:31.081761Z","id":"CVE-2024-9164","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-306"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.5.0","versionEndExcluding":"17.2.9","matchCriteriaId":"6A3DE32E-282D-463C-9117-E458316D4272"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.5.0","versionEndExcluding":"17.2.9","matchCriteriaId":"3352CF6D-12DF-434A-B514-A956C733FEEE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.3.5","matchCriteriaId":"EE7140D0-5D8A-4EDA-91AF-5F14BC4F6307"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.3.5","matchCriteriaId":"9A005AE5-1C1A-4515-9695-A502092BB75A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.4.0","versionEndExcluding":"17.4.2","matchCriteriaId":"7132410B-A160-4C18-8BB6-E53C6A0F35D7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.4.0","versionEndExcluding":"17.4.2","matchCriteriaId":"08991976-707A-4A7B-863D-766928E74FF7"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/493946","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2711204","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-6826","sourceIdentifier":"cve@gitlab.com","published":"2024-10-24T10:15:02.717","lastModified":"2026-06-17T08:18:47.517","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 11.2 before 17.3.6, 17.4 before 17.4.3, and 17.5 before 17.5.1. A denial of service could occur via importing a malicious crafted XML manifest file."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde la 11.2 hasta la 17.3.6, desde la 17.4 hasta la 17.4.3 y desde la 17.5 hasta la 17.5.1. Se podría producir una denegación de servicio al importar un archivo de manifiesto XML manipulado con fines malintencionados."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"11.2","lessThan":"17.3.6","versionType":"semver","status":"affected"},{"version":"17.4","lessThan":"17.4.3","versionType":"semver","status":"affected"},{"version":"17.5","lessThan":"17.5.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-10-24T12:56:34.924405Z","id":"CVE-2024-6826","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.2.0","versionEndExcluding":"17.3.6","matchCriteriaId":"2DAE658B-EAB6-42B9-990F-A9FF15696831"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.2.0","versionEndExcluding":"17.3.6","matchCriteriaId":"FB2E46F3-3C6D-4498-B185-6F47A3299044"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.4.0","versionEndExcluding":"17.4.3","matchCriteriaId":"7D8C07CE-4771-4620-96B3-17EA81B6AAF4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.4.0","versionEndExcluding":"17.4.3","matchCriteriaId":"F4373294-4C6B-4299-88D3-D3568A285A56"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.5.0:*:*:*:community:*:*:*","matchCriteriaId":"97618D0B-B13A-4111-A78E-3BCB4F023382"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.5.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"603F1273-E30C-4EBB-AFEA-6713D273C4F3"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/472928","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/2571364","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-8312","sourceIdentifier":"cve@gitlab.com","published":"2024-10-24T10:15:03.630","lastModified":"2026-06-17T08:22:20.370","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 17.3.6, 17.4 before 17.4.3, and 17.5 before 17.5.1. An attacker could inject HTML into the Global Search field on a diff view leading to XSS."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde la 15.10 hasta la 17.3.6, la 17.4 hasta la 17.4.3 y la 17.5 hasta la 17.5.1. Un atacante podría inyectar HTML en el campo de búsqueda global en una vista de diferencias, lo que provocaría un XSS."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.10","lessThan":"17.3.6","versionType":"semver","status":"affected"},{"version":"17.4","lessThan":"17.4.3","versionType":"semver","status":"affected"},{"version":"17.5","lessThan":"17.5.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-10-24T12:57:06.277953Z","id":"CVE-2024-8312","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.10.0","versionEndExcluding":"17.3.6","matchCriteriaId":"AF0E11FA-689E-468B-B427-8B68AEF145B2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.10.0","versionEndExcluding":"17.3.6","matchCriteriaId":"0826BB0F-5424-4A9A-81A2-5894EFC218DE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.4.0","versionEndExcluding":"17.4.3","matchCriteriaId":"7D8C07CE-4771-4620-96B3-17EA81B6AAF4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.4.0","versionEndExcluding":"17.4.3","matchCriteriaId":"F4373294-4C6B-4299-88D3-D3568A285A56"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.5.0:*:*:*:community:*:*:*","matchCriteriaId":"97618D0B-B13A-4111-A78E-3BCB4F023382"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.5.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"603F1273-E30C-4EBB-AFEA-6713D273C4F3"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/481819","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/2659386","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-8180","sourceIdentifier":"cve@gitlab.com","published":"2024-11-14T11:15:04.933","lastModified":"2026-06-17T08:22:04.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.3.7, 17.4 before 17.4.4, and 17.5 before 17.5.2. Improper output encoding could lead to XSS if CSP is not enabled."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde la 17.3 hasta la 17.3.7, desde la 17.4 hasta la 17.4.4 y desde la 17.5 hasta la 17.5.2. Una codificación de salida incorrecta podría provocar un error XSS si no se habilita CSP."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.3","lessThan":"17.3.7","versionType":"semver","status":"affected"},{"version":"17.4","lessThan":"17.4.4","versionType":"semver","status":"affected"},{"version":"17.5","lessThan":"17.5.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-11-14T18:53:46.673350Z","id":"CVE-2024-8180","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.3.7","matchCriteriaId":"74E30536-DC70-4B29-9949-A62CD91CFD30"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.3.7","matchCriteriaId":"29B62E43-F700-4612-8B62-CCE84B94D47A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.4.0","versionEndExcluding":"17.4.4","matchCriteriaId":"1F7F4C7C-334F-4015-AC25-74FCE4BAD311"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.4.0","versionEndExcluding":"17.4.4","matchCriteriaId":"7FF0B7C7-E0BD-4C6C-8938-0082CBE64847"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.5.0","versionEndExcluding":"17.5.2","matchCriteriaId":"34CDEED3-E7FB-4620-8E07-E4766F9B6593"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.5.0","versionEndExcluding":"17.5.2","matchCriteriaId":"DA99FF56-0441-464D-B369-CF72EF9EEDC7"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2024/11/13/patch-release-gitlab-17-5-2-released/#html-injection-in-vulnerability-code-flow-could-lead-to-xss-on-self-hosted-instances","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/480720","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2654010","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-9693","sourceIdentifier":"cve@gitlab.com","published":"2024-11-14T11:15:05.210","lastModified":"2026-06-17T08:25:04.533","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab CE/EE affecting all versions starting from 16.0 prior to 17.3.7, starting from 17.4 prior to 17.4.4, and starting from 17.5 prior to 17.5.2, which could have allowed unauthorized access to the Kubernetes agent in a cluster under specific configurations."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afectaba a todas las versiones desde la 16.0 anterior a la 17.3.7, desde la 17.4 anterior a la 17.4.4 y desde la 17.5 anterior a la 17.5.2, lo que podría haber permitido el acceso no autorizado al agente de Kubernetes en un clúster con configuraciones específicas."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.0","lessThan":"17.3.7","versionType":"semver","status":"affected"},{"version":"17.4.0","lessThan":"17.4.4","versionType":"semver","status":"affected"},{"version":"17.5.0","lessThan":"17.5.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":8.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":6.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-11-14T00:00:00+00:00","id":"CVE-2024-9693","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"17.3.7","matchCriteriaId":"5268F847-0BD4-4419-A504-861924E3E773"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"17.3.7","matchCriteriaId":"99100D1B-7A1C-44A0-89AD-23A4ADA34995"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.4.0","versionEndExcluding":"17.4.4","matchCriteriaId":"1F7F4C7C-334F-4015-AC25-74FCE4BAD311"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.4.0","versionEndExcluding":"17.4.4","matchCriteriaId":"7FF0B7C7-E0BD-4C6C-8938-0082CBE64847"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.5.0","versionEndExcluding":"17.5.2","matchCriteriaId":"34CDEED3-E7FB-4620-8E07-E4766F9B6593"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.5.0","versionEndExcluding":"17.5.2","matchCriteriaId":"DA99FF56-0441-464D-B369-CF72EF9EEDC7"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/497449","source":"cve@gitlab.com","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2024-7404","sourceIdentifier":"cve@gitlab.com","published":"2024-11-14T13:15:05.050","lastModified":"2026-06-17T08:20:01.790","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab CE/EE affecting all versions starting from 17.2 prior to 17.3.7, starting from 17.4 prior to 17.4.4 and starting from 17.5 prior to 17.5.2, which could have allowed an attacker gaining full API access as the victim via the Device OAuth flow."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde la 17.2 anterior a la 17.3.7, desde la 17.4 anterior a la 17.4.4 y desde la 17.5 anterior a la 17.5.2, lo que podría haber permitido que un atacante obtuviera acceso completo a la API como víctima a través del flujo OAuth del dispositivo."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.2","lessThan":"17.3.7","versionType":"semver","status":"affected"},{"version":"17.4","lessThan":"17.4.4","versionType":"semver","status":"affected"},{"version":"17.5","lessThan":"17.5.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N","baseScore":6.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-11-14T15:07:52.970956Z","id":"CVE-2024-7404","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1021"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.3.7","matchCriteriaId":"4CA2FC71-DC68-42DA-B9E7-AE64EFC48674"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.3.7","matchCriteriaId":"F95AF41C-A7D0-4401-881B-50456A18662E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.4.0","versionEndExcluding":"17.4.4","matchCriteriaId":"1F7F4C7C-334F-4015-AC25-74FCE4BAD311"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.4.0","versionEndExcluding":"17.4.4","matchCriteriaId":"7FF0B7C7-E0BD-4C6C-8938-0082CBE64847"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.5.0","versionEndExcluding":"17.5.2","matchCriteriaId":"34CDEED3-E7FB-4620-8E07-E4766F9B6593"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.5.0","versionEndExcluding":"17.5.2","matchCriteriaId":"DA99FF56-0441-464D-B369-CF72EF9EEDC7"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2024/11/13/patch-release-gitlab-17-5-2-released/#device-oauth-flow-allows-for-cross-window-forgery","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/476670","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2627925","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-8648","sourceIdentifier":"cve@gitlab.com","published":"2024-11-14T13:15:05.323","lastModified":"2026-06-17T08:23:02.957","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 16 before 17.3.7, 17.4 before 17.4.4, and 17.5 before 17.5.2. The vulnerability could allow an attacker to inject malicious JavaScript code in Analytics Dashboards through a specially crafted URL."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde la 16 hasta la 17.3.7, la 17.4 hasta la 17.4.4 y la 17.5 hasta la 17.5.2. La vulnerabilidad podría permitir que un atacante inyecte código JavaScript malicioso en los paneles de Analytics a través de una URL especialmente manipulada."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16","lessThan":"17.3.7","versionType":"semver","status":"affected"},{"version":"17.4","lessThan":"17.4.4","versionType":"semver","status":"affected"},{"version":"17.5","lessThan":"17.5.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-11-14T18:53:37.269594Z","id":"CVE-2024-8648","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"17.3.7","matchCriteriaId":"5268F847-0BD4-4419-A504-861924E3E773"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"17.3.7","matchCriteriaId":"99100D1B-7A1C-44A0-89AD-23A4ADA34995"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.4.0","versionEndExcluding":"17.4.4","matchCriteriaId":"1F7F4C7C-334F-4015-AC25-74FCE4BAD311"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.4.0","versionEndExcluding":"17.4.4","matchCriteriaId":"7FF0B7C7-E0BD-4C6C-8938-0082CBE64847"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.5.0","versionEndExcluding":"17.5.2","matchCriteriaId":"34CDEED3-E7FB-4620-8E07-E4766F9B6593"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.5.0","versionEndExcluding":"17.5.2","matchCriteriaId":"DA99FF56-0441-464D-B369-CF72EF9EEDC7"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2024/11/13/patch-release-gitlab-17-5-2-released/#stored-xss-through-javascript-url-in-analytics-dashboards","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/486220","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2683863","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-9633","sourceIdentifier":"cve@gitlab.com","published":"2024-11-14T14:15:19.660","lastModified":"2026-06-17T08:24:57.413","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.3 before 17.4.2, all versions starting from 17.5 before 17.5.4, all versions starting from 17.6 before 17.6.2. This issue allows an attacker to create a group with a name matching an existing unique Pages domain, potentially leading to domain confusion attacks."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones a partir de la 16.3 hasta la 17.3.7, a todas las versiones a partir de la 17.4 hasta la 17.4.4 y a todas las versiones a partir de la 17.5 hasta la 17.5.2. Este problema permite a un atacante crear un grupo con un nombre que coincida con un dominio de Pages único existente, lo que puede provocar ataques de confusión de dominios."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.3","lessThan":"17.4.2","versionType":"semver","status":"affected"},{"version":"17.5","lessThan":"17.5.4","versionType":"semver","status":"affected"},{"version":"17.6","lessThan":"17.6.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":3.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":1.6,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-11-14T14:40:30.942765Z","id":"CVE-2024-9633","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-708"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.3.0","versionEndExcluding":"17.4.2","matchCriteriaId":"4092FE04-AAC4-4867-8805-7FEF4E2C4B47"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.3.0","versionEndExcluding":"17.4.2","matchCriteriaId":"7A1E75BC-13E3-46A0-98A2-2D47F0B30E09"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.5.0","versionEndExcluding":"17.5.4","matchCriteriaId":"1587202E-2392-46F3-BE79-00BE065AD2AE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.5.0","versionEndExcluding":"17.5.4","matchCriteriaId":"0A13BB0D-E1E4-4C0B-A823-E661591D4E4F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.6.0","versionEndExcluding":"17.6.2","matchCriteriaId":"1E994AE4-0E47-4CF0-93B2-C28A5E274059"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.6.0","versionEndExcluding":"17.6.2","matchCriteriaId":"01C8A373-615F-45FE-8AF7-BB053EC77D82"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/498257","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2759470","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-11668","sourceIdentifier":"cve@gitlab.com","published":"2024-11-26T19:15:22.027","lastModified":"2026-06-17T06:58:11.750","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 16.11 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. Long-lived connections could potentially bypass authentication controls, allowing unauthorized access to streaming results."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde la 16.11 hasta la 17.4.5, desde la 17.5 hasta la 17.5.3 y desde la 17.6 hasta la 17.6.1. Las conexiones de larga duración podrían eludir los controles de autenticación, lo que permitiría el acceso no autorizado a los resultados de streaming."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.11","lessThan":"17.4.5","versionType":"semver","status":"affected"},{"version":"17.5","lessThan":"17.5.3","versionType":"semver","status":"affected"},{"version":"17.6","lessThan":"17.6.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","baseScore":4.2,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":2.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-11-26T18:42:30.596376Z","id":"CVE-2024-11668","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-613"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.11.0","versionEndExcluding":"17.4.5","matchCriteriaId":"43C3FFE7-F6D3-4DB9-B0BB-0BCA085E4AB7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.11.0","versionEndExcluding":"17.4.5","matchCriteriaId":"A1D2CF9A-94F8-4C5F-9FE5-C7E4CBA33EFC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.5.0","versionEndExcluding":"17.5.3","matchCriteriaId":"5C1F85A0-709A-4C88-9C40-93D3C47AFD54"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.5.0","versionEndExcluding":"17.5.3","matchCriteriaId":"305F5CB5-5B11-4AA7-ABAE-D4B9A05F6B4A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.6.0:*:*:*:community:*:*:*","matchCriteriaId":"3A39B04B-D109-467A-82E1-3FE6CBA48FEE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.6.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"1212AE23-98AB-4E7A-AAB5-0AD266DFC7D4"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/456922","source":"cve@gitlab.com","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2024-11669","sourceIdentifier":"cve@gitlab.com","published":"2024-11-26T19:15:22.367","lastModified":"2026-06-17T06:58:11.873","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab CE/EE affecting all versions from 16.9.8 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. Certain API endpoints could potentially allow unauthorized access to sensitive data due to overly broad application of token scopes."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afectaba a todas las versiones desde la 16.9.8 hasta la 17.4.5, desde la 17.5 hasta la 17.5.3 y desde la 17.6 hasta la 17.6.1. Ciertos endpoints de API podrían permitir el acceso no autorizado a datos confidenciales debido a la aplicación demasiado amplia de los alcances de los tokens."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.9.8","lessThan":"17.4.5","versionType":"semver","status":"affected"},{"version":"17.5","lessThan":"17.5.3","versionType":"semver","status":"affected"},{"version":"17.6","lessThan":"17.6.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-11-29T00:00:00+00:00","id":"CVE-2024-11669","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.9.8","versionEndExcluding":"17.4.5","matchCriteriaId":"555160BC-DF24-4025-ACB6-4B79907F7094"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.9.8","versionEndExcluding":"17.4.5","matchCriteriaId":"54A6B5EA-1A08-4D43-9C2B-CAC5DE109873"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.5.0","versionEndExcluding":"17.5.3","matchCriteriaId":"5C1F85A0-709A-4C88-9C40-93D3C47AFD54"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.5.0","versionEndExcluding":"17.5.3","matchCriteriaId":"305F5CB5-5B11-4AA7-ABAE-D4B9A05F6B4A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.6.0:*:*:*:community:*:*:*","matchCriteriaId":"3A39B04B-D109-467A-82E1-3FE6CBA48FEE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.6.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"1212AE23-98AB-4E7A-AAB5-0AD266DFC7D4"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/501528","source":"cve@gitlab.com","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2024-11828","sourceIdentifier":"cve@gitlab.com","published":"2024-11-26T19:15:22.910","lastModified":"2026-06-17T06:58:31.890","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A denial of service (DoS) condition was discovered in GitLab CE/EE affecting all versions from 13.2.4 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. By leveraging this vulnerability an attacker could create a DoS condition by sending crafted API calls. This was a regression of an earlier patch."},{"lang":"es","value":"Se descubrió una condición de denegación de servicio (DoS) en GitLab CE/EE que afectaba a todas las versiones desde la 13.2.4 hasta la 17.4.5, desde la 17.5 hasta la 17.5.3 y desde la 17.6 hasta la 17.6.1. Al aprovechar esta vulnerabilidad, un atacante podría crear una condición de denegación de servicio mediante el envío de llamadas a la API manipuladas. Se trataba de una regresión de un parche anterior."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"13.2.4","lessThan":"17.4.5","versionType":"semver","status":"affected"},{"version":"17.5","lessThan":"17.5.3","versionType":"semver","status":"affected"},{"version":"17.6","lessThan":"17.6.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-11-26T19:52:25.979086Z","id":"CVE-2024-11828","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-407"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.2.4","versionEndExcluding":"17.4.5","matchCriteriaId":"72B7025D-4FC9-45E0-9C5D-53B7E3427A28"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.2.4","versionEndExcluding":"17.4.5","matchCriteriaId":"D1F2B993-9A01-41DD-ABC8-158559A03548"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.5.0","versionEndExcluding":"17.5.3","matchCriteriaId":"5C1F85A0-709A-4C88-9C40-93D3C47AFD54"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.5.0","versionEndExcluding":"17.5.3","matchCriteriaId":"305F5CB5-5B11-4AA7-ABAE-D4B9A05F6B4A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.6.0:*:*:*:community:*:*:*","matchCriteriaId":"3A39B04B-D109-467A-82E1-3FE6CBA48FEE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.6.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"1212AE23-98AB-4E7A-AAB5-0AD266DFC7D4"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/443559","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2380264","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-8114","sourceIdentifier":"cve@gitlab.com","published":"2024-11-26T19:15:31.660","lastModified":"2026-06-17T08:21:55.160","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 8.12 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. This issue allows an attacker with access to a victim's Personal Access Token (PAT) to escalate privileges."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde la 8.12 hasta la 17.4.5, la 17.5 hasta la 17.5.3 y la 17.6 hasta la 17.6.1. Este problema permite que un atacante con acceso al token de acceso personal (PAT) de una víctima aumente los privilegios."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"8.12","lessThan":"17.4.5","versionType":"semver","status":"affected"},{"version":"17.5","lessThan":"17.5.3","versionType":"semver","status":"affected"},{"version":"17.6","lessThan":"17.6.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N","baseScore":8.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.8,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-11-29T00:00:00+00:00","id":"CVE-2024-8114","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.12.0","versionEndExcluding":"17.4.5","matchCriteriaId":"D229997A-33B2-44AC-A257-61E00353019C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.12.0","versionEndExcluding":"17.4.5","matchCriteriaId":"8AA194ED-6663-4D99-90C7-4CDBCAF0AE12"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.5.0","versionEndExcluding":"17.5.3","matchCriteriaId":"5C1F85A0-709A-4C88-9C40-93D3C47AFD54"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.5.0","versionEndExcluding":"17.5.3","matchCriteriaId":"305F5CB5-5B11-4AA7-ABAE-D4B9A05F6B4A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.6.0:*:*:*:community:*:*:*","matchCriteriaId":"3A39B04B-D109-467A-82E1-3FE6CBA48FEE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.6.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"1212AE23-98AB-4E7A-AAB5-0AD266DFC7D4"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/480494","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2649822","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-8177","sourceIdentifier":"cve@gitlab.com","published":"2024-11-26T19:15:31.860","lastModified":"2026-06-17T08:22:03.727","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab CE/EE affecting all versions starting from 15.6 prior to 17.4.5, starting from 17.5 prior to 17.5.3, starting from 17.6 prior to 17.6.1 which could cause Denial of Service via integrating a malicious harbor registry."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde la 15.6 anterior a la 17.4.5, desde la 17.5 anterior a la 17.5.3, desde la 17.6 anterior a la 17.6.1, que podría causar denegación de servicio mediante la integración de un registro de puerto malicioso."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.6","lessThan":"17.4.5","versionType":"semver","status":"affected"},{"version":"17.5","lessThan":"17.5.3","versionType":"semver","status":"affected"},{"version":"17.6","lessThan":"17.6.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":1.6,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-11-26T18:41:43.795383Z","id":"CVE-2024-8177","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-407"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.6.0","versionEndExcluding":"17.4.5","matchCriteriaId":"793FD94B-536F-4BC3-A2C6-76C02068D836"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.6.0","versionEndExcluding":"17.4.5","matchCriteriaId":"4C7417C8-D447-46F4-9CD1-11560012BFFC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.5.0","versionEndExcluding":"17.5.3","matchCriteriaId":"5C1F85A0-709A-4C88-9C40-93D3C47AFD54"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.5.0","versionEndExcluding":"17.5.3","matchCriteriaId":"305F5CB5-5B11-4AA7-ABAE-D4B9A05F6B4A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.6.0:*:*:*:community:*:*:*","matchCriteriaId":"3A39B04B-D109-467A-82E1-3FE6CBA48FEE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.6.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"1212AE23-98AB-4E7A-AAB5-0AD266DFC7D4"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/480706","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2637996","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-8237","sourceIdentifier":"cve@gitlab.com","published":"2024-11-26T19:15:32.033","lastModified":"2026-06-17T08:22:10.733","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all versions prior to 12.6 prior to 17.4.5, 17.5 prior to 17.5.3, and 17.6 prior to 17.6.1. An attacker could cause a denial of service with a crafted cargo.toml file."},{"lang":"es","value":"Se ha descubierto un problema de denegación de servicio (DoS) en GitLab CE/EE que afecta a todas las versiones anteriores a la 12.6 y anteriores a la 17.4.5, a la 17.5 y anteriores a la 17.5.3 y a la 17.6 y anteriores a la 17.6.1. Un atacante podría provocar una denegación de servicio con un archivo cargo.toml manipulado por un usuario."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"12.6","lessThan":"17.4.5","versionType":"semver","status":"affected"},{"version":"17.5","lessThan":"17.5.3","versionType":"semver","status":"affected"},{"version":"17.6","lessThan":"17.6.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-11-26T18:42:03.650671Z","id":"CVE-2024-8237","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-407"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.6.0","versionEndExcluding":"17.4.5","matchCriteriaId":"1C5A47DB-E540-4C0A-BBDC-C86C81153007"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.6.0","versionEndExcluding":"17.4.5","matchCriteriaId":"5D58733E-92D7-440C-B476-405892F3BAA0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.5.0","versionEndExcluding":"17.5.3","matchCriteriaId":"5C1F85A0-709A-4C88-9C40-93D3C47AFD54"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.5.0","versionEndExcluding":"17.5.3","matchCriteriaId":"305F5CB5-5B11-4AA7-ABAE-D4B9A05F6B4A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.6.0:*:*:*:community:*:*:*","matchCriteriaId":"3A39B04B-D109-467A-82E1-3FE6CBA48FEE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.6.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"1212AE23-98AB-4E7A-AAB5-0AD266DFC7D4"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/480900","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2648665","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-10240","sourceIdentifier":"cve@gitlab.com","published":"2024-11-26T20:15:24.487","lastModified":"2026-06-17T06:55:13.717","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions starting from 17.3 before 17.3.7, all versions starting from 17.4 before 17.4.4, all versions starting from 17.5 before 17.5.2 in which an unauthenticated user may be able to read some information about an MR in a private project, under certain circumstances."},{"lang":"es","value":"Se ha descubierto un problema en GitLab EE que afecta a todas las versiones desde la 17.3 hasta la 17.3.7, todas las versiones desde la 17.4 hasta la 17.4.4 y todas las versiones desde la 17.5 hasta la 17.5.2 en el que un usuario no autenticado puede leer información sobre un MR en un proyecto privado, bajo determinadas circunstancias."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.3","lessThan":"17.3.7","versionType":"semver","status":"affected"},{"version":"17.4","lessThan":"17.4.4","versionType":"semver","status":"affected"},{"version":"17.5","lessThan":"17.5.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-11-26T20:24:41.841038Z","id":"CVE-2024-10240","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-497"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.3.7","matchCriteriaId":"74E30536-DC70-4B29-9949-A62CD91CFD30"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.3.7","matchCriteriaId":"29B62E43-F700-4612-8B62-CCE84B94D47A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.4.0","versionEndExcluding":"17.4.4","matchCriteriaId":"1F7F4C7C-334F-4015-AC25-74FCE4BAD311"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.4.0","versionEndExcluding":"17.4.4","matchCriteriaId":"7FF0B7C7-E0BD-4C6C-8938-0082CBE64847"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.5.0","versionEndExcluding":"17.5.2","matchCriteriaId":"34CDEED3-E7FB-4620-8E07-E4766F9B6593"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.5.0","versionEndExcluding":"17.5.2","matchCriteriaId":"DA99FF56-0441-464D-B369-CF72EF9EEDC7"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2024/11/13/patch-release-gitlab-17-5-2-released/#information-disclosure-through-an-api-endpoint","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/493188","source":"cve@gitlab.com","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2024-10043","sourceIdentifier":"cve@gitlab.com","published":"2024-12-12T12:15:21.330","lastModified":"2026-06-17T06:54:49.383","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions starting from 14.3 before 17.4.6, all versions starting from 17.5 before 17.5.4 all versions starting from 17.6 before 17.6.2, that allows group users to view confidential incident title through the Wiki History Diff feature, potentially leading to information disclosure."},{"lang":"es","value":"Se ha descubierto un problema en GitLab EE que afecta a todas las versiones desde la 14.3 hasta la 17.4.6, todas las versiones desde la 17.5 hasta la 17.5.4 y todas las versiones desde la 17.6 hasta la 17.6.2, que permite a los usuarios del grupo ver el título del incidente confidencial a través de la función Wiki History Diff, lo que podría llevar a la divulgación de información."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"14.3","lessThan":"17.4.6","versionType":"semver","status":"affected"},{"version":"17.5","lessThan":"17.5.4","versionType":"semver","status":"affected"},{"version":"17.6","lessThan":"17.6.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":3.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-12-12T15:21:15.782797Z","id":"CVE-2024-10043","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.3.0","versionEndExcluding":"17.4.6","matchCriteriaId":"097BF70E-BBBB-463D-B272-9DF088FFF7D8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.5.0","versionEndExcluding":"17.5.4","matchCriteriaId":"0A13BB0D-E1E4-4C0B-A823-E661591D4E4F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.6.0","versionEndExcluding":"17.6.2","matchCriteriaId":"01C8A373-615F-45FE-8AF7-BB053EC77D82"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/499577","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/2774817","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-11274","sourceIdentifier":"cve@gitlab.com","published":"2024-12-12T12:15:22.267","lastModified":"2026-06-17T06:57:26.880","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 17.4.6, starting from 17.5 prior to 17.5.4, and starting from 17.6 prior to 17.6.2, injection of NEL headers in k8s proxy response could lead to session data exfiltration."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde la 16.1 anterior a la 17.4.6, desde la 17.5 anterior a la 17.5.4 y desde la 17.6 anterior a la 17.6.2: la inyección de encabezados NEL en la respuesta del proxy de k8 podría provocar la exfiltración de datos de la sesión."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.1","lessThan":"17.4.6","versionType":"semver","status":"affected"},{"version":"17.5","lessThan":"17.5.4","versionType":"semver","status":"affected"},{"version":"17.6","lessThan":"17.6.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":5.8}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-12-12T15:31:44.666728Z","id":"CVE-2024-11274","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-601"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.1.0","versionEndExcluding":"17.4.6","matchCriteriaId":"FA46E81F-A68D-43C3-AD1D-7D52DFD954B4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.1.0","versionEndExcluding":"17.4.6","matchCriteriaId":"491BFDA2-C20D-41C8-8875-4DB1907656F7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.5.0","versionEndExcluding":"17.5.4","matchCriteriaId":"1587202E-2392-46F3-BE79-00BE065AD2AE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.5.0","versionEndExcluding":"17.5.4","matchCriteriaId":"0A13BB0D-E1E4-4C0B-A823-E661591D4E4F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.6.0","versionEndExcluding":"17.6.2","matchCriteriaId":"1E994AE4-0E47-4CF0-93B2-C28A5E274059"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.6.0","versionEndExcluding":"17.6.2","matchCriteriaId":"01C8A373-615F-45FE-8AF7-BB053EC77D82"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/504707","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/2813673","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-12292","sourceIdentifier":"cve@gitlab.com","published":"2024-12-12T12:15:22.470","lastModified":"2026-06-17T06:59:26.353","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab CE/EE affecting all versions starting from 11.0 prior to 17.4.6, starting from 17.5 prior to 17.5.4, and starting from 17.6 prior to 17.6.2, where sensitive information passed in GraphQL mutations may have been retained in GraphQL logs."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde la 11.0 anterior a la 17.4.6, desde la 17.5 anterior a la 17.5.4 y desde la 17.6 anterior a la 17.6.2, donde la información confidencial pasada en mutaciones de GraphQL podría haberse conservado en los registros de GraphQL."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"11.0","lessThan":"17.4.6","versionType":"semver","status":"affected"},{"version":"17.5","lessThan":"17.5.4","versionType":"semver","status":"affected"},{"version":"17.6","lessThan":"17.6.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":4.0,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.5,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-12-12T15:21:18.361272Z","id":"CVE-2024-12292","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-532"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"17.4.6","matchCriteriaId":"099809DD-847E-4CAE-9A62-6E22892185B8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"17.4.6","matchCriteriaId":"2394D340-C29D-4D67-A54E-CC6060AF2ECF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.5.0","versionEndExcluding":"17.5.4","matchCriteriaId":"1587202E-2392-46F3-BE79-00BE065AD2AE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.5.0","versionEndExcluding":"17.5.4","matchCriteriaId":"0A13BB0D-E1E4-4C0B-A823-E661591D4E4F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.6.0","versionEndExcluding":"17.6.2","matchCriteriaId":"1E994AE4-0E47-4CF0-93B2-C28A5E274059"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.6.0","versionEndExcluding":"17.6.2","matchCriteriaId":"01C8A373-615F-45FE-8AF7-BB053EC77D82"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/475211","source":"cve@gitlab.com","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2024-12570","sourceIdentifier":"cve@gitlab.com","published":"2024-12-12T12:15:22.660","lastModified":"2026-06-17T06:59:57.940","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 prior to 17.4.6, from 17.5 prior to 17.5.4, and from 17.6 prior to 17.6.2. It may have been possible for an attacker with a victim's `CI_JOB_TOKEN` to obtain a GitLab session token belonging to the victim."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones a partir de la 13.7 anterior a la 17.4.6, de la 17.5 anterior a la 17.5.4 y de la 17.6 anterior a la 17.6.2. Es posible que un atacante con el `CI_JOB_TOKEN` de una víctima haya podido obtener un token de sesión de GitLab perteneciente a la víctima."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"13.7","lessThan":"17.4.6","versionType":"semver","status":"affected"},{"version":"17.5","lessThan":"17.5.4","versionType":"semver","status":"affected"},{"version":"17.6","lessThan":"17.6.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L","baseScore":6.7,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":1.2,"impactScore":5.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-12-16T00:00:00+00:00","id":"CVE-2024-12570","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-270"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"17.4.6","matchCriteriaId":"9FFA8298-553A-4B1D-96FB-5AB45C406DAC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"17.4.6","matchCriteriaId":"91150A41-265C-4C57-93DD-6751A3430EBB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.5.0","versionEndExcluding":"17.5.4","matchCriteriaId":"1587202E-2392-46F3-BE79-00BE065AD2AE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.5.0","versionEndExcluding":"17.5.4","matchCriteriaId":"0A13BB0D-E1E4-4C0B-A823-E661591D4E4F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.6.0","versionEndExcluding":"17.6.2","matchCriteriaId":"1E994AE4-0E47-4CF0-93B2-C28A5E274059"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.6.0","versionEndExcluding":"17.6.2","matchCriteriaId":"01C8A373-615F-45FE-8AF7-BB053EC77D82"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/494694","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/2724948","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-8179","sourceIdentifier":"cve@gitlab.com","published":"2024-12-12T12:15:27.937","lastModified":"2026-06-17T08:22:03.993","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. Improper output encoding could lead to XSS if CSP is not enabled."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde la 17.3 hasta la 17.4.6, desde la 17.5 hasta la 17.5.4 y desde la 17.6 hasta la 17.6.2. Una codificación de salida incorrecta podría provocar un error XSS si no se habilita CSP."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.6","lessThan":"17.6.2","versionType":"semver","status":"affected"},{"version":"17.5","lessThan":"17.5.4","versionType":"semver","status":"affected"},{"version":"17.3","lessThan":"17.4.6","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-12-12T15:21:07.535754Z","id":"CVE-2024-8179","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.4.6","matchCriteriaId":"EEE0B54C-3EFE-4BE1-9FE5-D0B7BFE59200"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.4.6","matchCriteriaId":"A26CDD4D-7364-49E8-A6A7-B7C6E1A4B6FE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.5.0","versionEndExcluding":"17.5.4","matchCriteriaId":"1587202E-2392-46F3-BE79-00BE065AD2AE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.5.0","versionEndExcluding":"17.5.4","matchCriteriaId":"0A13BB0D-E1E4-4C0B-A823-E661591D4E4F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.6.0","versionEndExcluding":"17.6.2","matchCriteriaId":"1E994AE4-0E47-4CF0-93B2-C28A5E274059"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.6.0","versionEndExcluding":"17.6.2","matchCriteriaId":"01C8A373-615F-45FE-8AF7-BB053EC77D82"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/480718","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2665929","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-8233","sourceIdentifier":"cve@gitlab.com","published":"2024-12-12T12:15:28.120","lastModified":"2026-06-17T08:22:10.257","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 9.4 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. An attacker could cause a denial of service with requests for diff files on a commit or merge request."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde la 9.4 hasta la 17.4.6, desde la 17.5 hasta la 17.5.4 y desde la 17.6 hasta la 17.6.2. Un atacante podría provocar una denegación de servicio con solicitudes de archivos diff en un commit o fusión."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"9.4","lessThan":"17.4.6","versionType":"semver","status":"affected"},{"version":"17.5","lessThan":"17.5.4","versionType":"semver","status":"affected"},{"version":"17.6","lessThan":"17.6.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-12-12T15:35:42.855154Z","id":"CVE-2024-8233","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-407"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"9.4.0","versionEndExcluding":"17.4.6","matchCriteriaId":"4AB8CD0D-4F91-4E46-BDBB-4A4933CC01A3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"9.4.0","versionEndExcluding":"17.4.6","matchCriteriaId":"7B82BE14-FBE3-4F52-A9A0-91B06590C0F8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.5.0","versionEndExcluding":"17.5.4","matchCriteriaId":"1587202E-2392-46F3-BE79-00BE065AD2AE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.5.0","versionEndExcluding":"17.5.4","matchCriteriaId":"0A13BB0D-E1E4-4C0B-A823-E661591D4E4F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.6.0","versionEndExcluding":"17.6.2","matchCriteriaId":"1E994AE4-0E47-4CF0-93B2-C28A5E274059"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.6.0","versionEndExcluding":"17.6.2","matchCriteriaId":"01C8A373-615F-45FE-8AF7-BB053EC77D82"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/480867","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/2650086","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-8647","sourceIdentifier":"cve@gitlab.com","published":"2024-12-12T12:15:28.297","lastModified":"2026-06-17T08:23:02.847","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab affecting all versions starting 15.2 to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2. On self hosted installs, it was possible to leak the anti-CSRF-token to an external site while the Harbor integration was enabled."},{"lang":"es","value":"Se descubrió un problema en GitLab que afectaba a todas las versiones desde la 15.2 hasta la 17.4.6, desde la 17.5 hasta la 17.5.4 y desde la 17.6 hasta la 17.6.2. En las instalaciones alojadas en servidores propios, era posible filtrar el token anti-CSRF a un sitio externo mientras la integración de Harbor estaba habilitada."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.2","lessThan":"17.4.6","versionType":"semver","status":"affected"},{"version":"17.5","lessThan":"17.5.4","versionType":"semver","status":"affected"},{"version":"17.6","lessThan":"17.6.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-12-12T15:21:09.955735Z","id":"CVE-2024-8647","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-22"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"15.2.0","versionEndExcluding":"17.4.6","matchCriteriaId":"AB8DCBC1-255B-4D24-9875-F901BE788DA0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"17.5.0","versionEndExcluding":"17.5.4","matchCriteriaId":"F97D9F30-A47B-4288-8B5C-28990A4F822F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"17.6.0","versionEndExcluding":"17.6.2","matchCriteriaId":"EFBA60E5-4212-459C-A79E-D676F02233B4"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/486051","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/2666341","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-9367","sourceIdentifier":"cve@gitlab.com","published":"2024-12-12T12:15:28.497","lastModified":"2026-06-17T08:24:26.030","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab CE/EE affecting all versions starting from 13.9 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2, that allows an attacker to cause uncontrolled CPU consumption, potentially leading to a Denial of Service (DoS) condition while parsing templates to generate changelogs."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde la 13.9 hasta la 17.4.6, la 17.5 hasta la 17.5.4 y la 17.6 hasta la 17.6.2, que permite a un atacante provocar un consumo descontrolado de CPU, lo que podría provocar una condición de denegación de servicio (DoS) al analizar plantillas para generar registros de cambios."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"13.9","lessThan":"17.4.6","versionType":"semver","status":"affected"},{"version":"17.5","lessThan":"17.5.4","versionType":"semver","status":"affected"},{"version":"17.6","lessThan":"17.6.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-12-12T15:21:12.663039Z","id":"CVE-2024-9367","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.9.0","versionEndExcluding":"17.4.6","matchCriteriaId":"F2E4E4EB-7E6A-4780-8C9A-DFDAEE3E5D87"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.9.0","versionEndExcluding":"17.4.6","matchCriteriaId":"0A91C9BA-5D3C-4D62-9346-06AD4ED5B71C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.5.0","versionEndExcluding":"17.5.4","matchCriteriaId":"1587202E-2392-46F3-BE79-00BE065AD2AE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.5.0","versionEndExcluding":"17.5.4","matchCriteriaId":"0A13BB0D-E1E4-4C0B-A823-E661591D4E4F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.6.0","versionEndExcluding":"17.6.2","matchCriteriaId":"1E994AE4-0E47-4CF0-93B2-C28A5E274059"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.6.0","versionEndExcluding":"17.6.2","matchCriteriaId":"01C8A373-615F-45FE-8AF7-BB053EC77D82"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/496631","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/2735311","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-9387","sourceIdentifier":"cve@gitlab.com","published":"2024-12-12T12:15:28.727","lastModified":"2026-06-17T08:24:28.057","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab CE/EE affecting all versions from 11.8 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. An attacker could potentially perform an open redirect against a given releases API endpoint."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afectaba a todas las versiones desde la 11.8 hasta la 17.4.6, la 17.5 hasta la 17.5.4 y la 17.6 hasta la 17.6.2. Un atacante podría realizar una redirección abierta contra un endpoint de API de una versión determinada."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"11.8","lessThan":"17.4.6","versionType":"semver","status":"affected"},{"version":"17.5","lessThan":"17.5.4","versionType":"semver","status":"affected"},{"version":"17.6","lessThan":"17.6.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-12-16T00:00:00+00:00","id":"CVE-2024-9387","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-601"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"17.4.6","matchCriteriaId":"D38336FD-820B-4216-B4CE-6736433CAA51"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"17.4.6","matchCriteriaId":"5A962F4E-0069-4436-BE37-204DEC387138"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.5.0","versionEndExcluding":"17.5.4","matchCriteriaId":"1587202E-2392-46F3-BE79-00BE065AD2AE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.5.0","versionEndExcluding":"17.5.4","matchCriteriaId":"0A13BB0D-E1E4-4C0B-A823-E661591D4E4F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.6.0","versionEndExcluding":"17.6.2","matchCriteriaId":"1E994AE4-0E47-4CF0-93B2-C28A5E274059"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.6.0","versionEndExcluding":"17.6.2","matchCriteriaId":"01C8A373-615F-45FE-8AF7-BB053EC77D82"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/496659","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/2732235","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-8116","sourceIdentifier":"cve@gitlab.com","published":"2024-12-16T05:15:05.520","lastModified":"2026-06-17T08:21:55.270","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 16.9 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. By using a specific GraphQL query, under specific conditions an unauthorized user can retrieve branch names."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde la 16.9 hasta la 17.4.6, desde la 17.5 hasta la 17.5.4 y desde la 17.6 hasta la 17.6.2. Al usar una consulta GraphQL específica, en determinadas condiciones, un usuario no autorizado puede recuperar nombres de ramas."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.9","lessThan":"17.4.6","versionType":"semver","status":"affected"},{"version":"17.5","lessThan":"17.5.4","versionType":"semver","status":"affected"},{"version":"17.6","lessThan":"17.6.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-12-16T16:44:39.431414Z","id":"CVE-2024-8116","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.9.0","versionEndExcluding":"17.4.6","matchCriteriaId":"8B70F5D0-3E6A-4C28-8614-EBCFFB8BE325"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.9.0","versionEndExcluding":"17.4.6","matchCriteriaId":"D1B4FB6C-6AF9-4259-B363-C439F8AFD8DB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.5.0","versionEndExcluding":"17.5.4","matchCriteriaId":"1587202E-2392-46F3-BE79-00BE065AD2AE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.5.0","versionEndExcluding":"17.5.4","matchCriteriaId":"0A13BB0D-E1E4-4C0B-A823-E661591D4E4F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.6.0","versionEndExcluding":"17.6.2","matchCriteriaId":"1E994AE4-0E47-4CF0-93B2-C28A5E274059"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.6.0","versionEndExcluding":"17.6.2","matchCriteriaId":"01C8A373-615F-45FE-8AF7-BB053EC77D82"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/480509","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/2666216","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-8650","sourceIdentifier":"cve@gitlab.com","published":"2024-12-16T05:15:05.780","lastModified":"2026-06-17T08:23:03.070","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab CE/EE affecting all versions from 15.0 prior to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2 that allowed non-member users to view unresolved threads marked as internal notes in public projects merge requests."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afectaba a todas las versiones desde la 15.0 anterior a la 17.4.6, desde la 17.5 anterior a la 17.5.4 y desde la 17.6 anterior a la 17.6.2 que permitía a usuarios no miembros ver hilos sin resolver marcados como notas internas en solicitudes de fusión de proyectos públicos."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.0","lessThan":"17.4.6","versionType":"semver","status":"affected"},{"version":"17.5","lessThan":"17.5.4","versionType":"semver","status":"affected"},{"version":"17.6","lessThan":"17.6.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-12-16T16:45:01.330707Z","id":"CVE-2024-8650","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.0.0","versionEndExcluding":"17.4.6","matchCriteriaId":"27669A69-2B52-4C30-9D36-986EAD4E41A0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.0.0","versionEndExcluding":"17.4.6","matchCriteriaId":"4BA58521-1351-4F24-A2F3-689CB4B905CE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.5.0","versionEndExcluding":"17.5.4","matchCriteriaId":"1587202E-2392-46F3-BE79-00BE065AD2AE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.5.0","versionEndExcluding":"17.5.4","matchCriteriaId":"0A13BB0D-E1E4-4C0B-A823-E661591D4E4F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.6.0","versionEndExcluding":"17.6.2","matchCriteriaId":"1E994AE4-0E47-4CF0-93B2-C28A5E274059"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.6.0","versionEndExcluding":"17.6.2","matchCriteriaId":"01C8A373-615F-45FE-8AF7-BB053EC77D82"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/486300","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/2705909","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-5117","sourceIdentifier":"cve@gitlab.com","published":"2024-12-25T15:15:05.900","lastModified":"2026-06-17T06:47:34.133","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab CE/EE affecting all versions before 17.6.0 in which users were unaware that files uploaded to comments on confidential issues and epics of public projects could be accessed without authentication via a direct link to the uploaded file URL."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afectaba a todas las versiones anteriores a 17.6.0 en el que los usuarios no sabían que se podía acceder a los archivos cargados para comentarios sobre temas confidenciales y epopeyas de proyectos públicos sin autenticación a través de un enlace directo a la URL del archivo cargado."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"0","lessThan":"17.6.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":3.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-12-26T18:10:46.314446Z","id":"CVE-2023-5117","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-213"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"17.6.0","matchCriteriaId":"D6EE0793-66CC-4C5B-902A-5A0B8256600D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"17.6.0","matchCriteriaId":"45FBD09A-2C93-40D5-9BB5-95550EE07A77"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/398250","source":"cve@gitlab.com","tags":["Issue Tracking","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2025-0194","sourceIdentifier":"cve@gitlab.com","published":"2025-01-08T20:15:29.193","lastModified":"2026-06-17T08:26:03.150","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab CE/EE affecting all versions starting from 17.4 prior to 17.5.5, starting from 17.6 prior to 17.6.3, and starting from 17.7 prior to 17.7.1. Under certain conditions, access tokens may have been logged when API requests were made in a specific manner."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afectaba a todas las versiones a partir de la 17.4 anterior a la 17.5.5, a partir de la 17.6 anterior a la 17.6.3 y a partir de la 17.7 anterior a la 17.7.1. En determinadas circunstancias, es posible que se hayan registrado tokens de acceso cuando se realizaron solicitudes de API de una manera específica."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.4","lessThan":"17.5.5","versionType":"semver","status":"affected"},{"version":"17.6","lessThan":"17.6.3","versionType":"semver","status":"affected"},{"version":"17.7","lessThan":"17.7.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-01-08T20:37:21.307337Z","id":"CVE-2025-0194","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-538"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.4.0","versionEndExcluding":"17.5.5","matchCriteriaId":"71B68640-B25D-43CA-AC79-D7331ACC6D73"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.4.0","versionEndExcluding":"17.5.5","matchCriteriaId":"EA8C2E16-BFC7-4F82-8FF8-B04979444FBF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.6.0","versionEndExcluding":"17.6.3","matchCriteriaId":"8BFB4F2D-7692-4241-AF8B-A0C5B5FA6021"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.6.0","versionEndExcluding":"17.6.3","matchCriteriaId":"464F7155-C7C2-4881-A78F-FB949540F3A9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.7.0","versionEndExcluding":"17.7.1","matchCriteriaId":"621F0CA2-6B85-45B3-92E0-5DE6D9724592"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.7.0","versionEndExcluding":"17.7.1","matchCriteriaId":"1C6BA293-BDF4-4D50-BD54-0329E00FC5ED"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2025/01/08/patch-release-gitlab-17-7-1-released/#possible-access-token-exposure-in-gitlab-logs","source":"cve@gitlab.com","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/489459","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2024-12431","sourceIdentifier":"cve@gitlab.com","published":"2025-01-08T21:15:11.760","lastModified":"2026-06-17T06:59:42.483","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab CE/EE affecting all versions starting from 15.5 before 17.5.5, 17.6 before 17.6.3, and 17.7 before 17.7.1, in which unauthorized users could manipulate the status of issues in public projects."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afectaba a todas las versiones desde la 15.5 hasta la 17.5.5, la 17.6 hasta la 17.6.3 y la 17.7 hasta la 17.7.1, en el que usuarios no autorizados podían manipular el estado de los problemas en proyectos públicos."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.5","lessThan":"17.5.5","versionType":"semver","status":"affected"},{"version":"17.6","lessThan":"17.6.3","versionType":"semver","status":"affected"},{"version":"17.7","lessThan":"17.7.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-12T17:12:55.939627Z","id":"CVE-2024-12431","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.5.0","versionEndExcluding":"17.5.5","matchCriteriaId":"1A6F00AD-6307-4A10-BD82-876C3C327CB4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.5.0","versionEndExcluding":"17.5.5","matchCriteriaId":"BF431D42-8A93-4FEA-985C-306259881544"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.6.0","versionEndExcluding":"17.6.3","matchCriteriaId":"8BFB4F2D-7692-4241-AF8B-A0C5B5FA6021"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.6.0","versionEndExcluding":"17.6.3","matchCriteriaId":"464F7155-C7C2-4881-A78F-FB949540F3A9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.7.0","versionEndExcluding":"17.7.1","matchCriteriaId":"621F0CA2-6B85-45B3-92E0-5DE6D9724592"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.7.0","versionEndExcluding":"17.7.1","matchCriteriaId":"1C6BA293-BDF4-4D50-BD54-0329E00FC5ED"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2025/01/08/patch-release-gitlab-17-7-1-released/#unauthorized-user-can-manipulate-status-of-issues-in-public-projects","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/508742","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/2877710","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-6324","sourceIdentifier":"cve@gitlab.com","published":"2025-01-09T06:15:15.390","lastModified":"2026-06-17T08:17:46.797","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab CE/EE affecting all versions starting from 15.7 prior to 17.5.5, starting from 17.6 prior to 17.6.3, and starting from 17.7 prior to 17.7.1. It was possible to trigger a DoS by creating cyclic references between epics."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afectaba a todas las versiones desde la 15.7 hasta la 17.5.5, desde la 17.6 hasta la 17.6.3 y desde la 17.7 hasta la 17.7.1. Era posible desencadenar un ataque de denegación de servicio mediante la creación de referencias cíclicas entre epopeyas."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.7","lessThan":"17.7.1","versionType":"semver","status":"affected"},{"version":"17.6","lessThan":"17.6.3","versionType":"semver","status":"affected"},{"version":"15.7","lessThan":"17.5.5","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-01-09T15:32:24.285965Z","id":"CVE-2024-6324","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-407"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.7.0","versionEndExcluding":"17.5.5","matchCriteriaId":"81C3F1C3-8B39-4E9B-8BAE-3B318399322B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.7.0","versionEndExcluding":"17.5.5","matchCriteriaId":"9E88DDF9-5AAC-4517-9A9B-AC92E37F4DE2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.6.0","versionEndExcluding":"17.6.3","matchCriteriaId":"8BFB4F2D-7692-4241-AF8B-A0C5B5FA6021"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.6.0","versionEndExcluding":"17.6.3","matchCriteriaId":"464F7155-C7C2-4881-A78F-FB949540F3A9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.7.0","versionEndExcluding":"17.7.1","matchCriteriaId":"621F0CA2-6B85-45B3-92E0-5DE6D9724592"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.7.0","versionEndExcluding":"17.7.1","matchCriteriaId":"1C6BA293-BDF4-4D50-BD54-0329E00FC5ED"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2025/01/08/patch-release-gitlab-17-7-1-released/#cyclic-reference-of-epics-leads-resource-exhaustion","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/468914","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/2553716","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-13041","sourceIdentifier":"cve@gitlab.com","published":"2025-01-09T07:15:26.497","lastModified":"2026-06-17T07:01:02.657","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.5.5, starting from 17.6 prior to 17.6.3, and starting from 17.7 prior to 17.7.1. When a user is created via the SAML provider, the external groups setting overrides the external provider configuration. As a result, the user may not be marked as external thereby giving those users access to internal projects or groups."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde la 16.4 hasta la 17.5.5, desde la 17.6 hasta la 17.6.3 y desde la 17.7 hasta la 17.7.1. Cuando se crea un usuario a través del proveedor SAML, la configuración de grupos externos anula la configuración del proveedor externo. Como resultado, es posible que el usuario no se marque como externo, lo que le otorga acceso a proyectos o grupos internos."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.4","lessThan":"17.5.5","versionType":"semver","status":"affected"},{"version":"17.6","lessThan":"17.6.3","versionType":"semver","status":"affected"},{"version":"17.7","lessThan":"17.7.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","baseScore":4.2,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":2.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-01-09T15:29:42.683723Z","id":"CVE-2024-13041","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-286"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.4.0","versionEndExcluding":"17.5.5","matchCriteriaId":"913E9C5D-ECFD-4366-A861-B4405CDC160D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.4.0","versionEndExcluding":"17.5.5","matchCriteriaId":"2F761D8C-2AA9-4204-B6D5-41164ABD54C4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.6.0","versionEndExcluding":"17.6.3","matchCriteriaId":"8BFB4F2D-7692-4241-AF8B-A0C5B5FA6021"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.6.0","versionEndExcluding":"17.6.3","matchCriteriaId":"464F7155-C7C2-4881-A78F-FB949540F3A9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.7.0","versionEndExcluding":"17.7.1","matchCriteriaId":"621F0CA2-6B85-45B3-92E0-5DE6D9724592"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.7.0","versionEndExcluding":"17.7.1","matchCriteriaId":"1C6BA293-BDF4-4D50-BD54-0329E00FC5ED"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2025/01/08/patch-release-gitlab-17-7-1-released/#instance-saml-does-not-respect-external_provider-configuration","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/479165","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]}]}},{"cve":{"id":"CVE-2024-11931","sourceIdentifier":"cve@gitlab.com","published":"2025-01-24T03:15:06.590","lastModified":"2026-06-17T06:58:43.427","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.6.4, from 17.7 prior to 17.7.3, and from 17.8 prior to 17.8.1. Under certain conditions, it may have been possible for users with developer role to exfiltrate protected CI variables via CI lint."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones a partir de la 17.0 anterior a la 17.6.4, de la 17.7 anterior a la 17.7.3 y de la 17.8 anterior a la 17.8.1. En determinadas circunstancias, es posible que los usuarios con función de desarrollador hayan podido exfiltrar variables de CI protegidas mediante CI lint."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.0","lessThan":"17.6.4","versionType":"semver","status":"affected"},{"version":"17.7","lessThan":"17.7.3","versionType":"semver","status":"affected"},{"version":"17.8","lessThan":"17.8.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-01-24T14:59:16.564153Z","id":"CVE-2024-11931","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1220"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"17.6.4","matchCriteriaId":"C1DFB4EC-BC51-4855-8FC4-D2BE552114A2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"17.6.4","matchCriteriaId":"1C755F6B-F942-42A3-87C7-33FF0AE4877D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.7.0","versionEndExcluding":"17.7.3","matchCriteriaId":"F58DBE0B-3F1A-4F44-A908-78C245D15151"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.7.0","versionEndExcluding":"17.7.3","matchCriteriaId":"BE3A08B9-AB93-4384-AC6F-479770F8F179"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.8.0:*:*:*:community:*:*:*","matchCriteriaId":"28392021-9008-4FE2-9425-C0F0DCF10119"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.8.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"51714D27-77B8-422D-B946-2277FB0DA2E7"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/480901","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking","Patch"]},{"url":"https://about.gitlab.com/releases/2025/01/22/patch-release-gitlab-17-8-1-released/https://about.gitlab.com/releases/2025/01/22/patch-release-gitlab-17-8-1-released/","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2025-0314","sourceIdentifier":"cve@gitlab.com","published":"2025-01-24T03:15:07.320","lastModified":"2026-06-17T08:26:16.020","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.6.4, 17.7 before 17.7.3, and 17.8 before 17.8.1. Improper rendering of certain file types lead to cross-site scripting."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde la 17.2 hasta la 17.6.4, desde la 17.7 hasta la 17.7.3 y desde la 17.8 hasta la 17.8.1. La representación incorrecta de ciertos tipos de archivos provoca cross-site scripting. "}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.2","lessThan":"17.6.4","versionType":"semver","status":"affected"},{"version":"17.7","lessThan":"17.7.3","versionType":"semver","status":"affected"},{"version":"17.8","lessThan":"17.8.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-01-24T15:00:41.642250Z","id":"CVE-2025-0314","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.6.4","matchCriteriaId":"6E818ED4-C5E6-4305-A26D-988D6246A6EB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.6.4","matchCriteriaId":"5C1A5D6E-9FA4-44C1-B1B4-DABD78AC9DE5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.7.0","versionEndExcluding":"17.7.3","matchCriteriaId":"F58DBE0B-3F1A-4F44-A908-78C245D15151"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.7.0","versionEndExcluding":"17.7.3","matchCriteriaId":"BE3A08B9-AB93-4384-AC6F-479770F8F179"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.8.0:*:*:*:community:*:*:*","matchCriteriaId":"28392021-9008-4FE2-9425-C0F0DCF10119"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.8.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"51714D27-77B8-422D-B946-2277FB0DA2E7"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/512118","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2922313","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-0290","sourceIdentifier":"cve@gitlab.com","published":"2025-01-28T09:15:09.363","lastModified":"2026-06-17T08:26:13.480","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.0 prior to 17.5.5, from 17.6 prior to 17.6.3, and from 17.7 prior to 17.7.1. Under certain conditions, processing of CI artifacts metadata could cause background jobs to become unresponsive."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones a partir de la 15.0 anterior a la 17.5.5, de la 17.6 anterior a la 17.6.3 y de la 17.7 anterior a la 17.7.1. En determinadas condiciones, el procesamiento de metadatos de artefactos de CI podría provocar que los trabajos en segundo plano dejaran de responder."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.0","lessThan":"17.6.4","versionType":"semver","status":"affected"},{"version":"17.7","lessThan":"17.7.2","versionType":"semver","status":"affected"},{"version":"17.8","lessThan":"17.8.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-01-28T14:41:43.330404Z","id":"CVE-2025-0290","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-835"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.0.0","versionEndExcluding":"17.5.5","matchCriteriaId":"28A6702B-36C8-4CCB-BB52-4C43946735E8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.0.0","versionEndExcluding":"17.5.5","matchCriteriaId":"DE92CABE-9E83-4C89-AF20-4AEEC23E0B33"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.6.0","versionEndExcluding":"17.6.3","matchCriteriaId":"8BFB4F2D-7692-4241-AF8B-A0C5B5FA6021"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.6.0","versionEndExcluding":"17.6.3","matchCriteriaId":"464F7155-C7C2-4881-A78F-FB949540F3A9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.7.0:*:*:*:community:*:*:*","matchCriteriaId":"F84BE558-D8B7-4C3E-B00D-DD1A273B8B3E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.7.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"0DE151E5-6D8D-4544-B88C-71394C460D75"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/372134","source":"cve@gitlab.com","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2023-6195","sourceIdentifier":"cve@gitlab.com","published":"2025-01-31T00:15:08.697","lastModified":"2026-06-17T06:50:16.717","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.5 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. GitLab was vulnerable to Server Side Request Forgery when an attacker uses a malicious URL in the markdown  image value when importing a GitHub repository."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde la 15.5 hasta la 16.9.7, desde la 16.10 hasta la 16.10.5 y desde la 16.11 hasta la 16.11.2. GitLab era vulnerable a Server Side Request Forgery cuando un atacante usa una URL maliciosa en el valor de la imagen de Markdown al importar un repositorio de GitHub."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.5","lessThan":"16.9.7","versionType":"semver","status":"affected"},{"version":"16.10","lessThan":"16.10.5","versionType":"semver","status":"affected"},{"version":"16.11","lessThan":"16.11.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N","baseScore":2.6,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-01-31T17:06:44.486206Z","id":"CVE-2023-6195","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.5.0","versionEndExcluding":"16.9.7","matchCriteriaId":"088CC298-02D2-4319-ACC3-FEFFA052058C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.5.0","versionEndExcluding":"16.9.7","matchCriteriaId":"6D6A85B4-971B-46D9-B80A-B7CB616E75FB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.10.0","versionEndExcluding":"16.10.5","matchCriteriaId":"356482CA-C9DF-418B-BBDF-C6C09CA8C16D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.10.0","versionEndExcluding":"16.10.5","matchCriteriaId":"154184A5-A34D-4DB1-85B4-DE47A3723E6B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.11.0","versionEndExcluding":"16.11.2","matchCriteriaId":"9B50E4E6-602E-470D-BB03-774CFB1461B6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.11.0","versionEndExcluding":"16.11.2","matchCriteriaId":"5ACCB718-2ABE-4F1A-AB57-B2D3B4879FAC"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/432276","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/2249268","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-1211","sourceIdentifier":"cve@gitlab.com","published":"2025-01-31T00:15:08.863","lastModified":"2026-06-17T07:03:43.300","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.6 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2 in which cross-site request forgery may have been possible on GitLab instances configured to use JWT as an OmniAuth provider."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde la 10.6 anterior a la 16.9.7, desde la 16.10 anterior a la 16.10.5 y desde la 16.11 anterior a la 16.11.2 en el que Cross-Site Request Forgery podría haber sido posible en instancias de GitLab configuradas para usar JWT como proveedor de OmniAuth."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"10.6","lessThan":"16.9.7","versionType":"semver","status":"affected"},{"version":"16.10","lessThan":"16.10.5","versionType":"semver","status":"affected"},{"version":"16.11","lessThan":"16.11.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-01-31T19:29:43.072740Z","id":"CVE-2024-1211","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-352"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.6.0","versionEndExcluding":"16.9.7","matchCriteriaId":"3E246C72-8933-4224-BB28-03AD48FDF69B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.6.0","versionEndExcluding":"16.9.7","matchCriteriaId":"0FBAC3E9-8AE1-4F05-B5F6-61C9683FF813"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.10.0","versionEndExcluding":"16.10.5","matchCriteriaId":"356482CA-C9DF-418B-BBDF-C6C09CA8C16D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.10.0","versionEndExcluding":"16.10.5","matchCriteriaId":"154184A5-A34D-4DB1-85B4-DE47A3723E6B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.11.0","versionEndExcluding":"16.11.2","matchCriteriaId":"9B50E4E6-602E-470D-BB03-774CFB1461B6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.11.0","versionEndExcluding":"16.11.2","matchCriteriaId":"5ACCB718-2ABE-4F1A-AB57-B2D3B4879FAC"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/440313","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2323594","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-6386","sourceIdentifier":"cve@gitlab.com","published":"2025-02-05T10:15:22.093","lastModified":"2026-06-17T06:50:39.710","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A denial of service vulnerability was identified in GitLab CE/EE, affecting all versions from 15.11 prior to 16.6.7, 16.7 prior to 16.7.5 and 16.8 prior to 16.8.2 which allows an attacker to spike the GitLab instance resource usage resulting in service degradation."},{"lang":"es","value":"Se identificó una vulnerabilidad de denegación de servicio en GitLab CE/EE, que afecta a todas las versiones desde la 15.11 anterior a la 16.6.7, la 16.7 anterior a la 16.7.5 y la 16.8 anterior a la 16.8.2, lo que permite a un atacante aumentar el uso de recursos de la instancia de GitLab, lo que resulta en una degradación del servicio."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.11","lessThan":"16.6.7","versionType":"semver","status":"affected"},{"version":"16.7","lessThan":"16.7.5","versionType":"semver","status":"affected"},{"version":"16.8","lessThan":"16.8.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-05T14:45:23.909393Z","id":"CVE-2023-6386","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.11.0","versionEndExcluding":"16.6.7","matchCriteriaId":"7124E700-DBBB-4F09-9887-2047740238AF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.11.0","versionEndExcluding":"16.6.7","matchCriteriaId":"7669B81D-047D-42B2-BAA5-69C6DA41CFCA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.7.0","versionEndExcluding":"16.7.5","matchCriteriaId":"CB714ECE-4A79-43F6-839F-7761965B7D1E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.7.0","versionEndExcluding":"16.7.5","matchCriteriaId":"8ECA9350-B77B-41F6-B234-72BF47FD50E7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.8.0","versionEndExcluding":"16.8.2","matchCriteriaId":"CE6476FF-7CAC-44B8-BB9B-56B54C8D1F4E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.8.0","versionEndExcluding":"16.8.2","matchCriteriaId":"FDA190F8-0AAA-44DF-8A6B-A9A4380D478C"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/433147","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2261581","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-1539","sourceIdentifier":"cve@gitlab.com","published":"2025-02-05T10:15:22.327","lastModified":"2026-06-17T07:04:27.277","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions starting from 15.2 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. It was possible to disclose updates to issues to a banned group member using the API."},{"lang":"es","value":"Se ha descubierto un problema en GitLab EE que afecta a todas las versiones desde la 15.2 hasta la 16.9.7, desde la 16.10 hasta la 16.10.5 y desde la 16.11 hasta la 16.11.2. Era posible divulgar actualizaciones de problemas a un miembro del grupo prohibido mediante la API."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.2","lessThan":"16.9.7","versionType":"semver","status":"affected"},{"version":"16.10","lessThan":"16.10.5","versionType":"semver","status":"affected"},{"version":"16.11","lessThan":"16.11.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-05T14:30:26.795245Z","id":"CVE-2024-1539","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.2.0","versionEndExcluding":"16.9.7","matchCriteriaId":"981EEC83-B6D7-45CA-A1A4-75949355CC46"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.10.0","versionEndExcluding":"16.10.5","matchCriteriaId":"154184A5-A34D-4DB1-85B4-DE47A3723E6B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.11.0","versionEndExcluding":"16.11.2","matchCriteriaId":"5ACCB718-2ABE-4F1A-AB57-B2D3B4879FAC"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/442049","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2369988","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-6356","sourceIdentifier":"cve@gitlab.com","published":"2025-02-05T10:15:22.523","lastModified":"2026-06-17T08:17:50.670","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2, which allowed cross project access for Security policy bot."},{"lang":"es","value":"Se descubrió un problema en GitLab EE que afectaba a todas las versiones desde la 16.0 anterior a la 17.0.6, desde la 17.1 anterior a la 17.1.4 y desde la 17.2 anterior a la 17.2.2, lo que permitía el acceso entre proyectos para el bot de política de seguridad."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.0","lessThan":"17.0.6","versionType":"semver","status":"affected"},{"version":"17.1","lessThan":"17.1.4","versionType":"semver","status":"affected"},{"version":"17.2","lessThan":"17.2.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":4.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.3,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":4.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-05T14:29:39.252229Z","id":"CVE-2024-6356","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-286"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"17.0.6","matchCriteriaId":"93702C7C-EB9B-47D8-9076-ABB1E6952DF0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"17.1.4","matchCriteriaId":"39754D78-BBE0-41D9-B2AB-5402B32C8ECF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.2","matchCriteriaId":"2BE7EFA9-D9B4-4E7E-81B2-597D3DC5756E"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/469108","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/2575051","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-5528","sourceIdentifier":"cve@gitlab.com","published":"2025-02-05T11:15:17.160","lastModified":"2026-06-17T08:16:08.090","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab CE/EE affecting all versions prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2, which allows a subdomain takeover in GitLab Pages."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones anteriores a 16.11.6, a partir de la 17.0 anterior a la 17.0.4, y a partir de la 17.1 anterior a la 17.1.2, que permite una toma de control de subdominio en GitLab Pages."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"0.0","lessThan":"16.11.6","versionType":"semver","status":"affected"},{"version":"17.0","lessThan":"17.0.4","versionType":"semver","status":"affected"},{"version":"17.1","lessThan":"17.1.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N","baseScore":3.5,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-05T14:15:48.499691Z","id":"CVE-2024-5528","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1023"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-697"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"16.11.6","matchCriteriaId":"B5411AD6-AF61-490A-88E2-65CE1C4FB51E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"16.11.6","matchCriteriaId":"BFE78BD6-735E-42F8-A0D4-D820E738922F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"17.0.4","matchCriteriaId":"C7412902-D4C7-4172-BE56-8D4677226D96"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"17.0.4","matchCriteriaId":"12CB9371-7540-4483-A3EE-061ACAF47067"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"17.1.2","matchCriteriaId":"45878C42-2DC4-4A09-ADA6-80BCCCF35DDA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"17.1.2","matchCriteriaId":"19C3FE9A-BACE-4750-A2C9-E43B7E824711"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/464558","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/2523654","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://about.gitlab.com/releases/2024/07/10/patch-release-gitlab-17-1-2-released/","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Release Notes"]}]}},{"cve":{"id":"CVE-2024-9631","sourceIdentifier":"cve@gitlab.com","published":"2025-02-05T11:15:17.567","lastModified":"2026-06-17T08:24:57.073","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab CE/EE affecting all versions starting from 13.6 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2, where viewing diffs of MR with conflicts can be slow."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde la 13.6 anterior a la 17.2.9, desde la 17.3 anterior a la 17.3.5 y desde la 17.4 anterior a la 17.4.2, donde la visualización de diferencias de MR con conflictos puede ser lenta."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"13.6","lessThan":"17.2.9","versionType":"semver","status":"affected"},{"version":"17.3","lessThan":"17.3.5","versionType":"semver","status":"affected"},{"version":"17.4","lessThan":"17.4.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-05T19:26:20.951787Z","id":"CVE-2024-9631","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-407"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.6.0","versionEndExcluding":"17.2.9","matchCriteriaId":"FC7B22DA-7D45-4B19-BA35-5A332F375E5B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.6.0","versionEndExcluding":"17.2.9","matchCriteriaId":"9EDFE0A2-EE46-40C2-B8A1-48BDEF464A93"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.3.5","matchCriteriaId":"EE7140D0-5D8A-4EDA-91AF-5F14BC4F6307"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.3.5","matchCriteriaId":"9A005AE5-1C1A-4515-9695-A502092BB75A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.4.0","versionEndExcluding":"17.4.2","matchCriteriaId":"7132410B-A160-4C18-8BB6-E53C6A0F35D7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.4.0","versionEndExcluding":"17.4.2","matchCriteriaId":"08991976-707A-4A7B-863D-766928E74FF7"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/480867","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/2650086","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/480867","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Exploit","Issue Tracking"]}]}},{"cve":{"id":"CVE-2024-3976","sourceIdentifier":"cve@gitlab.com","published":"2025-02-05T12:15:27.627","lastModified":"2026-06-17T07:45:35.343","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. It was possible to disclose via the UI the confidential issues title and description from a public project to unauthorised instance users."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde la 14.0 hasta la 16.9.7, desde la 16.10 hasta la 16.10.5 y desde la 16.11 hasta la 16.11.2. Era posible divulgar a través de la interfaz de usuario el título y la descripción de problemas confidenciales de un proyecto público a usuarios de instancias no autorizados."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"14.0","lessThan":"16.9.7","versionType":"semver","status":"affected"},{"version":"16.10","lessThan":"16.10.5","versionType":"semver","status":"affected"},{"version":"16.11","lessThan":"16.11.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-05T14:04:52.021207Z","id":"CVE-2024-3976","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"16.9.7","matchCriteriaId":"DE322CFF-9EF3-452B-9E07-B7DC68BC795F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"16.9.7","matchCriteriaId":"20A54371-18DF-40AC-B67F-4098C719F146"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.10.0","versionEndExcluding":"16.10.5","matchCriteriaId":"356482CA-C9DF-418B-BBDF-C6C09CA8C16D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.10.0","versionEndExcluding":"16.10.5","matchCriteriaId":"154184A5-A34D-4DB1-85B4-DE47A3723E6B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.11.0","versionEndExcluding":"16.11.2","matchCriteriaId":"9B50E4E6-602E-470D-BB03-774CFB1461B6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.11.0","versionEndExcluding":"16.11.2","matchCriteriaId":"5ACCB718-2ABE-4F1A-AB57-B2D3B4879FAC"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/457140","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2470939","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://about.gitlab.com/releases/2024/05/08/patch-release-gitlab-16-11-2-released/","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Release Notes"]}]}},{"cve":{"id":"CVE-2024-2878","sourceIdentifier":"cve@gitlab.com","published":"2025-02-05T13:15:22.523","lastModified":"2026-06-17T07:25:44.190","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.7 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. It was possible for an attacker to cause a denial of service by crafting unusual search terms for branch names."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde la 15.7 hasta la 16.9.7, desde la 16.10 hasta la 16.10.5 y desde la 16.11 hasta la 16.11.2. Un atacante podría provocar una denegación de servicio creando términos de búsqueda inusuales para los nombres de las ramas."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.7","lessThan":"16.9.7","versionType":"semver","status":"affected"},{"version":"16.10","lessThan":"16.10.5","versionType":"semver","status":"affected"},{"version":"16.11","lessThan":"16.11.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-05T14:00:20.380966Z","id":"CVE-2024-2878","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.7.0","versionEndExcluding":"16.9.7","matchCriteriaId":"A09448F4-3752-41B3-A532-EE6F84CED7FD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.7.0","versionEndExcluding":"16.9.7","matchCriteriaId":"0BEF697F-B00D-47B9-98F5-6DF27374171E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.10.0","versionEndExcluding":"16.10.5","matchCriteriaId":"356482CA-C9DF-418B-BBDF-C6C09CA8C16D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.10.0","versionEndExcluding":"16.10.5","matchCriteriaId":"154184A5-A34D-4DB1-85B4-DE47A3723E6B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.11.0","versionEndExcluding":"16.11.2","matchCriteriaId":"9B50E4E6-602E-470D-BB03-774CFB1461B6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.11.0","versionEndExcluding":"16.11.2","matchCriteriaId":"5ACCB718-2ABE-4F1A-AB57-B2D3B4879FAC"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/451918","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2416356","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://about.gitlab.com/releases/2024/05/08/patch-release-gitlab-16-11-2-released/","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Release Notes"]}]}},{"cve":{"id":"CVE-2025-1072","sourceIdentifier":"cve@gitlab.com","published":"2025-02-07T04:15:07.737","lastModified":"2026-06-17T08:38:20.090","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all versions starting from 7.14.1 prior to 17.3.7, 17.4 prior to 17.4.4, and 17.5 prior to 17.5.2. A denial of service could occur upon importing maliciously crafted content using the Fogbugz importer."},{"lang":"es","value":"Se ha descubierto un problema de denegación de servicio (DoS) en GitLab CE/EE que afecta a todas las versiones a partir de la 7.14.1 anterior a la 17.3.7, la 17.4 anterior a la 17.4.4 y la 17.5 anterior a la 17.5.2. Una denegación de servicio podría ocurrir al importar contenido manipulado con fines malintencionados mediante el importador Fogbugz."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"7.14.1","lessThan":"17.3.7","versionType":"semver","status":"affected"},{"version":"17.4","lessThan":"17.4.4","versionType":"semver","status":"affected"},{"version":"17.5","lessThan":"17.5.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-07T15:42:46.504374Z","id":"CVE-2025-1072","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"7.14.1","versionEndExcluding":"17.3.7","matchCriteriaId":"F657868E-09FD-4220-B119-C306351A7A99"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"7.14.1","versionEndExcluding":"17.3.7","matchCriteriaId":"71A132B0-4D3F-4752-919C-C6B1E5714FDF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.4.0","versionEndExcluding":"17.4.4","matchCriteriaId":"1F7F4C7C-334F-4015-AC25-74FCE4BAD311"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.5.0","versionEndExcluding":"17.5.2","matchCriteriaId":"34CDEED3-E7FB-4620-8E07-E4766F9B6593"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.5.0","versionEndExcluding":"17.5.2","matchCriteriaId":"DA99FF56-0441-464D-B369-CF72EF9EEDC7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.7.0","versionEndExcluding":"17.7.3","matchCriteriaId":"BE3A08B9-AB93-4384-AC6F-479770F8F179"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2024/11/13/patch-release-gitlab-17-5-2-released/#denial-of-service-by-importing-malicious-crafted-fogbugz-import-payload","source":"cve@gitlab.com","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/463093","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2504059","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-10383","sourceIdentifier":"cve@gitlab.com","published":"2025-02-07T15:15:16.703","lastModified":"2026-06-17T06:55:31.840","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in the gitlab-web-ide-vscode-fork component distributed over CDN affecting all versions prior to 1.89.1-1.0.0-dev-20241118094343and used by all versions of GitLab CE/EE starting from 15.11 prior to 17.3 and which also temporarily affected versions 17.4, 17.5 and 17.6, where a XSS attack was possible when loading .ipynb files in the web IDE"},{"lang":"es","value":"Se ha descubierto un problema en el componente gitlab-web-ide-vscode-fork distribuido a través de CDN que afecta a todas las versiones anteriores a 1.89.1-1.0.0-dev-20241118094343 y utilizado por todas las versiones de GitLab CE/EE a partir de 15.11 antes de 17.3 y que también afectó temporalmente a las versiones 17.4, 17.5 y 17.6, donde era posible un ataque XSS al cargar archivos .ipynb en el IDE web."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab VSCode Fork","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab-web-ide-vscode-fork:*:*:*:*:*:*:*:*"],"versions":[{"version":"0","lessThan":"1.89.1-1.0.0-dev-20241118094343","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-07T14:35:18.661709Z","id":"CVE-2024-10383","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.11.0","versionEndExcluding":"17.3.0","matchCriteriaId":"62E96CBC-9933-4126-BFE1-6FD6D04707CD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.11.0","versionEndExcluding":"17.3.0","matchCriteriaId":"E500AEAA-4822-421F-81D7-9ED5443C4ED8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.4.0:*:*:*:community:*:*:*","matchCriteriaId":"4FEBC1F7-0AAA-4CA2-B099-3F4218900FB3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.4.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"3AC3130C-A3AA-403A-85D9-92FD2B8BC091"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.5.0:*:*:*:community:*:*:*","matchCriteriaId":"97618D0B-B13A-4111-A78E-3BCB4F023382"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.5.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"603F1273-E30C-4EBB-AFEA-6713D273C4F3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.6.0:*:*:*:community:*:*:*","matchCriteriaId":"3A39B04B-D109-467A-82E1-3FE6CBA48FEE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.6.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"1212AE23-98AB-4E7A-AAB5-0AD266DFC7D4"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/500785","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2765778","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/500785","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2024-12379","sourceIdentifier":"cve@gitlab.com","published":"2025-02-12T15:15:12.707","lastModified":"2026-06-17T06:59:36.600","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A denial of service vulnerability in GitLab CE/EE affecting all versions from 14.1 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to impact the availability of GitLab via unbounded symbol creation via the scopes parameter in a Personal Access Token."},{"lang":"es","value":"Una vulnerabilidad de denegación de servicio en GitLab CE/EE que afecta a todas las versiones desde la 14.1 anterior a la 17.6.5, la 17.7 anterior a la 17.7.4 y la 17.8 anterior a la 17.8.2 permite a un atacante afectar la disponibilidad de GitLab mediante la creación de símbolos ilimitados por medio del parámetro scopes en un token de acceso personal."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"14.1","lessThan":"17.6.5","versionType":"semver","status":"affected"},{"version":"17.7","lessThan":"17.7.4","versionType":"semver","status":"affected"},{"version":"17.8","lessThan":"17.8.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-12T21:00:14.809170Z","id":"CVE-2024-12379","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"17.6.5","matchCriteriaId":"C45D5945-9302-40BA-AD99-D22199AADAF0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"17.6.5","matchCriteriaId":"CBAA7DD8-96CE-4123-A507-FE9E002496CA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.7.0","versionEndExcluding":"17.7.4","matchCriteriaId":"AC284F33-4C92-4C89-AC16-3C111D5ED888"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.7.0","versionEndExcluding":"17.7.4","matchCriteriaId":"23EE6F1C-8A6C-40F7-A89D-D97F9070697C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.8.0","versionEndExcluding":"17.8.2","matchCriteriaId":"840C2B42-F51F-459A-B365-FEA1A2EF7F42"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.8.0","versionEndExcluding":"17.8.2","matchCriteriaId":"C801E385-FAD0-44A5-BDE2-49708E256110"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/508559","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking","Patch"]},{"url":"https://hackerone.com/reports/2871791","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-0376","sourceIdentifier":"cve@gitlab.com","published":"2025-02-12T15:15:15.477","lastModified":"2026-06-17T08:26:22.600","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An XSS vulnerability exists in GitLab CE/EE affecting all versions from 13.3 prior to 17.6.5, 17.7 prior to 17.7.4 and 17.8 prior to 17.8.2 that allows an attacker to execute unauthorized actions via a change page."},{"lang":"es","value":"Existe una vulnerabilidad XSS en GitLab CE/EE que afecta a todas las versiones desde la 13.3 anterior a la 17.6.5, la 17.7 anterior a la 17.7.4 y la 17.8 anterior a la 17.8.2 que permite a un atacante ejecutar acciones no autorizadas a través de una página de cambios."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"13.3","lessThan":"17.6.5","versionType":"semver","status":"affected"},{"version":"17.7","lessThan":"17.7.4","versionType":"semver","status":"affected"},{"version":"17.8","lessThan":"17.8.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-13T14:14:04.357383Z","id":"CVE-2025-0376","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"17.6.5","matchCriteriaId":"BF937A81-7266-462C-AEA4-57D1EBCFF450"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"17.6.5","matchCriteriaId":"9C818DE8-A797-4BE3-A0F7-38B15E65FFEB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.7.0","versionEndExcluding":"17.7.4","matchCriteriaId":"AC284F33-4C92-4C89-AC16-3C111D5ED888"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.7.0","versionEndExcluding":"17.7.4","matchCriteriaId":"23EE6F1C-8A6C-40F7-A89D-D97F9070697C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.8.0","versionEndExcluding":"17.8.2","matchCriteriaId":"840C2B42-F51F-459A-B365-FEA1A2EF7F42"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.8.0","versionEndExcluding":"17.8.2","matchCriteriaId":"C801E385-FAD0-44A5-BDE2-49708E256110"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/512603","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2930243","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-1042","sourceIdentifier":"cve@gitlab.com","published":"2025-02-12T15:15:16.230","lastModified":"2026-06-17T08:38:16.860","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An insecure direct object reference vulnerability in GitLab EE affecting all versions from 15.7 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to view repositories in an unauthorized way."},{"lang":"es","value":"Una vulnerabilidad de referencia directa a objetos insegura en GitLab EE que afecta a todas las versiones desde la 15.7 anterior a la 17.6.5, la 17.7 anterior a la 17.7.4 y la 17.8 anterior a la 17.8.2 permite a un atacante ver repositorios de forma no autorizada."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.7","lessThan":"17.6.5","versionType":"semver","status":"affected"},{"version":"17.7","lessThan":"17.7.4","versionType":"semver","status":"affected"},{"version":"17.8","lessThan":"17.8.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-12T15:12:21.875682Z","id":"CVE-2025-1042","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-552"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.7.0","versionEndExcluding":"17.6.5","matchCriteriaId":"BD236CAB-497E-4C51-99D5-740EEC3A7994"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.7.0","versionEndExcluding":"17.7.4","matchCriteriaId":"23EE6F1C-8A6C-40F7-A89D-D97F9070697C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.8.0","versionEndExcluding":"17.8.2","matchCriteriaId":"C801E385-FAD0-44A5-BDE2-49708E256110"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/50849943","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2886976","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-1212","sourceIdentifier":"cve@gitlab.com","published":"2025-02-12T15:15:18.290","lastModified":"2026-06-17T08:38:36.793","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An information disclosure vulnerability in GitLab CE/EE affecting all versions from 8.3 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to send a crafted request to a backend server to reveal sensitive information."},{"lang":"es","value":"Una vulnerabilidad de divulgación de información en GitLab CE/EE que afecta a todas las versiones desde la 8.3 anterior a la 17.6.5, la 17.7 anterior a la 17.7.4 y la 17.8 anterior a la 17.8.2 permite a un atacante enviar una solicitud manipulada a un servidor backend para revelar información confidencial."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"8.3","lessThan":"17.6.5","versionType":"semver","status":"affected"},{"version":"17.7","lessThan":"17.7.4","versionType":"semver","status":"affected"},{"version":"17.8","lessThan":"17.8.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-12T21:05:47.400987Z","id":"CVE-2025-1212","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-497"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.3.0","versionEndExcluding":"17.6.5","matchCriteriaId":"A31D2D51-8790-4F4B-98ED-666CCD4F830A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.3.0","versionEndExcluding":"17.6.5","matchCriteriaId":"3E86CA66-85B5-409D-815F-20E8A7737B6D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.7.0","versionEndExcluding":"17.7.4","matchCriteriaId":"AC284F33-4C92-4C89-AC16-3C111D5ED888"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.7.0","versionEndExcluding":"17.7.4","matchCriteriaId":"23EE6F1C-8A6C-40F7-A89D-D97F9070697C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.8.0","versionEndExcluding":"17.8.2","matchCriteriaId":"840C2B42-F51F-459A-B365-FEA1A2EF7F42"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.8.0","versionEndExcluding":"17.8.2","matchCriteriaId":"C801E385-FAD0-44A5-BDE2-49708E256110"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/502196","source":"cve@gitlab.com","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2024-9870","sourceIdentifier":"cve@gitlab.com","published":"2025-02-12T16:15:42.563","lastModified":"2026-06-17T08:25:24.957","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An external service interaction vulnerability in GitLab EE affecting all versions from 15.11 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to send requests from the GitLab server to unintended services."},{"lang":"es","value":"Una vulnerabilidad de interacción de servicio externo en GitLab EE que afecta a todas las versiones desde 15.11 anterior a 17.6.5, 17.7 anterior a 17.7.4 y 17.8 anterior a 17.8.2 permite a un atacante enviar solicitudes desde el servidor de GitLab a servicios no deseados."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.11","lessThan":"17.6.5","versionType":"semver","status":"affected"},{"version":"17.7","lessThan":"17.7.4","versionType":"semver","status":"affected"},{"version":"17.8","lessThan":"17.8.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-12T15:59:33.527290Z","id":"CVE-2024-9870","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-441"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.11.0","versionEndExcluding":"17.6.5","matchCriteriaId":"4E75B188-F310-447B-AA53-B3A664E366AA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.7.0","versionEndExcluding":"17.7.4","matchCriteriaId":"23EE6F1C-8A6C-40F7-A89D-D97F9070697C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.8.0","versionEndExcluding":"17.8.2","matchCriteriaId":"C801E385-FAD0-44A5-BDE2-49708E256110"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/498911","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/2734142","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-0516","sourceIdentifier":"cve@gitlab.com","published":"2025-02-12T16:15:42.883","lastModified":"2026-06-17T08:26:38.147","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Improper Authorization in GitLab CE/EE affecting all versions from 17.7 prior to 17.7.4, 17.8 prior to 17.8.2 allow users with limited permissions to perform unauthorized actions on critical project data."},{"lang":"es","value":"La autorización incorrecta en GitLab CE/EE que afecta a todas las versiones desde la 17.7 anterior a la 17.7.4 y desde la 17.8 anterior a la 17.8.2 permite que los usuarios con permisos limitados realicen acciones no autorizadas en datos críticos del proyecto."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.7","lessThan":"17.7.4","versionType":"semver","status":"affected"},{"version":"17.8","lessThan":"17.8.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-12T16:00:02.863628Z","id":"CVE-2025-0516","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.7.0","versionEndExcluding":"17.7.4","matchCriteriaId":"AC284F33-4C92-4C89-AC16-3C111D5ED888"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.7.0","versionEndExcluding":"17.7.4","matchCriteriaId":"23EE6F1C-8A6C-40F7-A89D-D97F9070697C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.8.0","versionEndExcluding":"17.8.2","matchCriteriaId":"840C2B42-F51F-459A-B365-FEA1A2EF7F42"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.8.0","versionEndExcluding":"17.8.2","matchCriteriaId":"C801E385-FAD0-44A5-BDE2-49708E256110"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/513540","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/2914644","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-7102","sourceIdentifier":"cve@gitlab.com","published":"2025-02-13T01:15:24.980","lastModified":"2026-06-17T08:19:21.957","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.5.0 which allows an attacker to trigger a pipeline as another user under certain circumstances."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde la 16.4 hasta la 17.5.0, que permite a un atacante activar una canalización como otro usuario en determinadas circunstancias."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.4","lessThan":"17.5.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N","baseScore":9.6,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-13T14:58:30.991616Z","id":"CVE-2024-7102","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-250"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.4.0","versionEndExcluding":"17.5.0","matchCriteriaId":"53CF6D3C-3985-4057-9273-E116EAEB344F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.4.0","versionEndExcluding":"17.5.0","matchCriteriaId":"AFF24AD5-B0D4-412C-80C9-703276955BFF"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/474414","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2623063","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-8266","sourceIdentifier":"cve@gitlab.com","published":"2025-02-13T01:15:25.137","lastModified":"2026-06-17T08:22:13.730","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab CE/EE affecting all versions starting from 17.1 prior to 17.6.0, which allows an attacker with maintainer role to trigger a pipeline as project owner under certain circumstances."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde la 17.1 anterior a la 17.6.0, que permite a un atacante con el rol fabricante activar una canalización como propietario del proyecto en determinadas circunstancias."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.1","lessThan":"17.6.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N","baseScore":4.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":0.7,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":6.6,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":0.7,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-13T15:06:24.803590Z","id":"CVE-2024-8266","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-250"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"17.6.0","matchCriteriaId":"91B05777-F68E-473D-AF71-0714CE021A0C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"17.6.0","matchCriteriaId":"C8EC404F-01BA-41EF-8069-4B54A953CD81"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/481531","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/2649798","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-1198","sourceIdentifier":"cve@gitlab.com","published":"2025-02-13T02:15:29.627","lastModified":"2026-06-17T08:38:35.107","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue discovered in GitLab CE/EE affecting all versions from 16.11 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 meant that long-lived connections in ActionCable potentially allowed revoked Personal Access Tokens access to streaming results."},{"lang":"es","value":"Un problema descubierto en GitLab CE/EE que afectaba a todas las versiones desde 16.11 hasta 17.6.5, 17.7 hasta 17.7.4 y 17.8 hasta 17.8.2 significaba que las conexiones de larga duración en ActionCable potencialmente permitían el acceso de tokens de acceso personal revocados a los resultados de transmisión."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.11","lessThan":"17.6.5","versionType":"semver","status":"affected"},{"version":"17.7","lessThan":"17.7.4","versionType":"semver","status":"affected"},{"version":"17.8","lessThan":"17.8.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","baseScore":4.2,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":2.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-13T14:57:14.620465Z","id":"CVE-2025-1198","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-613"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.11.0","versionEndExcluding":"17.6.5","matchCriteriaId":"077B7BD7-29E8-4D43-99DA-D20EB7FF1679"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.11.0","versionEndExcluding":"17.6.5","matchCriteriaId":"319B2E66-6FC7-4881-9FC4-C1F83F9B3D00"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.7.0","versionEndExcluding":"17.7.4","matchCriteriaId":"AC284F33-4C92-4C89-AC16-3C111D5ED888"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.7.0","versionEndExcluding":"17.7.4","matchCriteriaId":"23EE6F1C-8A6C-40F7-A89D-D97F9070697C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.8.0","versionEndExcluding":"17.8.2","matchCriteriaId":"840C2B42-F51F-459A-B365-FEA1A2EF7F42"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.8.0","versionEndExcluding":"17.8.2","matchCriteriaId":"C801E385-FAD0-44A5-BDE2-49708E256110"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/511477","source":"cve@gitlab.com","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2024-3303","sourceIdentifier":"cve@gitlab.com","published":"2025-02-13T09:15:09.653","lastModified":"2026-06-17T07:43:44.973","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.6.5, starting from 17.7 prior to 17.7.4, and starting from 17.8 prior to 17.8.2, which allows an attacker to exfiltrate contents of a private issue using prompt injection."},{"lang":"es","value":"Se descubrió un problema en GitLab EE que afecta a todas las versiones desde la 16.0 anterior a la 17.6.5, desde la 17.7 anterior a la 17.7.4 y desde la 17.8 anterior a la 17.8.2, que permite a un atacante exfiltrar el contenido de una emisión privada mediante inyección rápida."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.0","lessThan":"17.6.5","versionType":"semver","status":"affected"},{"version":"17.7","lessThan":"17.7.4","versionType":"semver","status":"affected"},{"version":"17.8","lessThan":"17.8.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N","baseScore":5.7,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-13T14:35:39.833821Z","id":"CVE-2024-3303","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"17.6.5","matchCriteriaId":"50288C87-C49A-4370-8A07-229E6BAD9779"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.7.0","versionEndExcluding":"17.7.4","matchCriteriaId":"23EE6F1C-8A6C-40F7-A89D-D97F9070697C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.8.0","versionEndExcluding":"17.8.2","matchCriteriaId":"C801E385-FAD0-44A5-BDE2-49708E256110"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/454460","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/2418620","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-8186","sourceIdentifier":"cve@gitlab.com","published":"2025-03-03T10:15:09.937","lastModified":"2026-06-17T08:22:04.750","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 16.6 before 17.7.6, 17.8 before 17.8.4, and 17.9 before 17.9.1. An attacker could inject HMTL into the child item search potentially leading to XSS in certain situations."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde la 16.6 hasta la 17.7.6, desde la 17.8 hasta la 17.8.4 y desde la 17.9 hasta la 17.9.1. Un atacante podría inyectar HTML en la búsqueda de elementos secundarios, lo que podría provocar un XSS en determinadas situaciones."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.6","lessThan":"17.7.6","versionType":"semver","status":"affected"},{"version":"17.8","lessThan":"17.8.4","versionType":"semver","status":"affected"},{"version":"17.9","lessThan":"17.9.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-03-03T12:31:28.250221Z","id":"CVE-2024-8186","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.6.0","versionEndExcluding":"17.7.6","matchCriteriaId":"6280CF51-DBF6-43EF-B411-859AB0B05901"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.6.0","versionEndExcluding":"17.7.6","matchCriteriaId":"6D4D80E8-2B17-4AE0-AA83-EF34C8AF31BF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.8.0","versionEndExcluding":"17.8.4","matchCriteriaId":"AB79FD0B-E2CB-48C8-9403-FC11D98CE75B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.8.0","versionEndExcluding":"17.8.4","matchCriteriaId":"BBA524F8-D246-4E22-AD19-D5A7A73BAFDB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.9.0:*:*:*:community:*:*:*","matchCriteriaId":"840493B6-1601-45C8-835A-2ACFBB4A84E2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.9.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"520D3C67-BAA9-49B0-8613-7DC0127499D3"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/480751","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2655757","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-10925","sourceIdentifier":"cve@gitlab.com","published":"2025-03-03T11:15:10.253","lastModified":"2026-06-17T06:56:42.660","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability in GitLab-EE affecting all versions from 16.2 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1 allows a Guest user to read Security policy YAML"},{"lang":"es","value":"Una vulnerabilidad en GitLab-EE que afecta a todas las versiones desde la 16.2 anterior a la 17.7.6, la 17.8 anterior a la 17.8.4 y la 17.9 anterior a la 17.9.1 permite que un usuario invitado lea la política de seguridad YAML"}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.2","lessThan":"17.7.6","versionType":"semver","status":"affected"},{"version":"17.8","lessThan":"17.8.4","versionType":"semver","status":"affected"},{"version":"17.9","lessThan":"17.9.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":3.6},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-03-03T12:03:27.377800Z","id":"CVE-2024-10925","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-639"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.2","versionEndExcluding":"17.7.6","matchCriteriaId":"1725DB84-8B4A-4E9A-B3F4-4E0854AB5814"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.8.0","versionEndExcluding":"17.8.4","matchCriteriaId":"BBA524F8-D246-4E22-AD19-D5A7A73BAFDB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.9.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"520D3C67-BAA9-49B0-8613-7DC0127499D3"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/502857","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/2818270","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-0475","sourceIdentifier":"cve@gitlab.com","published":"2025-03-03T11:15:15.517","lastModified":"2026-06-17T08:26:33.427","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1. A proxy feature could potentially allow unintended content rendering leading to XSS under specific circumstances."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde la 15.10 hasta la 17.7.6, desde la 17.8 hasta la 17.8.4 y desde la 17.9 hasta la 17.9.1. Una función de proxy podría permitir la representación no deseada de contenido, lo que daría lugar a XSS en determinadas circunstancias."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.10","lessThan":"17.7.6","versionType":"semver","status":"affected"},{"version":"17.8","lessThan":"17.8.4","versionType":"semver","status":"affected"},{"version":"17.9","lessThan":"17.9.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-03-03T12:07:34.003288Z","id":"CVE-2025-0475","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.10.0","versionEndExcluding":"17.7.6","matchCriteriaId":"282D9A25-DA2A-425F-AE91-BF3FA3B49BD1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.10.0","versionEndExcluding":"17.7.6","matchCriteriaId":"12A40EC3-CCAA-4967-9634-1B6CE2AAACCA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.8.0","versionEndExcluding":"17.8.4","matchCriteriaId":"AB79FD0B-E2CB-48C8-9403-FC11D98CE75B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.8.0","versionEndExcluding":"17.8.4","matchCriteriaId":"BBA524F8-D246-4E22-AD19-D5A7A73BAFDB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.9.0:*:*:*:community:*:*:*","matchCriteriaId":"840493B6-1601-45C8-835A-2ACFBB4A84E2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.9.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"520D3C67-BAA9-49B0-8613-7DC0127499D3"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/513142","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2932309","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-0555","sourceIdentifier":"cve@gitlab.com","published":"2025-03-03T16:15:39.227","lastModified":"2026-06-17T08:26:41.860","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A Cross Site Scripting (XSS) vulnerability in GitLab-EE affecting all versions from 16.6 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1 allows an attacker to bypass security controls and execute arbitrary scripts in a users browser under specific conditions."},{"lang":"es","value":"Una vulnerabilidad de cross-site scripting (XSS) en GitLab-EE que afecta a todas las versiones desde la 16.6 anterior a la 17.7.6, desde la 17.8 anterior a la 17.8.4 y desde la 17.9 anterior a la 17.9.1 permite a un atacante eludir los controles de seguridad y ejecutar secuencias de comandos arbitrarias en el navegador de un usuario en condiciones específicas."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.6","lessThan":"17.7.6","versionType":"semver","status":"affected"},{"version":"17.8","lessThan":"17.8.4","versionType":"semver","status":"affected"},{"version":"17.9","lessThan":"17.9.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":7.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.3,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-03-04T16:50:31.910092Z","id":"CVE-2025-0555","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.6.0","versionEndExcluding":"17.7.6","matchCriteriaId":"6D4D80E8-2B17-4AE0-AA83-EF34C8AF31BF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.8.0","versionEndExcluding":"17.8.4","matchCriteriaId":"BBA524F8-D246-4E22-AD19-D5A7A73BAFDB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.9.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"520D3C67-BAA9-49B0-8613-7DC0127499D3"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/514004","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2939833","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-1540","sourceIdentifier":"cve@gitlab.com","published":"2025-03-06T09:15:26.317","lastModified":"2026-06-17T08:39:20.153","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE for Self-Managed and Dedicated instances affecting all versions from 17.5 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2. It was possible for a user added as an External to read and clone internal projects under certain circumstances.\""},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE para instancias autoadministradas y dedicadas que afecta a todas las versiones desde la 17.5 anterior a la 17.6.5, desde la 17.7 anterior a la 17.7.4 y desde la 17.8 anterior a la 17.8.2. Era posible que un usuario agregado como externo leyera y clonara proyectos internos en determinadas circunstancias."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.5","lessThan":"17.6.5","versionType":"semver","status":"affected"},{"version":"17.7","lessThan":"17.7.4","versionType":"semver","status":"affected"},{"version":"17.8","lessThan":"17.8.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":3.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","baseScore":4.2,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-03-06T16:28:45.786600Z","id":"CVE-2025-1540","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.5.0","versionEndExcluding":"17.6.5","matchCriteriaId":"999EB085-473F-4939-B50F-4EC84943BFD3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.5.0","versionEndExcluding":"17.6.5","matchCriteriaId":"A7F2F198-6F74-422A-8623-DB29E9E5916A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.7.0","versionEndExcluding":"17.7.4","matchCriteriaId":"AC284F33-4C92-4C89-AC16-3C111D5ED888"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.7.0","versionEndExcluding":"17.7.4","matchCriteriaId":"23EE6F1C-8A6C-40F7-A89D-D97F9070697C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.8.0","versionEndExcluding":"17.8.2","matchCriteriaId":"840C2B42-F51F-459A-B365-FEA1A2EF7F42"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.8.0","versionEndExcluding":"17.8.2","matchCriteriaId":"C801E385-FAD0-44A5-BDE2-49708E256110"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2025/02/12/patch-release-gitlab-17-8-2-released/#saml-authentication-misconfigures-external-user-attribute","source":"cve@gitlab.com","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/512765","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]}]}},{"cve":{"id":"CVE-2025-2045","sourceIdentifier":"cve@gitlab.com","published":"2025-03-06T13:15:12.553","lastModified":"2026-06-17T09:06:11.470","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Improper authorization in GitLab EE affecting all versions from 17.7 prior to 17.7.6, 17.8 prior to 17.8.4, 17.9 prior to 17.9.1  allow users with limited permissions to access to potentially sensitive project analytics data."},{"lang":"es","value":"La autorización incorrecta en GitLab EE que afecta a todas las versiones desde la 17.7 anterior a la 17.7.6, la 17.8 anterior a la 17.8.4 y la 17.9 anterior a la 17.9.1 permite a los usuarios con permisos limitados acceder a datos de análisis de proyectos potencialmente confidenciales."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.7.0","lessThan":"17.7.6","versionType":"semver","status":"affected"},{"version":"17.8","lessThan":"17.8.4","versionType":"semver","status":"affected"},{"version":"17.9","lessThan":"17.9.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-03-06T16:07:06.235439Z","id":"CVE-2025-2045","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.7.0","versionEndExcluding":"17.7.6","matchCriteriaId":"8E917B5A-660A-496F-A300-7870ABBDDA24"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.8.0","versionEndExcluding":"17.8.4","matchCriteriaId":"BBA524F8-D246-4E22-AD19-D5A7A73BAFDB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.9.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"520D3C67-BAA9-49B0-8613-7DC0127499D3"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/512050","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/2921111","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-12380","sourceIdentifier":"cve@gitlab.com","published":"2025-03-13T06:15:35.220","lastModified":"2026-06-17T06:59:36.723","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab EE/CE affecting all versions starting from 11.5 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 before 17.9.2. Certain user inputs in repository mirroring settings could potentially expose sensitive authentication information."},{"lang":"es","value":"Se detectó un problema en GitLab EE/CE que afectaba a todas las versiones (desde la 11.5 hasta la 17.7.7), a todas las versiones (desde la 17.8 hasta la 17.8.5) y a todas las versiones (desde la 17.9 hasta la 17.9.2). Ciertas entradas de usuario en la configuración de duplicación del repositorio podrían exponer información confidencial de autenticación."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"11.5","lessThan":"17.7.7","versionType":"semver","status":"affected"},{"version":"17.8","lessThan":"17.8.5","versionType":"semver","status":"affected"},{"version":"17.9","lessThan":"17.9.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N","baseScore":4.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":0.7,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-03-14T14:32:51.742963Z","id":"CVE-2024-12380","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-209"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"17.7.7","matchCriteriaId":"B6900812-E6F7-47EC-8144-F7B9048AC020"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"17.7.7","matchCriteriaId":"E98F669E-4F7D-4C2C-A8D4-3733746B6C92"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.8.0","versionEndExcluding":"17.8.5","matchCriteriaId":"51278A1A-6BB1-461B-B4D0-38FD58680C3F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.8.0","versionEndExcluding":"17.8.5","matchCriteriaId":"9793DFF7-AA7F-4727-91EE-A05FB4B63D5A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.9.0","versionEndExcluding":"17.9.2","matchCriteriaId":"257CE2B6-A495-4F46-990B-BF5D283530DA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.9.0","versionEndExcluding":"17.9.2","matchCriteriaId":"6373756D-2959-4F3C-AFBA-33BB55570428"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/508557","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2868951","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-13054","sourceIdentifier":"cve@gitlab.com","published":"2025-03-13T06:15:35.427","lastModified":"2026-06-17T07:01:04.263","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab CE/EE affecting all versions before 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17.9.2. where a denial of service vulnerability could allow an attacker to cause a system reboot under certain conditions."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones anteriores a 17.7.7, 17.8 anteriores a 17.8.5 y 17.9 anteriores a 17.9.2, donde una vulnerabilidad de denegación de servicio podría permitir a un atacante provocar un reinicio del sistema en determinadas condiciones."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"0","lessThan":"17.7.7","versionType":"semver","status":"affected"},{"version":"17.8","lessThan":"17.8.5","versionType":"semver","status":"affected"},{"version":"17.9","lessThan":"17.9.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-03-14T14:36:04.155613Z","id":"CVE-2024-13054","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"17.7.7","matchCriteriaId":"0F3B107C-F187-4FDB-B9D7-91E0F79C9367"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"17.7.7","matchCriteriaId":"D032DED0-41AA-4BF7-9C6E-6CCECF99A208"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.8.0","versionEndExcluding":"17.8.5","matchCriteriaId":"51278A1A-6BB1-461B-B4D0-38FD58680C3F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.8.0","versionEndExcluding":"17.8.5","matchCriteriaId":"9793DFF7-AA7F-4727-91EE-A05FB4B63D5A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.9.0","versionEndExcluding":"17.9.2","matchCriteriaId":"257CE2B6-A495-4F46-990B-BF5D283530DA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.9.0","versionEndExcluding":"17.9.2","matchCriteriaId":"6373756D-2959-4F3C-AFBA-33BB55570428"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/511004","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2911928","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-7296","sourceIdentifier":"cve@gitlab.com","published":"2025-03-13T06:15:35.937","lastModified":"2026-06-17T08:19:47.900","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab EE affecting all versions from 16.5 prior to 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17.9.2  which allowed a user with a custom permission to approve pending membership requests beyond the maximum number of allowed users."},{"lang":"es","value":"Se descubrió un problema en GitLab EE que afectaba a todas las versiones desde la 16.5 anterior a la 17.7.7, la 17.8 anterior a la 17.8.5 y la 17.9 anterior a la 17.9.2, que permitía que un usuario con un permiso personalizado aprobara solicitudes de membresía pendientes más allá del número máximo de usuarios permitidos."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.5","lessThan":"17.7.7","versionType":"semver","status":"affected"},{"version":"17.8","lessThan":"17.8.5","versionType":"semver","status":"affected"},{"version":"17.9","lessThan":"17.9.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N","baseScore":2.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-03-14T13:43:26.839368Z","id":"CVE-2024-7296","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.5.0","versionEndExcluding":"17.7.7","matchCriteriaId":"ADE71D75-7A91-46FE-808A-2B90DAB6BBC2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.5.0","versionEndExcluding":"17.7.7","matchCriteriaId":"D24757E6-110B-423A-A85B-4DA06FF951B3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.8.0","versionEndExcluding":"17.8.5","matchCriteriaId":"51278A1A-6BB1-461B-B4D0-38FD58680C3F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.8.0","versionEndExcluding":"17.8.5","matchCriteriaId":"9793DFF7-AA7F-4727-91EE-A05FB4B63D5A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.9.0","versionEndExcluding":"17.9.2","matchCriteriaId":"257CE2B6-A495-4F46-990B-BF5D283530DA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.9.0","versionEndExcluding":"17.9.2","matchCriteriaId":"6373756D-2959-4F3C-AFBA-33BB55570428"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/475056","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/2602274","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-8402","sourceIdentifier":"cve@gitlab.com","published":"2025-03-13T06:15:36.117","lastModified":"2026-06-17T08:22:30.887","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab EE affecting all versions starting from 17.2 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 before 17.9.2. An input validation issue in the Google Cloud IAM integration feature could have enabled a Maintainer to introduce malicious code."},{"lang":"es","value":"Se detectó un problema en GitLab EE que afectaba a todas las versiones (desde la 17.2 hasta la 17.7.7), a todas las versiones (desde la 17.8 hasta la 17.8.5) y a todas las versiones (desde la 17.9 hasta la 17.9.2). Un problema de validación de entrada en la función de integración de Google Cloud IAM podría haber permitido que un fabricante introdujera código malicioso."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.2","lessThan":"17.7.7","versionType":"semver","status":"affected"},{"version":"17.8","lessThan":"17.8.5","versionType":"semver","status":"affected"},{"version":"17.9","lessThan":"17.9.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:N","baseScore":3.7,"baseSeverity":"LOW","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":0.6,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N","baseScore":7.4,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.1,"impactScore":5.8}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-03-13T19:38:50.911735Z","id":"CVE-2024-8402","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-77"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.7.7","matchCriteriaId":"B88C25EC-9DE4-43FF-9042-D2A9FAC07ABB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.8.0","versionEndExcluding":"17.8.5","matchCriteriaId":"9793DFF7-AA7F-4727-91EE-A05FB4B63D5A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.9.0","versionEndExcluding":"17.9.2","matchCriteriaId":"6373756D-2959-4F3C-AFBA-33BB55570428"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/482813","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/2601569","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-0652","sourceIdentifier":"cve@gitlab.com","published":"2025-03-13T06:15:36.643","lastModified":"2026-06-17T08:26:54.500","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE/CE affecting all versions starting from 16.9 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 before 17.9.2 could allow unauthorized users to access confidential information intended for internal use only."},{"lang":"es","value":"Se ha descubierto un problema en GitLab EE/CE que afecta a todas las versiones desde la 16.9 anterior a la 17.7.7, a todas las versiones desde la 17.8 anterior a la 17.8.5 y a todas las versiones desde la 17.9 anterior a la 17.9.2, que podría permitir que usuarios no autorizados accedan a información confidencial destinada únicamente para uso interno."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.9","lessThan":"17.7.7","versionType":"semver","status":"affected"},{"version":"17.8","lessThan":"17.8.5","versionType":"semver","status":"affected"},{"version":"17.9","lessThan":"17.9.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-03-14T18:04:17.187518Z","id":"CVE-2025-0652","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.9.0","versionEndExcluding":"17.7.7","matchCriteriaId":"CDF61374-BBBB-4C6D-B8B1-E08E0C19B942"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.9.0","versionEndExcluding":"17.7.7","matchCriteriaId":"4F69D15B-F94B-4FD8-9836-92C3AB21C1AE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.8.0","versionEndExcluding":"17.8.5","matchCriteriaId":"51278A1A-6BB1-461B-B4D0-38FD58680C3F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.8.0","versionEndExcluding":"17.8.5","matchCriteriaId":"9793DFF7-AA7F-4727-91EE-A05FB4B63D5A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.9.0","versionEndExcluding":"17.9.2","matchCriteriaId":"257CE2B6-A495-4F46-990B-BF5D283530DA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.9.0","versionEndExcluding":"17.9.2","matchCriteriaId":"6373756D-2959-4F3C-AFBA-33BB55570428"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/514532","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2947863","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-1257","sourceIdentifier":"cve@gitlab.com","published":"2025-03-13T06:15:36.810","lastModified":"2026-06-17T08:38:41.490","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab EE affecting all versions starting with 12.3 before 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17.9.2. A vulnerability in certain GitLab instances could allow an attacker to cause a denial of service condition by manipulating specific API inputs."},{"lang":"es","value":"Se descubrió un problema en GitLab EE que afectaba a todas las versiones a partir de la 12.3 anterior a la 17.7.7, de la 17.8 anterior a la 17.8.5 y de la 17.9 anterior a la 17.9.2. Una vulnerabilidad en ciertas instancias de GitLab podría permitir a un atacante provocar una denegación de servicio manipulando entradas específicas de la API."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"12.3","lessThan":"17.7.7","versionType":"semver","status":"affected"},{"version":"17.8","lessThan":"17.8.5","versionType":"semver","status":"affected"},{"version":"17.9","lessThan":"17.9.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-03-14T13:44:00.643584Z","id":"CVE-2025-1257","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.3.0","versionEndExcluding":"17.7.7","matchCriteriaId":"78C5B273-88D5-40AD-9BAF-DA938ABEC4C5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.8.0","versionEndExcluding":"17.8.5","matchCriteriaId":"9793DFF7-AA7F-4727-91EE-A05FB4B63D5A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.9.0","versionEndExcluding":"17.9.2","matchCriteriaId":"6373756D-2959-4F3C-AFBA-33BB55570428"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/519348","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2984218","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-9773","sourceIdentifier":"cve@gitlab.com","published":"2025-03-27T13:15:35.523","lastModified":"2026-06-17T08:25:13.980","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab EE affecting all versions starting from 14.9 before 17.8.6, all versions starting from 17.9 before 17.8.3, all versions starting from 17.10 before 17.10.1. An input validation issue in the Harbor registry integration could have allowed a maintainer to add malicious code to the CLI commands shown in the UI."},{"lang":"es","value":"Se detectó un problema en GitLab EE que afectaba a todas las versiones (desde la 14.9 hasta la 17.8.6), a todas las versiones (desde la 17.9 hasta la 17.8.3) y a todas las versiones (desde la 17.10 hasta la 17.10.1). Un problema de validación de entrada en la integración del registro Harbor podría haber permitido que un responsable añadiera código malicioso a los comandos CLI mostrados en la interfaz de usuario."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"14.9","lessThan":"17.8.6","versionType":"semver","status":"affected"},{"version":"17.9","lessThan":"17.9.3","versionType":"semver","status":"affected"},{"version":"17.10","lessThan":"17.10.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:N","baseScore":3.7,"baseSeverity":"LOW","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":0.6,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","baseScore":8.0,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.1,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-03-27T13:07:31.748921Z","id":"CVE-2024-9773","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-77"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"17.8.6","matchCriteriaId":"0087D9FB-3DDA-4DE3-BFAB-D69B51C7F94E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.9.0","versionEndExcluding":"17.9.3","matchCriteriaId":"CCB5AC8D-FAC9-4C2B-B273-53D84D1F98B7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.10.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"7C528FCC-126C-4DA8-9484-91C9DFAD2585"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/498557","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/2671808","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-0811","sourceIdentifier":"cve@gitlab.com","published":"2025-03-27T13:15:36.237","lastModified":"2026-06-17T08:27:11.123","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. Improper rendering of certain file types leads to cross-site scripting."},{"lang":"es","value":"Se ha detectado un problema en GitLab CE/EE que afecta a todas las versiones (desde la 17.7 hasta la 17.8.6), la 17.9 hasta la 17.9.3 y la 17.10 hasta la 17.10.1. La representación incorrecta de ciertos tipos de archivos provoca cross-site scripting. "}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.7","lessThan":"17.8.6","versionType":"semver","status":"affected"},{"version":"17.9","lessThan":"17.9.3","versionType":"semver","status":"affected"},{"version":"17.10","lessThan":"17.10.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-03-27T13:08:02.820317Z","id":"CVE-2025-0811","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.7.0","versionEndExcluding":"17.8.6","matchCriteriaId":"E0897AE6-9A89-4DD1-9954-49D32D2AACBB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.7.0","versionEndExcluding":"17.8.6","matchCriteriaId":"F401D956-2CC4-4C4A-8010-8435A12593DB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.9.0","versionEndExcluding":"17.9.3","matchCriteriaId":"DC72F4EF-256C-46DB-9DC0-30BF1A463E36"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.9.0","versionEndExcluding":"17.9.3","matchCriteriaId":"CCB5AC8D-FAC9-4C2B-B273-53D84D1F98B7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.10.0:*:*:*:community:*:*:*","matchCriteriaId":"715EED42-B42D-470F-BAB2-8317716200F0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.10.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"7C528FCC-126C-4DA8-9484-91C9DFAD2585"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/515566","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/2961854","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-2242","sourceIdentifier":"cve@gitlab.com","published":"2025-03-27T13:15:36.387","lastModified":"2026-06-17T09:06:36.460","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An improper access control vulnerability in GitLab CE/EE affecting all versions from 17.4 prior to 17.8.6, 17.9 prior to 17.9.3, and 17.10 prior to 17.10.1 allows a user who was an instance admin before but has since been downgraded to a regular user to continue to maintain elevated privileges to groups and projects."},{"lang":"es","value":"Una vulnerabilidad de control de acceso inadecuado en GitLab CE/EE que afecta a todas las versiones desde la 17.4 anterior a la 17.8.6, la 17.9 anterior a la 17.9.3 y la 17.10 anterior a la 17.10.1 permite que un usuario que antes era administrador de instancia, pero que desde entonces ha sido degradado a usuario normal, continúe manteniendo privilegios elevados en grupos y proyectos."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.4","lessThan":"17.8.6","versionType":"semver","status":"affected"},{"version":"17.9","lessThan":"17.9.3","versionType":"semver","status":"affected"},{"version":"17.10","lessThan":"17.10.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.6,"impactScore":5.9},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-03-27T13:10:51.657154Z","id":"CVE-2025-2242","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.4.0","versionEndExcluding":"17.8.6","matchCriteriaId":"36E91DAC-C810-4357-B054-C48D9AA8A134"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.4.0","versionEndExcluding":"17.8.6","matchCriteriaId":"FA812577-FBDB-4CE7-AC16-E63D8F67119F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.9.0","versionEndExcluding":"17.9.3","matchCriteriaId":"DC72F4EF-256C-46DB-9DC0-30BF1A463E36"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.9.0","versionEndExcluding":"17.9.3","matchCriteriaId":"CCB5AC8D-FAC9-4C2B-B273-53D84D1F98B7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.10.0:*:*:*:community:*:*:*","matchCriteriaId":"715EED42-B42D-470F-BAB2-8317716200F0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.10.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"7C528FCC-126C-4DA8-9484-91C9DFAD2585"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/516271","source":"cve@gitlab.com","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2025-2255","sourceIdentifier":"cve@gitlab.com","published":"2025-03-27T13:15:36.520","lastModified":"2026-06-17T09:06:38.267","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in Gitlab EE/CE for AppSec affecting all versions from 13.5.0 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. Certain error messages could allow Cross-Site Scripting attacks (XSS). for AppSec."},{"lang":"es","value":"Se ha detectado un problema en Gitlab EE/CE para AppSec que afecta a todas las versiones desde la 13.5.0 hasta la 17.8.6, la 17.9 hasta la 17.9.3 y la 17.10 hasta la 17.10.1. Algunos mensajes de error podrían permitir ataques de Cross-Site Scripting  (XSS) para AppSec."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"13.5.0","lessThan":"17.8.6","versionType":"semver","status":"affected"},{"version":"17.9","lessThan":"17.9.3","versionType":"semver","status":"affected"},{"version":"17.10","lessThan":"17.10.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-03-27T13:13:05.427586Z","id":"CVE-2025-2255","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.5.0","versionEndExcluding":"17.8.6","matchCriteriaId":"A40ADA19-8565-4CF6-81F9-8EB2185CC1C7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.5.0","versionEndExcluding":"17.8.6","matchCriteriaId":"70A46B00-68BC-45C4-A4CC-5938BB0605A0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.9.0","versionEndExcluding":"17.9.3","matchCriteriaId":"DC72F4EF-256C-46DB-9DC0-30BF1A463E36"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.9.0","versionEndExcluding":"17.9.3","matchCriteriaId":"CCB5AC8D-FAC9-4C2B-B273-53D84D1F98B7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.10.0:*:*:*:community:*:*:*","matchCriteriaId":"715EED42-B42D-470F-BAB2-8317716200F0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.10.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"7C528FCC-126C-4DA8-9484-91C9DFAD2585"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/524635","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/2994150","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-2867","sourceIdentifier":"cve@gitlab.com","published":"2025-03-27T14:15:55.827","lastModified":"2026-06-17T09:07:45.850","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in the GitLab Duo with Amazon Q affecting all versions from 17.8 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. A specifically crafted issue could manipulate AI-assisted development features to potentially expose sensitive project data to unauthorized users."},{"lang":"es","value":"Se ha descubierto un problema en GitLab Duo con Amazon Q que afecta a todas las versiones (desde la 17.8 hasta la 17.8.6), desde la 17.9 hasta la 17.9.3 y desde la 17.10 hasta la 17.10.1. Un problema manipulado específicamente podría manipular las funciones de desarrollo asistido por IA para exponer datos confidenciales del proyecto a usuarios no autorizados."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.8","lessThan":"17.8.6","versionType":"semver","status":"affected"},{"version":"17.9","lessThan":"17.9.3","versionType":"semver","status":"affected"},{"version":"17.10","lessThan":"17.10.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":4.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.3,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-03-27T14:18:23.211357Z","id":"CVE-2025-2867","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-94"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.8.0","versionEndExcluding":"17.8.6","matchCriteriaId":"2B1E1891-6616-488B-8C97-10B93670A27D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.8.0","versionEndExcluding":"17.8.6","matchCriteriaId":"FB3812AE-5369-4CC0-BD74-8731C55A7CE3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.9.0","versionEndExcluding":"17.9.3","matchCriteriaId":"DC72F4EF-256C-46DB-9DC0-30BF1A463E36"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.9.0","versionEndExcluding":"17.9.3","matchCriteriaId":"CCB5AC8D-FAC9-4C2B-B273-53D84D1F98B7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.10.0:*:*:*:community:*:*:*","matchCriteriaId":"715EED42-B42D-470F-BAB2-8317716200F0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.10.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"7C528FCC-126C-4DA8-9484-91C9DFAD2585"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/512509","source":"cve@gitlab.com","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2024-10307","sourceIdentifier":"cve@gitlab.com","published":"2025-03-28T10:15:15.427","lastModified":"2026-06-17T06:55:22.887","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE/CE affecting all versions from 12.10 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. A maliciously crafted file can cause uncontrolled CPU consumption when viewing the associated merge request."},{"lang":"es","value":"Se ha descubierto un problema en GitLab EE/CE que afecta a todas las versiones desde la 12.10 hasta la 17.8.6, la 17.9 hasta la 17.9.3 y la 17.10 hasta la 17.10.1. Un archivo malintencionado puede causar un consumo descontrolado de CPU al visualizar la solicitud de fusión asociada."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"12.10","lessThan":"17.8.6","versionType":"semver","status":"affected"},{"version":"17.9","lessThan":"17.9.3","versionType":"semver","status":"affected"},{"version":"17.10","lessThan":"17.10.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-03-28T13:42:02.441017Z","id":"CVE-2024-10307","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.10.0","versionEndExcluding":"17.8.6","matchCriteriaId":"396E9F87-A3EA-4ECE-BA24-6BC35FF568AB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.10.0","versionEndExcluding":"17.8.6","matchCriteriaId":"70D9DB5B-B239-403F-AB36-528D9ECB592D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.9.0","versionEndExcluding":"17.9.3","matchCriteriaId":"DC72F4EF-256C-46DB-9DC0-30BF1A463E36"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.9.0","versionEndExcluding":"17.9.3","matchCriteriaId":"CCB5AC8D-FAC9-4C2B-B273-53D84D1F98B7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.10.0:*:*:*:community:*:*:*","matchCriteriaId":"715EED42-B42D-470F-BAB2-8317716200F0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.10.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"7C528FCC-126C-4DA8-9484-91C9DFAD2585"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/500497","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2775113","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-12619","sourceIdentifier":"cve@gitlab.com","published":"2025-03-28T10:15:15.760","lastModified":"2026-06-17T07:00:09.397","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1, allowing internal users to gain unauthorized access to internal projects."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde la 16.0 hasta la 17.8.6, la 17.9 hasta la 17.9.3 y la 17.10 hasta la 17.10.1, lo que permite que los usuarios internos obtengan acceso no autorizado a proyectos internos."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.0","lessThan":"17.8.6","versionType":"semver","status":"affected"},{"version":"17.9","lessThan":"17.9.3","versionType":"semver","status":"affected"},{"version":"17.10","lessThan":"17.10.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:L/A:N","baseScore":5.2,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":0.9,"impactScore":4.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-03-28T13:46:02.996419Z","id":"CVE-2024-12619","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1220"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"17.8.6","matchCriteriaId":"B953D693-BEC1-459D-AF77-87B585C5C905"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"17.8.6","matchCriteriaId":"DD53ACDB-ED16-4BC1-B261-6149240AD0D0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.9.0","versionEndExcluding":"17.9.3","matchCriteriaId":"DC72F4EF-256C-46DB-9DC0-30BF1A463E36"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.9.0","versionEndExcluding":"17.9.3","matchCriteriaId":"CCB5AC8D-FAC9-4C2B-B273-53D84D1F98B7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.10.0:*:*:*:community:*:*:*","matchCriteriaId":"715EED42-B42D-470F-BAB2-8317716200F0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.10.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"7C528FCC-126C-4DA8-9484-91C9DFAD2585"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/509324","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/2888260","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-11129","sourceIdentifier":"cve@gitlab.com","published":"2025-04-10T13:15:43.993","lastModified":"2026-06-17T06:57:07.830","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions from 17.1 before 17.8.7, 17.9 before  17.9.6, and 17.10 before 17.10.4. This allows attackers to perform targeted searches with sensitive keywords to get the count of issues containing the searched term.\""},{"lang":"es","value":" Se ha descubierto un problema en GitLab EE que afecta a todas las versiones desde la 17.1 hasta la 17.8.7, la 17.9 hasta la 17.9.6 y la 17.10 hasta la 17.10.4. Esto permite a los atacantes realizar búsquedas específicas con palabras clave sensibles para obtener el recuento de problemas que contienen el término buscado."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.1","lessThan":"17.8.7","versionType":"semver","status":"affected"},{"version":"17.9","lessThan":"17.9.6","versionType":"semver","status":"affected"},{"version":"17.10","lessThan":"17.10.4","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N","baseScore":6.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.8,"impactScore":4.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-04-10T13:16:18.635193Z","id":"CVE-2024-11129","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-209"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"17.8.6","matchCriteriaId":"90FFEF88-9D28-4C80-A135-C4FE12395620"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"17.8.7","matchCriteriaId":"2C53F271-B34B-479C-8061-39B81BD181F5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.9.0","versionEndExcluding":"17.9.6","matchCriteriaId":"DA3826E3-A00E-4E5A-81A0-28DCB2BE10B5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.9.0","versionEndExcluding":"17.9.6","matchCriteriaId":"2BE64DE3-7E01-4B8C-81D3-A1443D2450A3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.10.0","versionEndExcluding":"17.10.4","matchCriteriaId":"73742B4C-F768-4F0D-A34D-B551A3BC6177"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.10.0","versionEndExcluding":"17.10.4","matchCriteriaId":"F95150D7-C98E-4177-AB2B-8E9B7100DF2D"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/503722","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2717400","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-1677","sourceIdentifier":"cve@gitlab.com","published":"2025-04-10T13:15:46.473","lastModified":"2026-06-17T08:39:35.303","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all up to 17.8.7, 17.9 prior to 17.9.6 and 17.10 prior to 17.10.4 A denial of service could occur upon injecting oversized payloads into CI pipeline exports."},{"lang":"es","value":" Se ha descubierto un problema de denegación de servicio (DoS) en GitLab CE/EE que afecta a todas las versiones hasta 17.8.7, 17.9 anteriores a 17.9.6 y 17.10 anteriores a 17.10.4. Una denegación de servicio podría ocurrir al inyectar payloads de gran tamaño en las exportaciones de la canalización de CI."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"0","lessThan":"17.8.7","versionType":"semver","status":"affected"},{"version":"17.9","lessThan":"17.9.6","versionType":"semver","status":"affected"},{"version":"17.10","lessThan":"17.10.4","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-04-10T13:02:47.849946Z","id":"CVE-2025-1677","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndIncluding":"17.8.7","matchCriteriaId":"2ED7DA69-5136-41CF-8BAD-B9C63E565A0F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndIncluding":"17.8.7","matchCriteriaId":"EDC53ABA-492A-420A-A524-FD380806E111"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.9.0","versionEndExcluding":"17.9.6","matchCriteriaId":"DA3826E3-A00E-4E5A-81A0-28DCB2BE10B5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.9.0","versionEndExcluding":"17.9.6","matchCriteriaId":"2BE64DE3-7E01-4B8C-81D3-A1443D2450A3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.10.0","versionEndExcluding":"17.10.4","matchCriteriaId":"73742B4C-F768-4F0D-A34D-B551A3BC6177"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.10.0","versionEndExcluding":"17.10.4","matchCriteriaId":"F95150D7-C98E-4177-AB2B-8E9B7100DF2D"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/521117","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3004008","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-2408","sourceIdentifier":"cve@gitlab.com","published":"2025-04-10T13:15:51.760","lastModified":"2026-06-17T09:06:58.267","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 13.12 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. Under certain conditions users could bypass IP access restrictions and view sensitive information."},{"lang":"es","value":" Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde la 13.12 hasta la 17.8.7, la 17.9 hasta la 17.9.6 y la 17.10 hasta la 17.10.4. En determinadas condiciones, los usuarios podrían omitir las restricciones de acceso IP y ver información confidencial."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"13.12","lessThan":"17.8.7","versionType":"semver","status":"affected"},{"version":"17.9","lessThan":"17.9.6","versionType":"semver","status":"affected"},{"version":"17.10","lessThan":"17.10.4","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-04-10T13:03:20.124293Z","id":"CVE-2025-2408","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1220"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.12.0","versionEndExcluding":"17.8.7","matchCriteriaId":"D6A1C09B-6403-43A0-BAB5-D57F4BBA8007"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.12.0","versionEndExcluding":"17.8.7","matchCriteriaId":"D826CD76-AE92-42B5-A858-9A125CC89C72"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.9.0","versionEndExcluding":"17.9.6","matchCriteriaId":"DA3826E3-A00E-4E5A-81A0-28DCB2BE10B5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.9.0","versionEndExcluding":"17.9.6","matchCriteriaId":"2BE64DE3-7E01-4B8C-81D3-A1443D2450A3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.10.0","versionEndExcluding":"17.10.4","matchCriteriaId":"73742B4C-F768-4F0D-A34D-B551A3BC6177"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.10.0","versionEndExcluding":"17.10.4","matchCriteriaId":"F95150D7-C98E-4177-AB2B-8E9B7100DF2D"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/525323","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/3027775","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-2469","sourceIdentifier":"cve@gitlab.com","published":"2025-04-10T14:15:27.317","lastModified":"2026-06-17T09:07:00.700","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.9.6, and 17.10 before 17.10.4. The runtime profiling data of a specific service was accessible to unauthenticated users."},{"lang":"es","value":" Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde la 17.9 anterior a la 17.9.6 y desde la 17.10 anterior a la 17.10.4. Los datos de creación de perfiles en tiempo de ejecución de un servicio específico eran accesibles para usuarios no autenticados."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.9","lessThan":"17.9.6","versionType":"semver","status":"affected"},{"version":"17.10","lessThan":"17.10.4","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":3.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-04-10T14:12:51.491511Z","id":"CVE-2025-2469","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1295"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.9.0","versionEndExcluding":"17.9.6","matchCriteriaId":"DA3826E3-A00E-4E5A-81A0-28DCB2BE10B5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.9.0","versionEndExcluding":"17.9.6","matchCriteriaId":"2BE64DE3-7E01-4B8C-81D3-A1443D2450A3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.10.0","versionEndExcluding":"17.10.4","matchCriteriaId":"73742B4C-F768-4F0D-A34D-B551A3BC6177"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.10.0","versionEndExcluding":"17.10.4","matchCriteriaId":"F95150D7-C98E-4177-AB2B-8E9B7100DF2D"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/525374","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/3030586","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-0362","sourceIdentifier":"cve@gitlab.com","published":"2025-04-10T15:16:02.337","lastModified":"2026-06-17T08:26:21.097","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 7.7 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. Under certain conditions, an attacker could potentially trick users into unintentionally authorizing sensitive actions on their behalf."},{"lang":"es","value":" Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde la 7.7 hasta la 17.8.7, la 17.9 hasta la 17.9.6 y la 17.10 hasta la 17.10.4. Bajo ciertas condiciones, un atacante podría potencialmente engañar a los usuarios para que autoricen involuntariamente acciones confidenciales en su nombre."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"7.7","lessThan":"17.8.7","versionType":"semver","status":"affected"},{"version":"17.9","lessThan":"17.9.6","versionType":"semver","status":"affected"},{"version":"17.10","lessThan":"17.10.4","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-04-10T14:56:03.299148Z","id":"CVE-2025-0362","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1021"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"7.7.0","versionEndExcluding":"17.8.7","matchCriteriaId":"9117D28C-FE99-4EF0-83F3-CA5D78B154D6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"7.7.0","versionEndExcluding":"17.8.7","matchCriteriaId":"E5662965-ECBA-4B15-9BCE-B60C742E0C52"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.9.0","versionEndExcluding":"17.9.6","matchCriteriaId":"DA3826E3-A00E-4E5A-81A0-28DCB2BE10B5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.9.0","versionEndExcluding":"17.9.6","matchCriteriaId":"2BE64DE3-7E01-4B8C-81D3-A1443D2450A3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.10.0","versionEndExcluding":"17.10.4","matchCriteriaId":"73742B4C-F768-4F0D-A34D-B551A3BC6177"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.10.0","versionEndExcluding":"17.10.4","matchCriteriaId":"F95150D7-C98E-4177-AB2B-8E9B7100DF2D"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/512425","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2926425","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-12244","sourceIdentifier":"cve@gitlab.com","published":"2025-04-24T08:15:14.020","lastModified":"2026-06-17T06:59:19.503","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in access controls could allow users to view certain restricted project information even when related features are disabled in GitLab EE, affecting all versions from 17.7 prior to 17.9.7, 17.10 prior to 17.10.5, and 17.11 prior to 17.11.1."},{"lang":"es","value":"Se ha descubierto un problema en los controles de acceso que podría permitir a los usuarios ver cierta información restringida del proyecto incluso cuando las funciones relacionadas están deshabilitadas en GitLab EE, lo que afecta a todas las versiones desde la 17.7 anterior a la 17.9.7, la 17.10 anterior a la 17.10.5 y la 17.11 anterior a la 17.11.1."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.7","lessThan":"17.9.7","versionType":"semver","status":"affected"},{"version":"17.10","lessThan":"17.10.5","versionType":"semver","status":"affected"},{"version":"17.11","lessThan":"17.11.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-04-24T13:43:12.202214Z","id":"CVE-2024-12244","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.7.0","versionEndExcluding":"17.9.7","matchCriteriaId":"5F0499FE-AB96-4929-B157-EEF7E87941DD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.7.0","versionEndExcluding":"17.9.7","matchCriteriaId":"95E72E4A-81D8-445D-A4BD-2F7A15ABB44D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.10.0","versionEndExcluding":"17.10.5","matchCriteriaId":"C81D345F-13AE-4508-B4C6-60E361EADC00"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.10.0","versionEndExcluding":"17.10.5","matchCriteriaId":"CA1D8D06-9A39-43E9-A638-5C82A59C00B4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.11.0:*:*:*:community:*:*:*","matchCriteriaId":"DC849E49-FBCD-4F20-BCFA-E28BC7FF640F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.11.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"D30C941F-4464-4E1A-AA49-624F451A9A4E"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/508046","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/2862754","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-0639","sourceIdentifier":"cve@gitlab.com","published":"2025-04-24T08:15:14.190","lastModified":"2026-06-17T08:26:53.233","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered affecting service availability via issue preview in GitLab CE/EE affecting all versions from 16.7 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1."},{"lang":"es","value":"Se ha descubierto un problema que afecta la disponibilidad del servicio a través de la vista previa del problema en GitLab CE/EE que afecta a todas las versiones desde la 16.7 hasta la 17.9.7, la 17.10 hasta la 17.10.5 y la 17.11 hasta la 17.11.1."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.7","lessThan":"17.9.7","versionType":"semver","status":"affected"},{"version":"17.10","lessThan":"17.10.5","versionType":"semver","status":"affected"},{"version":"17.11","lessThan":"17.11.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-04-24T13:43:16.613158Z","id":"CVE-2025-0639","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.7.0","versionEndExcluding":"17.9.7","matchCriteriaId":"9BDDA20F-1EC1-4772-9904-512D1AE232CD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.7.0","versionEndExcluding":"17.9.7","matchCriteriaId":"10EDE3BE-A0E2-41CF-B564-0111AF088886"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.10.0","versionEndExcluding":"17.10.5","matchCriteriaId":"C81D345F-13AE-4508-B4C6-60E361EADC00"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.10.0","versionEndExcluding":"17.10.5","matchCriteriaId":"CA1D8D06-9A39-43E9-A638-5C82A59C00B4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.11.0:*:*:*:community:*:*:*","matchCriteriaId":"DC849E49-FBCD-4F20-BCFA-E28BC7FF640F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.11.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"D30C941F-4464-4E1A-AA49-624F451A9A4E"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/514507","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2946553","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-1908","sourceIdentifier":"cve@gitlab.com","published":"2025-04-24T08:15:14.333","lastModified":"2026-06-17T08:40:19.140","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE/CE that could allow an attacker to track users' browsing activities, potentially leading to full account take-over, affecting all versions from 16.6 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1."},{"lang":"es","value":"Se ha descubierto un problema en GitLab EE/CE que podría permitir a un atacante rastrear las actividades de navegación de los usuarios, lo que podría llevar al control total de la cuenta, afectando a todas las versiones desde la 16.6 hasta la 17.9.7, la 17.10 hasta la 17.10.5 y la 17.11 hasta la 17.11.1."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.6","lessThan":"17.9.7","versionType":"semver","status":"affected"},{"version":"17.10","lessThan":"17.10.5","versionType":"semver","status":"affected"},{"version":"17.11","lessThan":"17.11.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":7.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.3,"impactScore":5.8}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-04-24T13:43:22.710892Z","id":"CVE-2025-1908","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-840"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.6.0","versionEndExcluding":"17.9.7","matchCriteriaId":"24E20FB2-2D62-44D3-B33F-041B393073DC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.6.0","versionEndExcluding":"17.9.7","matchCriteriaId":"9B9C18BF-5C6B-4F81-9F0E-13C61C98D4D9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.10.0","versionEndExcluding":"17.10.5","matchCriteriaId":"C81D345F-13AE-4508-B4C6-60E361EADC00"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.10.0","versionEndExcluding":"17.10.5","matchCriteriaId":"CA1D8D06-9A39-43E9-A638-5C82A59C00B4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.11.0:*:*:*:community:*:*:*","matchCriteriaId":"DC849E49-FBCD-4F20-BCFA-E28BC7FF640F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.11.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"D30C941F-4464-4E1A-AA49-624F451A9A4E"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/523065","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/3016623","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-8973","sourceIdentifier":"cve@gitlab.com","published":"2025-05-09T17:15:50.453","lastModified":"2026-06-17T08:23:39.607","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.1 prior to 17.9.8, from 17.10 prior to 17.10.6, and from 17.11 prior to 17.11.2. It was possible to cause a DoS condition via GitHub import requests using a malicious crafted payload."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones (desde la 17.1 hasta la 17.9.8), desde la 17.10 hasta la 17.10.6 y desde la 17.11 hasta la 17.11.2. Era posible provocar una denegación de servicio (DoS) mediante solicitudes de importación de GitHub utilizando un payload malicioso."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.1","lessThan":"17.9.8","versionType":"semver","status":"affected"},{"version":"17.10","lessThan":"17.10.6","versionType":"semver","status":"affected"},{"version":"17.11","lessThan":"17.11.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-09T19:54:09.840803Z","id":"CVE-2024-8973","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"17.9.8","matchCriteriaId":"669F6B5C-E23F-41E0-A731-394AB4FF4042"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"17.9.8","matchCriteriaId":"FC5E023B-C289-4B41-BA38-A21701469038"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.10.0","versionEndExcluding":"17.10.6","matchCriteriaId":"EB9C790F-E33F-41DB-A218-BB5DC6C0AC34"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.10.0","versionEndExcluding":"17.10.6","matchCriteriaId":"F8A5F80D-BB57-439E-B66D-2B0675FB1156"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.11.0","versionEndExcluding":"17.11.2","matchCriteriaId":"F0485096-6827-447F-8D93-EFB058AA31DC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.11.0","versionEndExcluding":"17.11.2","matchCriteriaId":"9DBAC61C-C127-4833-979B-CFFE433204DD"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/491041","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2711684","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-0549","sourceIdentifier":"cve@gitlab.com","published":"2025-05-09T17:15:50.643","lastModified":"2026-06-17T08:26:41.643","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.3 prior to 17.9.8, from 17.10 prior to 17.10.6, and from 17.11 prior to 17.11.2. A security vulnerability allows attackers to bypass Device OAuth flow protections, enabling authorization form submission through minimal user interaction."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones (desde la 17.3 hasta la 17.9.8), desde la 17.10 hasta la 17.10.6 y desde la 17.11 hasta la 17.11.2. Una vulnerabilidad de seguridad permite a los atacantes eludir las protecciones del flujo OAuth del dispositivo, lo que permite el envío de formularios de autorización con una mínima interacción del usuario."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.3","lessThan":"17.9.8","versionType":"semver","status":"affected"},{"version":"17.10","lessThan":"17.10.6","versionType":"semver","status":"affected"},{"version":"17.11","lessThan":"17.11.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N","baseScore":6.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-09T19:55:41.860099Z","id":"CVE-2025-0549","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-288"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.9.8","matchCriteriaId":"45538A1F-8ADA-4AF8-BC42-EAE19D2D791F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.9.8","matchCriteriaId":"62C1BE7B-73E1-4B09-BAD0-35A39115D3E0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.10.0","versionEndExcluding":"17.10.6","matchCriteriaId":"EB9C790F-E33F-41DB-A218-BB5DC6C0AC34"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.10.0","versionEndExcluding":"17.10.6","matchCriteriaId":"F8A5F80D-BB57-439E-B66D-2B0675FB1156"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.11.0","versionEndExcluding":"17.11.2","matchCriteriaId":"F0485096-6827-447F-8D93-EFB058AA31DC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.11.0","versionEndExcluding":"17.11.2","matchCriteriaId":"9DBAC61C-C127-4833-979B-CFFE433204DD"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/513996","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/2927555","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-1278","sourceIdentifier":"cve@gitlab.com","published":"2025-05-09T17:15:50.790","lastModified":"2026-06-17T08:38:43.993","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 12.0 before 17.9.8, 17.10 before 17.10.6, and 17.11 before 17.11.2. Under certain conditions users could bypass IP access restrictions and view sensitive information."},{"lang":"es","value":"Se ha detectado un problema en GitLab CE/EE que afecta a todas las versiones (desde la 12.0 hasta la 17.9.8), la 17.10 hasta la 17.10.6 y la 17.11 hasta la 17.11.2. En determinadas circunstancias, los usuarios podían eludir las restricciones de acceso IP y acceder a información confidencial."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"12.0","lessThan":"17.9.8","versionType":"semver","status":"affected"},{"version":"17.10","lessThan":"17.10.6","versionType":"semver","status":"affected"},{"version":"17.11","lessThan":"17.11.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-09T20:03:01.720971Z","id":"CVE-2025-1278","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1220"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.0.0","versionEndExcluding":"17.9.8","matchCriteriaId":"805A7E82-754C-4622-8BC2-A2ED9570F003"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.0.0","versionEndExcluding":"17.9.8","matchCriteriaId":"7AE283A8-B304-4CEE-B03E-6BFC9224110F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.10.0","versionEndExcluding":"17.10.6","matchCriteriaId":"EB9C790F-E33F-41DB-A218-BB5DC6C0AC34"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.10.0","versionEndExcluding":"17.10.6","matchCriteriaId":"F8A5F80D-BB57-439E-B66D-2B0675FB1156"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.11.0","versionEndExcluding":"17.11.2","matchCriteriaId":"F0485096-6827-447F-8D93-EFB058AA31DC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.11.0","versionEndExcluding":"17.11.2","matchCriteriaId":"9DBAC61C-C127-4833-979B-CFFE433204DD"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/519580","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2977149","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-1110","sourceIdentifier":"cve@gitlab.com","published":"2025-05-22T14:16:02.300","lastModified":"2026-06-17T08:38:24.177","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 18.0 before 18.0.1. In certain circumstances, a user with limited permissions could access Job Data via a crafted GraphQL query."},{"lang":"es","value":"Se ha detectado un problema en GitLab CE/EE que afecta a todas las versiones, desde la 18.0 hasta la 18.0.1. En determinadas circunstancias, un usuario con permisos limitados podría acceder a los datos del trabajo mediante una consulta GraphQL manipulada."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.0","lessThan":"18.0.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N","baseScore":2.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-22T14:17:35.369233Z","id":"CVE-2025-1110","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1220"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.0.0:*:*:*:community:*:*:*","matchCriteriaId":"C7F28C32-4C21-4EE4-985C-34BD8C9FE300"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"52187A72-1412-48DE-90DD-2948630CFC19"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/517693","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2972576","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-2853","sourceIdentifier":"cve@gitlab.com","published":"2025-05-22T14:16:02.677","lastModified":"2026-06-17T09:07:44.230","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of proper validation in GitLab could allow an authenticated user to cause a denial of service condition."},{"lang":"es","value":"Se ha detectado un problema en GitLab CE/EE que afecta a todas las versiones anteriores a la 17.10.7, 17.11 anteriores a la 17.11.3 y 18.0 anteriores a la 18.0.1. La falta de una validación adecuada en GitLab podría permitir que un usuario autenticado provoque una denegación de servicio."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"0","lessThan":"17.10.7","versionType":"semver","status":"affected"},{"version":"17.11","lessThan":"17.11.3","versionType":"semver","status":"affected"},{"version":"18.0","lessThan":"18.0.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-22T14:50:23.112145Z","id":"CVE-2025-2853","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"17.10.7","matchCriteriaId":"D134A1A8-5E9C-4252-B0AA-1684A76EC3B4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"17.10.7","matchCriteriaId":"8064E80E-002F-4809-A7DB-B50F7449C3E2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.11.0","versionEndExcluding":"17.11.3","matchCriteriaId":"194F7832-AEB6-4CD4-8CA8-81D8BF1666C9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.11.0","versionEndExcluding":"17.11.3","matchCriteriaId":"85308EBB-8AB6-4344-9944-D124878DA138"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.0.0:*:*:*:community:*:*:*","matchCriteriaId":"C7F28C32-4C21-4EE4-985C-34BD8C9FE300"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"52187A72-1412-48DE-90DD-2948630CFC19"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/527218","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3015673","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-3111","sourceIdentifier":"cve@gitlab.com","published":"2025-05-22T14:16:02.893","lastModified":"2026-06-17T09:19:12.167","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 10.2 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of input validation in the Kubernetes integration could allow an authenticated user to cause denial of service.."},{"lang":"es","value":"Se ha detectado un problema en GitLab CE/EE que afecta a todas las versiones (desde la 10.2 hasta la 17.10.7), la 17.11 hasta la 17.11.3 y la 18.0 hasta la 18.0.1. La falta de validación de entrada en la integración de Kubernetes podría permitir que un usuario autenticado provoque una denegación de servicio."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"10.2","lessThan":"17.10.7","versionType":"semver","status":"affected"},{"version":"17.11","lessThan":"17.11.3","versionType":"semver","status":"affected"},{"version":"18.0","lessThan":"18.0.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-22T14:51:00.607792Z","id":"CVE-2025-3111","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.2.0","versionEndExcluding":"17.10.7","matchCriteriaId":"4706A0BC-B0FE-4FD0-96D0-24CE76473740"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.2.0","versionEndExcluding":"17.10.7","matchCriteriaId":"6AA931D0-55A0-4DC9-9943-E8ACFB0423CF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.11.0","versionEndExcluding":"17.11.3","matchCriteriaId":"194F7832-AEB6-4CD4-8CA8-81D8BF1666C9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.11.0","versionEndExcluding":"17.11.3","matchCriteriaId":"85308EBB-8AB6-4344-9944-D124878DA138"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.0.0:*:*:*:community:*:*:*","matchCriteriaId":"C7F28C32-4C21-4EE4-985C-34BD8C9FE300"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"52187A72-1412-48DE-90DD-2948630CFC19"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/533313","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3045424","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-4979","sourceIdentifier":"cve@gitlab.com","published":"2025-05-22T14:16:08.617","lastModified":"2026-06-17T09:34:25.803","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. An attacker may be able to reveal masked or hidden CI variables (that they did not author) in the WebUI, by simply creating their own variable and observing the HTTP response."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones anteriores a la 17.10.7, 17.11 anteriores a la 17.11.3 y 18.0 anteriores a la 18.0.1. Un atacante podría revelar variables de CI ocultas o enmascaradas (que no son de su autoría) en la interfaz web, simplemente creando su propia variable y observando la respuesta HTTP."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"0","lessThan":"17.10.7","versionType":"semver","status":"affected"},{"version":"17.11","lessThan":"17.11.3","versionType":"semver","status":"affected"},{"version":"18.0","lessThan":"18.0.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-22T14:21:13.148571Z","id":"CVE-2025-4979","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1220"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"17.10.7","matchCriteriaId":"D134A1A8-5E9C-4252-B0AA-1684A76EC3B4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"17.10.7","matchCriteriaId":"8064E80E-002F-4809-A7DB-B50F7449C3E2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.11.0","versionEndExcluding":"17.11.3","matchCriteriaId":"194F7832-AEB6-4CD4-8CA8-81D8BF1666C9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.11.0","versionEndExcluding":"17.11.3","matchCriteriaId":"85308EBB-8AB6-4344-9944-D124878DA138"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.0.0:*:*:*:community:*:*:*","matchCriteriaId":"C7F28C32-4C21-4EE4-985C-34BD8C9FE300"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"52187A72-1412-48DE-90DD-2948630CFC19"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/524455","source":"cve@gitlab.com","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2024-12093","sourceIdentifier":"cve@gitlab.com","published":"2025-05-22T15:16:03.580","lastModified":"2026-06-17T06:59:02.260","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 11.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Improper XPath validation allows modified SAML response to bypass 2FA requirement under specialized conditions."},{"lang":"es","value":"Se ha detectado un problema en GitLab CE/EE que afecta a todas las versiones (desde la 11.1 hasta la 17.10.7), la 17.11 hasta la 17.11.3 y la 18.0 hasta la 18.0.1. Una validación XPath incorrecta permite que una respuesta SAML modificada omita el requisito de 2FA en condiciones especiales."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"11.1","lessThan":"17.10.7","versionType":"semver","status":"affected"},{"version":"17.11","lessThan":"17.11.3","versionType":"semver","status":"affected"},{"version":"18.0","lessThan":"18.0.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","baseScore":6.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-22T14:43:49.819950Z","id":"CVE-2024-12093","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1288"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.1.0","versionEndExcluding":"17.10.7","matchCriteriaId":"324A7EFC-5A8A-4BE6-BB02-E081AB4C0C35"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.1.0","versionEndExcluding":"17.10.7","matchCriteriaId":"0EC8F73E-AB7C-4129-B262-72E484D52F4B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.11.0","versionEndExcluding":"17.11.3","matchCriteriaId":"194F7832-AEB6-4CD4-8CA8-81D8BF1666C9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.11.0","versionEndExcluding":"17.11.3","matchCriteriaId":"85308EBB-8AB6-4344-9944-D124878DA138"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.0.0:*:*:*:community:*:*:*","matchCriteriaId":"C7F28C32-4C21-4EE4-985C-34BD8C9FE300"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"52187A72-1412-48DE-90DD-2948630CFC19"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/507445","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/2851261","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-0605","sourceIdentifier":"cve@gitlab.com","published":"2025-05-22T15:16:03.957","lastModified":"2026-06-17T08:26:47.773","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 16.8 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Group access controls could allow certain users to bypass two-factor authentication requirements."},{"lang":"es","value":"Se ha detectado un problema en GitLab CE/EE que afecta a todas las versiones (desde la 16.8 hasta la 17.10.7), la 17.11 hasta la 17.11.3 y la 18.0 hasta la 18.0.1. Los controles de acceso de grupo podrían permitir que ciertos usuarios eludan los requisitos de autenticación de dos factores."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.8","lessThan":"17.10.7","versionType":"semver","status":"affected"},{"version":"17.11","lessThan":"17.11.3","versionType":"semver","status":"affected"},{"version":"18.0","lessThan":"18.0.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N","baseScore":4.6,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":2.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-22T14:44:32.756358Z","id":"CVE-2025-0605","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1390"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-287"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.8.0","versionEndExcluding":"17.10.7","matchCriteriaId":"5AAFCE83-4468-462D-9014-C67C78B8EE15"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.8.0","versionEndExcluding":"17.10.7","matchCriteriaId":"02052723-DBF5-4937-AF54-5026E3299FB3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.11.0","versionEndExcluding":"17.11.3","matchCriteriaId":"194F7832-AEB6-4CD4-8CA8-81D8BF1666C9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.11.0","versionEndExcluding":"17.11.3","matchCriteriaId":"85308EBB-8AB6-4344-9944-D124878DA138"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.0.0:*:*:*:community:*:*:*","matchCriteriaId":"C7F28C32-4C21-4EE4-985C-34BD8C9FE300"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"52187A72-1412-48DE-90DD-2948630CFC19"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/514204","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2919391","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-0679","sourceIdentifier":"cve@gitlab.com","published":"2025-05-22T15:16:04.117","lastModified":"2026-06-17T08:26:57.313","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 17.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Under certain conditions un-authorised users can view full email addresses that should be partially obscured."},{"lang":"es","value":"Se ha detectado un problema en GitLab CE/EE que afecta a todas las versiones (desde la 17.1 hasta la 17.10.7), la 17.11 hasta la 17.11.3 y la 18.0 hasta la 18.0.1. En determinadas circunstancias, usuarios no autorizados pueden ver direcciones de correo electrónico completas que deberían estar parcialmente ocultas."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.1","lessThan":"17.10.7","versionType":"semver","status":"affected"},{"version":"17.11","lessThan":"17.11.3","versionType":"semver","status":"affected"},{"version":"18.0","lessThan":"18.0.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-22T14:45:46.695933Z","id":"CVE-2025-0679","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-359"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"17.10.7","matchCriteriaId":"F87C9997-D4E7-4099-9500-A243CE45C135"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"17.10.7","matchCriteriaId":"CFF9DBBD-8A64-4DCD-9290-DE203D380418"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.11.0","versionEndExcluding":"17.11.3","matchCriteriaId":"194F7832-AEB6-4CD4-8CA8-81D8BF1666C9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.11.0","versionEndExcluding":"17.11.3","matchCriteriaId":"85308EBB-8AB6-4344-9944-D124878DA138"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.0.0:*:*:*:community:*:*:*","matchCriteriaId":"C7F28C32-4C21-4EE4-985C-34BD8C9FE300"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"52187A72-1412-48DE-90DD-2948630CFC19"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/514751","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2952536","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-0993","sourceIdentifier":"cve@gitlab.com","published":"2025-05-22T15:16:04.273","lastModified":"2026-06-17T08:27:29.077","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. This could allow an authenticated attacker to cause a denial of service condition by exhausting server resources."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones anteriores a la 17.10.7, a la 17.11 anterior a la 17.11.3 y a la 18.0 anterior a la 18.0.1. Esto podría permitir que un atacante autenticado provoque una denegación de servicio al agotar los recursos del servidor."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"0","lessThan":"17.10.7","versionType":"semver","status":"affected"},{"version":"17.11","lessThan":"17.11.3","versionType":"semver","status":"affected"},{"version":"18.0","lessThan":"18.0.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-22T14:46:45.341653Z","id":"CVE-2025-0993","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"17.10.7","matchCriteriaId":"D134A1A8-5E9C-4252-B0AA-1684A76EC3B4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"17.10.7","matchCriteriaId":"8064E80E-002F-4809-A7DB-B50F7449C3E2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.11.0","versionEndExcluding":"17.11.3","matchCriteriaId":"194F7832-AEB6-4CD4-8CA8-81D8BF1666C9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.11.0","versionEndExcluding":"17.11.3","matchCriteriaId":"85308EBB-8AB6-4344-9944-D124878DA138"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.0.0:*:*:*:community:*:*:*","matchCriteriaId":"C7F28C32-4C21-4EE4-985C-34BD8C9FE300"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"52187A72-1412-48DE-90DD-2948630CFC19"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/516927","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2967771","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-7803","sourceIdentifier":"cve@gitlab.com","published":"2025-05-23T13:15:24.910","lastModified":"2026-06-17T08:20:56.793","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 11.6 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A Discord webhook integration may cause DoS."},{"lang":"es","value":"Se ha detectado un problema en GitLab CE/EE que afecta a todas las versiones (desde la 11.6 hasta la 17.10.7), la 17.11 hasta la 17.11.3 y la 18.0 hasta la 18.0.1. La integración de un webhook de Discord podría causar un ataque de denegación de servicio (DoS)."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"11.6","lessThan":"17.10.7","versionType":"semver","status":"affected"},{"version":"17.11","lessThan":"17.11.3","versionType":"semver","status":"affected"},{"version":"18.0","lessThan":"18.0.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-27T14:40:00.482188Z","id":"CVE-2024-7803","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"17.10.7","matchCriteriaId":"BD51055E-3B91-4A3E-BC49-ADDE020B4095"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"17.10.7","matchCriteriaId":"6DBCDD49-4959-4C72-8F6A-C81E0693E77A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.11.0","versionEndExcluding":"17.11.3","matchCriteriaId":"194F7832-AEB6-4CD4-8CA8-81D8BF1666C9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.11.0","versionEndExcluding":"17.11.3","matchCriteriaId":"85308EBB-8AB6-4344-9944-D124878DA138"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.0.0:*:*:*:community:*:*:*","matchCriteriaId":"C7F28C32-4C21-4EE4-985C-34BD8C9FE300"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"52187A72-1412-48DE-90DD-2948630CFC19"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/479168","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2648631","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-9163","sourceIdentifier":"cve@gitlab.com","published":"2025-05-23T13:15:25.530","lastModified":"2026-06-17T08:24:04.440","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A business logic error in GitLab CE/EE affecting all versions starting from 12.1 prior to 17.10.7, 17.11 prior to 17.11.3 and 18.0 prior to 18.0.1 where an attacker can cause a branch name confusion in confidential MRs."},{"lang":"es","value":"Un error de lógica empresarial en GitLab CE/EE que afecta a todas las versiones a partir de la 12.1 anterior a la 17.10.7, la 17.11 anterior a la 17.11.3 y la 18.0 anterior a la 18.0.1, donde un atacante puede causar una confusión en el nombre de la rama en los MR confidenciales."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"12.1","lessThan":"17.10.7","versionType":"semver","status":"affected"},{"version":"17.11","lessThan":"17.11.3","versionType":"semver","status":"affected"},{"version":"18.0","lessThan":"18.0.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N","baseScore":3.5,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-27T14:40:27.765884Z","id":"CVE-2024-9163","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-451"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"17.10.7","matchCriteriaId":"FB6AA970-04FE-48CF-8BBB-F7C9546A7FA8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.1.0","versionEndExcluding":"17.10.7","matchCriteriaId":"11B00073-6474-41F1-AFC5-9E8190CA09DA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.11.0","versionEndExcluding":"17.11.3","matchCriteriaId":"194F7832-AEB6-4CD4-8CA8-81D8BF1666C9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.11.0","versionEndExcluding":"17.11.3","matchCriteriaId":"85308EBB-8AB6-4344-9944-D124878DA138"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.0.0:*:*:*:community:*:*:*","matchCriteriaId":"C7F28C32-4C21-4EE4-985C-34BD8C9FE300"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"52187A72-1412-48DE-90DD-2948630CFC19"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/493942","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2705566","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-1763","sourceIdentifier":"cve@gitlab.com","published":"2025-05-30T11:15:20.213","lastModified":"2026-06-17T08:39:44.163","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE that allows for cross-site-scripting attack and content security policy bypass in a user's browser under specific conditions, affecting all versions from 16.6 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1."},{"lang":"es","value":"Se ha descubierto un problema en GitLab EE que permite ataques de cross-site-scripting y eludir la política de seguridad de contenido en el navegador de un usuario en condiciones específicas, lo que afecta a todas las versiones desde la 16.6 hasta la 17.9.7, la 17.10 hasta la 17.10.5 y la 17.11 hasta la 17.11.1."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.6","lessThan":"17.9.7","versionType":"semver","status":"affected"},{"version":"17.10","lessThan":"17.10.5","versionType":"semver","status":"affected"},{"version":"17.11","lessThan":"17.11.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":5.8}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-30T12:50:03.389990Z","id":"CVE-2025-1763","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.6.0","versionEndExcluding":"17.9.7","matchCriteriaId":"24E20FB2-2D62-44D3-B33F-041B393073DC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.6.0","versionEndExcluding":"17.9.7","matchCriteriaId":"9B9C18BF-5C6B-4F81-9F0E-13C61C98D4D9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.10.0","versionEndExcluding":"17.10.5","matchCriteriaId":"C81D345F-13AE-4508-B4C6-60E361EADC00"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.10.0","versionEndExcluding":"17.10.5","matchCriteriaId":"CA1D8D06-9A39-43E9-A638-5C82A59C00B4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.11.0:*:*:*:community:*:*:*","matchCriteriaId":"DC849E49-FBCD-4F20-BCFA-E28BC7FF640F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.11.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"D30C941F-4464-4E1A-AA49-624F451A9A4E"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/521718","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/3016600","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-1478","sourceIdentifier":"cve@gitlab.com","published":"2025-06-12T10:16:28.033","lastModified":"2026-06-17T08:39:13.600","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 8.13 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of input validation in Board Names could be used to trigger a denial of service."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones (desde la 8.13 hasta la 17.10.7), la 17.11 hasta la 17.11.3 y la 18.0 hasta la 18.0.1. La falta de validación de entrada en los nombres de los foros podría utilizarse para desencadenar una denegación de servicio."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"8.13","lessThan":"17.10.8","versionType":"semver","status":"affected"},{"version":"17.11","lessThan":"17.11.4","versionType":"semver","status":"affected"},{"version":"18.0","lessThan":"18.0.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-06-12T13:28:26.807319Z","id":"CVE-2025-1478","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.13.0","versionEndExcluding":"17.10.7","matchCriteriaId":"FF75FCAB-85C6-4136-A0FE-B1431C44FCE7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.13.0","versionEndExcluding":"17.10.7","matchCriteriaId":"486EB975-2DD8-41E5-AE6C-B7D2C6008374"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.11.0","versionEndExcluding":"17.11.3","matchCriteriaId":"194F7832-AEB6-4CD4-8CA8-81D8BF1666C9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.11.0","versionEndExcluding":"17.11.3","matchCriteriaId":"85308EBB-8AB6-4344-9944-D124878DA138"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.0.0:*:*:*:community:*:*:*","matchCriteriaId":"C7F28C32-4C21-4EE4-985C-34BD8C9FE300"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"52187A72-1412-48DE-90DD-2948630CFC19"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/520354","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2987444","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-1516","sourceIdentifier":"cve@gitlab.com","published":"2025-06-12T10:16:38.260","lastModified":"2026-06-17T08:39:17.573","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 8.7 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. Improper input validation in Tokens Names could be used to trigger a denial of service."},{"lang":"es","value":"Se ha detectado un problema en GitLab CE/EE que afecta a todas las versiones (desde la 8.7 hasta la 17.10.8), la 17.11 hasta la 17.11.4 y la 18.0 hasta la 18.0.2. Una validación de entrada incorrecta en los nombres de tokens podría provocar una denegación de servicio."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"8.7","lessThan":"17.10.8","versionType":"semver","status":"affected"},{"version":"17.11","lessThan":"17.11.4","versionType":"semver","status":"affected"},{"version":"18.0","lessThan":"18.0.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-06-12T13:37:46.047033Z","id":"CVE-2025-1516","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.7.0","versionEndExcluding":"17.10.8","matchCriteriaId":"1E694D6D-982F-4EA9-9172-8C8F6E3A87F6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.7.0","versionEndExcluding":"17.10.8","matchCriteriaId":"F60540E3-F5A2-4940-B909-9596634BBA70"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.11.0","versionEndExcluding":"17.11.4","matchCriteriaId":"C804F9B0-8B23-4160-B24E-199411A81B95"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.11.0","versionEndExcluding":"17.11.4","matchCriteriaId":"CEAA838C-7B3C-45AF-9D3D-BD5DE41E57BC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.0.0","versionEndExcluding":"18.0.2","matchCriteriaId":"7BD21B25-753E-48AB-B0D4-DFE90A135C04"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.0.0","versionEndExcluding":"18.0.2","matchCriteriaId":"6224AE70-D146-4A3B-BD4E-2853891F24FA"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/520553","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2991435","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-2254","sourceIdentifier":"cve@gitlab.com","published":"2025-06-12T10:16:38.747","lastModified":"2026-06-17T09:06:38.150","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. Improper output encoding in the snipper viewer functionality lead to Cross-Site scripting attacks."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones (desde la 17.9 hasta la 17.10.8), la 17.11 hasta la 17.11.4 y la 18.0 hasta la 18.0.2. La codificación incorrecta de la salida en el visor de fragmentos provoca ataques de cross-site scripting."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.9","lessThan":"17.10.8","versionType":"semver","status":"affected"},{"version":"17.11","lessThan":"17.11.4","versionType":"semver","status":"affected"},{"version":"18.0","lessThan":"18.0.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-06-12T13:38:28.989165Z","id":"CVE-2025-2254","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.9.0","versionEndExcluding":"17.10.8","matchCriteriaId":"3D9817AE-98CB-4B27-88CC-8C5729614848"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.9.0","versionEndExcluding":"17.10.8","matchCriteriaId":"51B3CD0D-781F-4B27-9963-F01EE244B455"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.11.0","versionEndExcluding":"17.11.4","matchCriteriaId":"C804F9B0-8B23-4160-B24E-199411A81B95"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.11.0","versionEndExcluding":"17.11.4","matchCriteriaId":"CEAA838C-7B3C-45AF-9D3D-BD5DE41E57BC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.0.0","versionEndExcluding":"18.0.2","matchCriteriaId":"7BD21B25-753E-48AB-B0D4-DFE90A135C04"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.0.0","versionEndExcluding":"18.0.2","matchCriteriaId":"6224AE70-D146-4A3B-BD4E-2853891F24FA"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/524636","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2973939","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-4278","sourceIdentifier":"cve@gitlab.com","published":"2025-06-12T10:16:39.200","lastModified":"2026-06-17T09:32:55.690","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting with 18.0 before 18.0.2. Under certain conditions html injection in new search page could lead to account takeover."},{"lang":"es","value":"Se ha detectado un problema en GitLab CE/EE que afecta a todas las versiones a partir de la 18.0 y anteriores a la 18.0.2. En determinadas circunstancias, la inyección de HTML en una nueva página de búsqueda podría provocar el robo de cuentas."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.0","lessThan":"18.0.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":5.8}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-06-12T13:43:03.990067Z","id":"CVE-2025-4278","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-80"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.0.0","versionEndExcluding":"18.0.2","matchCriteriaId":"7BD21B25-753E-48AB-B0D4-DFE90A135C04"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.0.0","versionEndExcluding":"18.0.2","matchCriteriaId":"6224AE70-D146-4A3B-BD4E-2853891F24FA"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/539198","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3085738","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-5996","sourceIdentifier":"cve@gitlab.com","published":"2025-06-12T10:16:39.640","lastModified":"2026-06-17T09:49:10.693","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 2.1.0 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. A lack of input validation in HTTP responses could allow an authenticated user to cause denial of service."},{"lang":"es","value":"Se ha detectado un problema en GitLab CE/EE que afecta a todas las versiones (desde la 2.1.0 hasta la 17.10.8), la 17.11 hasta la 17.11.4 y la 18.0 hasta la 18.0.2. La falta de validación de entrada en las respuestas HTTP podría permitir que un usuario autenticado provoque una denegación de servicio."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"2.10","lessThan":"17.10.7","versionType":"semver","status":"affected"},{"version":"17.11","lessThan":"17.11.3","versionType":"semver","status":"affected"},{"version":"18.0","lessThan":"18.0.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-06-12T13:50:25.240569Z","id":"CVE-2025-5996","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"2.1.0","versionEndExcluding":"17.10.8","matchCriteriaId":"EF65A84E-4A4D-4899-84AB-8AF461C056A0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"2.1.0","versionEndExcluding":"17.10.8","matchCriteriaId":"8A2D500A-7DFA-4245-BDEE-90D3F17B4D0F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.11.0","versionEndExcluding":"17.11.4","matchCriteriaId":"C804F9B0-8B23-4160-B24E-199411A81B95"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.11.0","versionEndExcluding":"17.11.4","matchCriteriaId":"CEAA838C-7B3C-45AF-9D3D-BD5DE41E57BC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.0.0","versionEndExcluding":"18.0.2","matchCriteriaId":"7BD21B25-753E-48AB-B0D4-DFE90A135C04"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.0.0","versionEndExcluding":"18.0.2","matchCriteriaId":"6224AE70-D146-4A3B-BD4E-2853891F24FA"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/476671","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/479167","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/483111","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/483150","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/498649","source":"cve@gitlab.com","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2025-0673","sourceIdentifier":"cve@gitlab.com","published":"2025-06-12T11:15:18.700","lastModified":"2026-06-17T08:26:56.623","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2, allow an attacker to trigger an infinite redirect loop, potentially leading to a denial of service condition."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde la 17.7 hasta la 17.10.8, la 17.11 hasta la 17.11.4 y la 18.0 hasta la 18.0.2, que permite a un atacante activar un bucle de redirección infinito, lo que puede derivar en una condición de denegación de servicio."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.7","lessThan":"17.10.8","versionType":"semver","status":"affected"},{"version":"17.11","lessThan":"17.11.4","versionType":"semver","status":"affected"},{"version":"18.0","lessThan":"18.0.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-06-12T13:15:44.746004Z","id":"CVE-2025-0673","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-835"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.7.0","versionEndExcluding":"17.10.8","matchCriteriaId":"B30D7168-F8CC-4E7D-AF68-A7596FAD8FD6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.7.0","versionEndExcluding":"17.10.8","matchCriteriaId":"354BF446-A3F8-4B32-92B1-0943C3858BE9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.11.0","versionEndExcluding":"17.11.4","matchCriteriaId":"C804F9B0-8B23-4160-B24E-199411A81B95"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.11.0","versionEndExcluding":"17.11.4","matchCriteriaId":"CEAA838C-7B3C-45AF-9D3D-BD5DE41E57BC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.0.0","versionEndExcluding":"18.0.2","matchCriteriaId":"7BD21B25-753E-48AB-B0D4-DFE90A135C04"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.0.0","versionEndExcluding":"18.0.2","matchCriteriaId":"6224AE70-D146-4A3B-BD4E-2853891F24FA"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/514732","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/2936949","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-5195","sourceIdentifier":"cve@gitlab.com","published":"2025-06-12T11:15:19.647","lastModified":"2026-06-17T09:47:25.677","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. It was possible for authenticated users to access arbitrary compliance frameworks, leading to unauthorized data disclosure."},{"lang":"es","value":"Se ha detectado un problema en GitLab CE/EE que afecta a todas las versiones (desde la 17.9 hasta la 17.10.7), la 17.11 hasta la 17.11.3 y la 18.0 hasta la 18.0.1. Los usuarios autenticados podían acceder a frameworks de cumplimiento arbitrarios, lo que provocaba la divulgación no autorizada de datos."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.9","lessThan":"17.10.8","versionType":"semver","status":"affected"},{"version":"17.11","lessThan":"17.11.4","versionType":"semver","status":"affected"},{"version":"18.0","lessThan":"18.0.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-06-12T13:22:10.914910Z","id":"CVE-2025-5195","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-639"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.9.0","versionEndExcluding":"17.10.7","matchCriteriaId":"C7A341DC-6679-4B9F-87FC-18CE5ACB0E44"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.9.0","versionEndExcluding":"17.10.7","matchCriteriaId":"FE404772-0AE4-43C4-87A0-2486808CD6F9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.11.0","versionEndExcluding":"17.11.3","matchCriteriaId":"194F7832-AEB6-4CD4-8CA8-81D8BF1666C9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.11.0","versionEndExcluding":"17.11.3","matchCriteriaId":"85308EBB-8AB6-4344-9944-D124878DA138"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.0.0:*:*:*:community:*:*:*","matchCriteriaId":"C7F28C32-4C21-4EE4-985C-34BD8C9FE300"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"52187A72-1412-48DE-90DD-2948630CFC19"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/534960","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]}]}},{"cve":{"id":"CVE-2024-9512","sourceIdentifier":"cve@gitlab.com","published":"2025-06-12T14:15:29.680","lastModified":"2026-06-17T08:24:42.723","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions prior to 17.10.8, 17.11 prior to 17.11.4, and 18.0 prior to 18.0.2. It may have been possible for private repository to be cloned in case of race condition when a secondary node is out of sync."},{"lang":"es","value":"Se ha detectado un problema en GitLab EE que afecta a todas las versiones anteriores a la 17.10.8, 17.11 anteriores a la 17.11.4 y 18.0 anteriores a la 18.0.2. Es posible que se haya clonado un repositorio privado en caso de una condición de ejecución cuando un nodo secundario no está sincronizado."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"0","lessThan":"17.10.8","versionType":"semver","status":"affected"},{"version":"17.11","lessThan":"17.11.4","versionType":"semver","status":"affected"},{"version":"18.0","lessThan":"18.0.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-06-12T14:12:49.948999Z","id":"CVE-2024-9512","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-367"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"17.10.8","matchCriteriaId":"61E74077-8E03-45E9-B5C0-50D1C5706D29"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"17.10.8","matchCriteriaId":"AE1C02F8-A03B-4647-8FA2-5C297D86BE26"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.11.0","versionEndExcluding":"17.11.4","matchCriteriaId":"C804F9B0-8B23-4160-B24E-199411A81B95"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.11.0","versionEndExcluding":"17.11.4","matchCriteriaId":"CEAA838C-7B3C-45AF-9D3D-BD5DE41E57BC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.0.0","versionEndExcluding":"18.0.2","matchCriteriaId":"7BD21B25-753E-48AB-B0D4-DFE90A135C04"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.0.0","versionEndExcluding":"18.0.2","matchCriteriaId":"6224AE70-D146-4A3B-BD4E-2853891F24FA"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/497748","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2683469","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-5982","sourceIdentifier":"cve@gitlab.com","published":"2025-06-12T17:15:29.440","lastModified":"2026-06-17T09:49:09.047","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions from 12.0 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. Under certain conditions users could bypass IP access restrictions and view sensitive information."},{"lang":"es","value":"Se ha detectado un problema en GitLab EE que afecta a todas las versiones, desde la 12.0 hasta la 17.10.8, la 17.11 hasta la 17.11.4 y la 18.0 hasta la 18.0.2. En determinadas circunstancias, los usuarios podían eludir las restricciones de acceso IP y acceder a información confidencial."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"12.0","lessThan":"17.10.8","versionType":"semver","status":"affected"},{"version":"17.11","lessThan":"17.11.4","versionType":"semver","status":"affected"},{"version":"18.0","lessThan":"18.0.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":3.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-06-12T17:27:31.493512Z","id":"CVE-2025-5982","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1220"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.0.0","versionEndExcluding":"17.10.8","matchCriteriaId":"52E2D1AE-40F8-456D-80B4-46CCF7FC6A3B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.11.0","versionEndExcluding":"17.11.4","matchCriteriaId":"CEAA838C-7B3C-45AF-9D3D-BD5DE41E57BC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.0.0","versionEndExcluding":"18.0.2","matchCriteriaId":"6224AE70-D146-4A3B-BD4E-2853891F24FA"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/514456","source":"cve@gitlab.com","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2024-7586","sourceIdentifier":"cve@gitlab.com","published":"2025-06-20T14:15:26.983","lastModified":"2026-06-17T08:20:29.970","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab EE affecting all versions starting from 17.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2, where webhook deletion audit log preserved auth credentials."},{"lang":"es","value":"Se descubrió un problema en GitLab EE que afecta a todas las versiones desde la 17.0 anterior a la 17.0.6, desde la 17.1 anterior a la 17.1.4 y desde la 17.2 anterior a la 17.2.2, donde el registro de auditoría de eliminación de webhook conservaba las credenciales de autenticación."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.0","lessThan":"17.0.6","versionType":"semver","status":"affected"},{"version":"17.1","lessThan":"17.1.4","versionType":"semver","status":"affected"},{"version":"17.2","lessThan":"17.2.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N","baseScore":4.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-06-20T14:52:57.204671Z","id":"CVE-2024-7586","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-532"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"17.0.6","matchCriteriaId":"D855EA28-704A-46C0-97D4-DC4C42D00AAF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"17.0.6","matchCriteriaId":"548D76DB-334D-4571-84B6-79D0EBAAC0AF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"17.1.4","matchCriteriaId":"6CA14692-9997-4A11-8B3D-29199A3498D4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"17.1.4","matchCriteriaId":"39754D78-BBE0-41D9-B2AB-5402B32C8ECF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.2","matchCriteriaId":"153C136B-FF14-43EC-AE67-68273DF7D9ED"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.2.2","matchCriteriaId":"2BE7EFA9-D9B4-4E7E-81B2-597D3DC5756E"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/463866","source":"cve@gitlab.com","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2025-2443","sourceIdentifier":"cve@gitlab.com","published":"2025-06-20T18:15:28.270","lastModified":"2026-06-17T09:07:00.353","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE that allows for cross-site-scripting attack and content security policy bypass in a user's browser under specific conditions, affecting all versions from 16.6 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1."},{"lang":"es","value":"Se ha descubierto un problema en GitLab EE que permite ataques de Cross-Site Scripting y eludir la política de seguridad de contenido en el navegador de un usuario en condiciones específicas, lo que afecta a todas las versiones desde la 16.6 hasta la 17.9.7, la 17.10 hasta la 17.10.5 y la 17.11 hasta la 17.11.1."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.6","lessThan":"17.9.7","versionType":"semver","status":"affected"},{"version":"17.10","lessThan":"17.10.5","versionType":"semver","status":"affected"},{"version":"17.11","lessThan":"17.11.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-06-20T17:27:10.978071Z","id":"CVE-2025-2443","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.6.0","versionEndExcluding":"17.9.7","matchCriteriaId":"9B9C18BF-5C6B-4F81-9F0E-13C61C98D4D9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.10.0","versionEndExcluding":"17.10.5","matchCriteriaId":"CA1D8D06-9A39-43E9-A638-5C82A59C00B4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.11.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"D30C941F-4464-4E1A-AA49-624F451A9A4E"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/525363","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3037340","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-5121","sourceIdentifier":"cve@gitlab.com","published":"2025-06-20T18:15:28.913","lastModified":"2026-06-17T09:47:14.147","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 17.11 before 17.11.4 and 18.0 before 18.0.2. A missing authorization check may have allowed compliance frameworks to be applied to projects outside the compliance framework's group."},{"lang":"es","value":"Se ha detectado un problema en GitLab CE/EE que afecta a todas las versiones, desde la 17.11 hasta la 17.11.4 y desde la 18.0 hasta la 18.0.2. La falta de una comprobación de autorización podría haber permitido la aplicación de frameworks de cumplimiento a proyectos fuera del grupo del framework de cumplimiento."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.11","lessThan":"17.11.4","versionType":"semver","status":"affected"},{"version":"18.0","lessThan":"18.0.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":8.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":6.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":9.9,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.1,"impactScore":6.0}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-06-20T17:29:24.611488Z","id":"CVE-2025-5121","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.11.0","versionEndExcluding":"17.11.4","matchCriteriaId":"C804F9B0-8B23-4160-B24E-199411A81B95"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.11.0","versionEndExcluding":"17.11.4","matchCriteriaId":"CEAA838C-7B3C-45AF-9D3D-BD5DE41E57BC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.0.0","versionEndExcluding":"18.0.2","matchCriteriaId":"7BD21B25-753E-48AB-B0D4-DFE90A135C04"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.0.0","versionEndExcluding":"18.0.2","matchCriteriaId":"6224AE70-D146-4A3B-BD4E-2853891F24FA"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/545429","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3153908","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-4025","sourceIdentifier":"cve@gitlab.com","published":"2025-06-20T19:15:35.290","lastModified":"2026-06-17T08:00:57.607","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions from 7.10 prior before 16.11.5, version 17.0 before 17.0.3, and 17.1 before 17.1.1. It is possible for an attacker to cause a denial of service using a crafted markdown page."},{"lang":"es","value":"Se ha detectado una condición de denegación de servicio (DoS) en GitLab CE/EE que afecta a todas las versiones desde la 7.10 hasta la 16.11.5, la 17.0 hasta la 17.0.3 y la 17.1 hasta la 17.1.1. Un atacante podría provocar una denegación de servicio mediante una página de Markdown manipulada."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"7.10","lessThan":"16.11.5","versionType":"semver","status":"affected"},{"version":"17.0","lessThan":"17.0.3","versionType":"semver","status":"affected"},{"version":"17.1","lessThan":"17.1.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-06-23T15:22:52.164817Z","id":"CVE-2024-4025","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1333"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"7.10.0","versionEndExcluding":"16.11.5","matchCriteriaId":"9E695D9E-834B-4028-968B-826A63C05433"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"7.10.0","versionEndExcluding":"16.11.5","matchCriteriaId":"F23667D9-3A57-4E4D-9416-A08FEA9C5C4D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"17.0.3","matchCriteriaId":"541958DE-CB05-43D9-921B-4ADD2E436BF7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"17.0.3","matchCriteriaId":"C987EC42-A56B-462A-A0CE-7417CC0FD414"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.1.0:*:*:*:community:*:*:*","matchCriteriaId":"D2461A15-EA5F-43D1-B359-0F24713A713B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"9AA7835D-35E6-44D6-9194-2AC4C38961CE"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/457474","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2024974","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-4994","sourceIdentifier":"cve@gitlab.com","published":"2025-06-20T19:15:35.460","lastModified":"2026-06-17T08:03:20.743","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 16.1.0 before 16.11.5, all versions starting from 17.0 before 17.0.3, all versions starting from 17.1.0 before 17.1.1 which allowed for a CSRF attack on GitLab's GraphQL API leading to the execution of arbitrary GraphQL mutations."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde la 16.1.0 anterior a la 16.11.5, todas las versiones desde la 17.0 anterior a la 17.0.3 y todas las versiones desde la 17.1.0 anterior a la 17.1.1, lo que permitió un ataque CSRF a la API GraphQL de GitLab que provocó la ejecución de mutaciones arbitrarias de GraphQL."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.1","lessThan":"16.11.5","versionType":"semver","status":"affected"},{"version":"17.0.0","lessThan":"17.0.3","versionType":"semver","status":"affected"},{"version":"17.1.0","lessThan":"17.1.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-06-23T15:22:30.992339Z","id":"CVE-2024-4994","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-352"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.1.0","versionEndExcluding":"16.11.5","matchCriteriaId":"8467259D-8274-43C7-AF90-8036AACC1B0C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.1.0","versionEndExcluding":"16.11.5","matchCriteriaId":"64A0D7B6-27D3-4E5C-83ED-C72FBB84B5D5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"17.0.3","matchCriteriaId":"541958DE-CB05-43D9-921B-4ADD2E436BF7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"17.0.3","matchCriteriaId":"C987EC42-A56B-462A-A0CE-7417CC0FD414"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.1.0:*:*:*:community:*:*:*","matchCriteriaId":"D2461A15-EA5F-43D1-B359-0F24713A713B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"9AA7835D-35E6-44D6-9194-2AC4C38961CE"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/462012","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/2473644","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2023-5600","sourceIdentifier":"cve@gitlab.com","published":"2025-06-20T20:15:26.860","lastModified":"2026-06-17T06:48:55.283","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions starting from 16.0 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. Arbitrary access to the titles of an private specific references could be leaked through the service-desk custom email template."},{"lang":"es","value":"Se ha detectado un problema en GitLab EE que afecta a todas las versiones (desde la 16.0 hasta la 16.3.6), a todas las versiones (desde la 16.4 hasta la 16.4.2) y a todas las versiones (desde la 16.5 hasta la 16.5.1). El acceso arbitrario a los títulos de referencias privadas específicas podría filtrarse a través de la plantilla de correo electrónico personalizada del servicio de asistencia."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.0","lessThan":"16.3.6","versionType":"semver","status":"affected"},{"version":"16.4","lessThan":"16.4.2","versionType":"semver","status":"affected"},{"version":"16.5","lessThan":"16.5.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":3.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-06-20T19:51:52.159951Z","id":"CVE-2023-5600","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"16.3.6","matchCriteriaId":"D460B5B4-689D-46C2-ADCE-EB1220EAC0D1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.4.0","versionEndExcluding":"16.4.2","matchCriteriaId":"F67E4E44-65EA-494F-B1FA-D080F53329AD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.5.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"A7286C51-077E-4093-9AF9-66CEE22915AA"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/428268","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/2209702","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-1754","sourceIdentifier":"cve@gitlab.com","published":"2025-06-26T06:15:22.570","lastModified":"2026-06-17T08:39:43.167","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed unauthenticated attackers to upload arbitrary files to public projects by sending crafted API requests, potentially leading to resource abuse and unauthorized content storage."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde la 17.2 hasta la 17.11.5, la 18.0 hasta la 18.0.3 y la 18.1 hasta la 18.1.1 que podría haber permitido a atacantes no autenticados cargar archivos arbitrarios en proyectos públicos mediante el envío de solicitudes de API manipuladas, lo que podría provocar un abuso de recursos y un almacenamiento de contenido no autorizado."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.2","lessThan":"17.11.5","versionType":"semver","status":"affected"},{"version":"18.0","lessThan":"18.0.3","versionType":"semver","status":"affected"},{"version":"18.1","lessThan":"18.1.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-06-26T13:19:36.958100Z","id":"CVE-2025-1754","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-306"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.11.5","matchCriteriaId":"E561C0D3-12B9-432E-9FAC-4C7B7D5EEC38"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.11.5","matchCriteriaId":"61CA81F1-7FD4-4616-84FA-F23243CDB4C8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.0.0","versionEndExcluding":"18.0.3","matchCriteriaId":"12A2A86E-8DD7-482C-8CAD-191E0E5C635D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.0.0","versionEndExcluding":"18.0.3","matchCriteriaId":"912DFFB2-0D98-4506-AEB6-2AC3C2330554"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.1.0:*:*:*:community:*:*:*","matchCriteriaId":"792C874D-21C4-4715-95B8-489B65F7AE0D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"1FA1F1D0-87EA-44A6-AFB7-267BB21A7412"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/521619","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3009067","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-2938","sourceIdentifier":"cve@gitlab.com","published":"2025-06-26T06:15:22.980","lastModified":"2026-06-17T09:07:53.213","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated users to gain elevated project privileges by requesting access to projects where role modifications during the approval process resulted in unintended permission grants."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde la 17.3 hasta la 17.11.5, la 18.0 hasta la 18.0.3 y la 18.1 hasta la 18.1.1 que podría haber permitido que usuarios autenticados obtuvieran privilegios elevados de proyecto al solicitar acceso a proyectos en los que las modificaciones de roles durante el proceso de aprobación dieron como resultado concesiones de permisos no deseadas."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.3","lessThan":"17.11.5","versionType":"semver","status":"affected"},{"version":"18.0","lessThan":"18.0.3","versionType":"semver","status":"affected"},{"version":"18.1","lessThan":"18.1.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":3.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-06-27T03:55:22.451517Z","id":"CVE-2025-2938","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-840"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.11.5","matchCriteriaId":"02334DAC-25B3-4E5C-B59F-D9F1DB409F9A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.3.0","versionEndExcluding":"17.11.5","matchCriteriaId":"B367ACC4-64FB-488C-B0D8-82D427DF0D50"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.0.0","versionEndExcluding":"18.0.3","matchCriteriaId":"12A2A86E-8DD7-482C-8CAD-191E0E5C635D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.0.0","versionEndExcluding":"18.0.3","matchCriteriaId":"912DFFB2-0D98-4506-AEB6-2AC3C2330554"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.1.0:*:*:*:community:*:*:*","matchCriteriaId":"792C874D-21C4-4715-95B8-489B65F7AE0D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"1FA1F1D0-87EA-44A6-AFB7-267BB21A7412"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/529006","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3063091","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-3279","sourceIdentifier":"cve@gitlab.com","published":"2025-06-26T06:15:23.307","lastModified":"2026-06-17T09:19:34.200","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 10.7 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated attackers to create a DoS condition by sending crafted GraphQL requests."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde la 10.7 hasta la 17.11.5, la 18.0 hasta la 18.0.3 y la 18.1 hasta la 18.1.1 que podría haber permitido a atacantes autenticados crear una condición de denegación de servicio mediante el envío de solicitudes GraphQL manipuladas."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"10.7","lessThan":"17.11.5","versionType":"semver","status":"affected"},{"version":"18.0","lessThan":"18.0.3","versionType":"semver","status":"affected"},{"version":"18.1","lessThan":"18.1.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-06-26T13:22:25.220242Z","id":"CVE-2025-3279","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.7.0","versionEndExcluding":"17.11.5","matchCriteriaId":"23A378E8-473E-4F2E-AD47-E88D4BBF883C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.7.0","versionEndExcluding":"17.11.5","matchCriteriaId":"DEFFB3F4-657A-4080-80BD-947025AD6DDF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.0.0","versionEndExcluding":"18.0.3","matchCriteriaId":"12A2A86E-8DD7-482C-8CAD-191E0E5C635D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.0.0","versionEndExcluding":"18.0.3","matchCriteriaId":"912DFFB2-0D98-4506-AEB6-2AC3C2330554"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.1.0:*:*:*:community:*:*:*","matchCriteriaId":"792C874D-21C4-4715-95B8-489B65F7AE0D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"1FA1F1D0-87EA-44A6-AFB7-267BB21A7412"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/534424","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3067111","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-5315","sourceIdentifier":"cve@gitlab.com","published":"2025-06-26T06:15:23.873","lastModified":"2026-06-17T09:47:39.780","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated users with Guest role permissions to add child items to incident work items by sending crafted API requests that bypassed UI-enforced role restrictions."},{"lang":"es","value":"Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde la 17.2 hasta la 17.11.5, la 18.0 hasta la 18.0.3 y la 18.1 hasta la 18.1.1 que podría haber permitido a los usuarios autenticados con permisos de rol de Invitado agregar elementos secundarios a los elementos de trabajo del incidente mediante el envío de solicitudes de API manipuladas que eludían las restricciones de rol impuestas por la interfaz de usuario."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.2","lessThan":"17.11.5","versionType":"semver","status":"affected"},{"version":"18.0","lessThan":"18.0.3","versionType":"semver","status":"affected"},{"version":"18.1","lessThan":"18.1.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-06-26T13:22:37.271723Z","id":"CVE-2025-5315","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.11.5","matchCriteriaId":"E561C0D3-12B9-432E-9FAC-4C7B7D5EEC38"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"17.11.5","matchCriteriaId":"61CA81F1-7FD4-4616-84FA-F23243CDB4C8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.0.0","versionEndExcluding":"18.0.3","matchCriteriaId":"12A2A86E-8DD7-482C-8CAD-191E0E5C635D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.0.0","versionEndExcluding":"18.0.3","matchCriteriaId":"912DFFB2-0D98-4506-AEB6-2AC3C2330554"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.1.0:*:*:*:community:*:*:*","matchCriteriaId":"792C874D-21C4-4715-95B8-489B65F7AE0D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"1FA1F1D0-87EA-44A6-AFB7-267BB21A7412"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/546282","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3163037","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-5846","sourceIdentifier":"cve@gitlab.com","published":"2025-06-26T06:15:24.030","lastModified":"2026-06-17T09:48:51.877","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions from 16.10 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated users to assign unrelated compliance frameworks to projects by sending crafted GraphQL mutations that bypassed framework-specific permission checks."},{"lang":"es","value":"Se ha descubierto un problema en GitLab EE que afecta a todas las versiones desde la 16.10 hasta la 17.11.5, la 18.0 hasta la 18.0.3 y la 18.1 hasta la 18.1.1 que podría haber permitido a los usuarios autenticados asignar frameworks de cumplimiento no relacionados a los proyectos mediante el envío de mutaciones GraphQL manipuladas que eludían los controles de permisos específicos del framework."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.10","lessThan":"17.11.5","versionType":"semver","status":"affected"},{"version":"18.0","lessThan":"18.0.3","versionType":"semver","status":"affected"},{"version":"18.1","lessThan":"18.1.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N","baseScore":2.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-06-26T13:22:54.557423Z","id":"CVE-2025-5846","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.10.0","versionEndExcluding":"17.11.5","matchCriteriaId":"07AEA00E-F0F2-4E5A-97A5-9AD0ECB732F0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.0.0","versionEndExcluding":"18.0.3","matchCriteriaId":"912DFFB2-0D98-4506-AEB6-2AC3C2330554"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"1FA1F1D0-87EA-44A6-AFB7-267BB21A7412"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/546435","source":"cve@gitlab.com","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2025-3396","sourceIdentifier":"cve@gitlab.com","published":"2025-07-10T09:15:29.980","lastModified":"2026-06-17T09:19:52.543","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions from 13.3 before 17.11.6, 18.0 before 18.0.4, and 18.1 before 18.1.2 that could have allowed authenticated project owners to bypass group-level forking restrictions by manipulating API requests."},{"lang":"es","value":"Se ha descubierto un problema en GitLab EE que afecta a todas las versiones desde la 13.3 hasta la 17.11.6, la 18.0 hasta la 18.0.4 y la 18.1 hasta la 18.1.2 que podría haber permitido a los propietarios de proyectos autenticados eludir las restricciones de bifurcación a nivel de grupo manipulando las solicitudes de API."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"13.3","lessThan":"17.11.6","versionType":"semver","status":"affected"},{"version":"18.0","lessThan":"18.0.4","versionType":"semver","status":"affected"},{"version":"18.1","lessThan":"18.1.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-07-10T20:11:33.179611Z","id":"CVE-2025-3396","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.3.0","versionEndExcluding":"17.11.6","matchCriteriaId":"82BBA6B0-370A-4213-9916-753AAA1D155E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.0.0","versionEndExcluding":"18.0.4","matchCriteriaId":"4F27FCAE-C2B3-489C-AEDB-BA19DD32DE7A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.1.0","versionEndExcluding":"18.1.2","matchCriteriaId":"163718AE-806A-4D9C-ADA1-30FBFA87C317"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/534636","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3079956","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-4972","sourceIdentifier":"cve@gitlab.com","published":"2025-07-10T09:15:30.180","lastModified":"2026-06-17T09:34:25.050","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions from 18.0 before 18.0.4 and 18.1 before 18.1.2 that could have allowed authenticated users with invitation privileges to bypass group-level user invitation restrictions by manipulating group invitation functionality."},{"lang":"es","value":"Se ha descubierto un problema en GitLab EE que afecta a todas las versiones desde la 18.0 anterior a la 18.0.4 y desde la 18.1 anterior a la 18.1.2 que podría haber permitido a usuarios autenticados con privilegios de invitación eludir las restricciones de invitación de usuarios a nivel de grupo manipulando la funcionalidad de invitación de grupo."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.0","lessThan":"18.0.4","versionType":"semver","status":"affected"},{"version":"18.1","lessThan":"18.1.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N","baseScore":2.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-07-10T20:08:31.332460Z","id":"CVE-2025-4972","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.0.0","versionEndExcluding":"18.0.4","matchCriteriaId":"4F27FCAE-C2B3-489C-AEDB-BA19DD32DE7A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.1.0","versionEndExcluding":"18.1.2","matchCriteriaId":"163718AE-806A-4D9C-ADA1-30FBFA87C317"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/543816","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3148693","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-6168","sourceIdentifier":"cve@gitlab.com","published":"2025-07-10T09:15:30.803","lastModified":"2026-06-17T10:01:18.727","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions from 18.0 before 18.0.4 and 18.1 before 18.1.2 that could have allowed authenticated maintainers to bypass group-level user invitation restrictions by sending crafted API requests."},{"lang":"es","value":"Se ha descubierto un problema en GitLab EE que afecta a todas las versiones desde la 18.0 hasta la 18.0.4 y desde la 18.1 hasta la 18.1.2 que podría haber permitido a los mantenedores autenticados eludir las restricciones de invitación de usuarios a nivel de grupo mediante el envío de solicitudes de API manipuladas."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.0","lessThan":"18.0.4","versionType":"semver","status":"affected"},{"version":"18.1","lessThan":"18.1.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N","baseScore":2.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N","baseScore":2.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-07-10T20:08:04.162538Z","id":"CVE-2025-6168","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.0.0","versionEndExcluding":"18.0.4","matchCriteriaId":"4F27FCAE-C2B3-489C-AEDB-BA19DD32DE7A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.1.0","versionEndExcluding":"18.1.2","matchCriteriaId":"163718AE-806A-4D9C-ADA1-30FBFA87C317"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/549725","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3196745","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-6948","sourceIdentifier":"cve@gitlab.com","published":"2025-07-10T09:15:30.990","lastModified":"2026-06-17T10:02:55.547","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 17.11 before 17.11.6, 18.0 before 18.0.4, and 18.1 before 18.1.2 that, under certain conditions, could have allowed a successful attacker to execute actions on behalf of users by injecting malicious content."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde la 17.11 anterior a la 17.11.6, la 18.0 anterior a la 18.0.4 y la 18.1 anterior a la 18.1.2 que, en determinadas condiciones, podría haber permitido a un atacante exitoso ejecutar acciones en nombre de los usuarios inyectando contenido malicioso."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.11","lessThan":"17.11.6","versionType":"semver","status":"affected"},{"version":"18.0","lessThan":"18.0.4","versionType":"semver","status":"affected"},{"version":"18.1","lessThan":"18.1.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","baseScore":8.0,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.1,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-07-11T03:55:23.139738Z","id":"CVE-2025-6948","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.11.0","versionEndExcluding":"17.11.6","matchCriteriaId":"60F87BFE-7A24-4D47-BC2D-7E03A36A01C0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.11.0","versionEndExcluding":"17.11.6","matchCriteriaId":"F8DBDAFE-3F46-4DB7-B9A8-666CD2168228"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.0.0","versionEndExcluding":"18.0.4","matchCriteriaId":"A4839A98-785F-41DD-A6A1-51476E823CFE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.0.0","versionEndExcluding":"18.0.4","matchCriteriaId":"4F27FCAE-C2B3-489C-AEDB-BA19DD32DE7A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.1.0","versionEndExcluding":"18.1.2","matchCriteriaId":"BE71AB34-398E-4A9B-A90C-63B1CD883426"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.1.0","versionEndExcluding":"18.1.2","matchCriteriaId":"163718AE-806A-4D9C-ADA1-30FBFA87C317"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/552616","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3227316","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-4439","sourceIdentifier":"cve@gitlab.com","published":"2025-07-23T18:15:27.593","lastModified":"2026-06-17T09:33:15.217","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that could have allowed an authenticated user to perform cross-site scripting attacks when the instance is served through certain content delivery networks."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde la 15.10 hasta la 18.0.5, la 18.1 hasta la 18.1.3 y la 18.2 hasta la 18.2.1 que podría haber permitido que un usuario autenticado realizara ataques de cross-site scripting cuando la instancia se sirve a través de determinadas redes de distribución de contenido."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.10","lessThan":"18.0.5","versionType":"semver","status":"affected"},{"version":"18.1","lessThan":"18.1.3","versionType":"semver","status":"affected"},{"version":"18.2","lessThan":"18.2.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":7.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.3,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-07-25T03:55:24.387871Z","id":"CVE-2025-4439","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.10.0","versionEndExcluding":"18.0.5","matchCriteriaId":"B4843D35-6AAB-4476-B87A-411B03F12CFB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.10.0","versionEndExcluding":"18.0.5","matchCriteriaId":"8B296ED8-416F-454C-85B7-D537A0C12B35"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.1.0","versionEndExcluding":"18.1.3","matchCriteriaId":"F6FBDC48-B16F-4DE3-8A25-650EA1B3A7E6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.1.0","versionEndExcluding":"18.1.3","matchCriteriaId":"1BD9DE80-2A4C-421F-98AC-25F160771956"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.2:*:*:*:community:*:*:*","matchCriteriaId":"C56C6B73-A79C-4B34-82FA-6451CCA9C093"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"8931BAA0-5961-46EC-BF0C-62EE4E8A7BE1"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/541177","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3120111","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-4700","sourceIdentifier":"cve@gitlab.com","published":"2025-07-23T18:15:27.750","lastModified":"2026-06-17T09:33:48.933","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that, under specific circumstances, could have potentially allowed a successful attacker to trigger unintended content rendering leading to XSS."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde la 15.10 hasta la 18.0.5, la 18.1 hasta la 18.1.3 y la 18.2 hasta la 18.2.1 que, en circunstancias específicas, podría haber permitido que un atacante exitoso desencadenara una representación de contenido no deseada que condujera a XSS."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.10","lessThan":"18.0.5","versionType":"semver","status":"affected"},{"version":"18.1","lessThan":"18.1.3","versionType":"semver","status":"affected"},{"version":"18.2","lessThan":"18.2.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-07-25T03:55:23.228372Z","id":"CVE-2025-4700","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.10.0","versionEndExcluding":"18.0.5","matchCriteriaId":"B4843D35-6AAB-4476-B87A-411B03F12CFB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.10.0","versionEndExcluding":"18.0.5","matchCriteriaId":"8B296ED8-416F-454C-85B7-D537A0C12B35"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.1.0","versionEndExcluding":"18.1.3","matchCriteriaId":"F6FBDC48-B16F-4DE3-8A25-650EA1B3A7E6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.1.0","versionEndExcluding":"18.1.3","matchCriteriaId":"1BD9DE80-2A4C-421F-98AC-25F160771956"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.2:*:*:*:community:*:*:*","matchCriteriaId":"C56C6B73-A79C-4B34-82FA-6451CCA9C093"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"8931BAA0-5961-46EC-BF0C-62EE4E8A7BE1"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/542915","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3120062","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-0765","sourceIdentifier":"cve@gitlab.com","published":"2025-07-24T07:15:52.397","lastModified":"2026-06-17T08:27:07.170","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that could have allowed an unauthorized user to access custom service desk email addresses."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde la 17.9 hasta la 18.0.5, la 18.1 hasta la 18.1.3 y la 18.2 hasta la 18.2.1, que podría haber permitido que un usuario no autorizado accediera a direcciones de correo electrónico de la mesa de ayuda personalizadas."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.9","lessThan":"18.0.5","versionType":"semver","status":"affected"},{"version":"18.1","lessThan":"18.1.3","versionType":"semver","status":"affected"},{"version":"18.2","lessThan":"18.2.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-07-24T13:09:53.141107Z","id":"CVE-2025-0765","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.9.0","versionEndExcluding":"18.0.5","matchCriteriaId":"E9AD35A3-1BAC-4E3D-A918-02F46842F014"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.9.0","versionEndExcluding":"18.0.5","matchCriteriaId":"70A3CB4F-B7F5-4EB1-80D7-08F06FCA777E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.1.0","versionEndExcluding":"18.1.3","matchCriteriaId":"F6FBDC48-B16F-4DE3-8A25-650EA1B3A7E6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.1.0","versionEndExcluding":"18.1.3","matchCriteriaId":"1BD9DE80-2A4C-421F-98AC-25F160771956"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.2:*:*:*:community:*:*:*","matchCriteriaId":"C56C6B73-A79C-4B34-82FA-6451CCA9C093"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"8931BAA0-5961-46EC-BF0C-62EE4E8A7BE1"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/515381","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2956315","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-1299","sourceIdentifier":"cve@gitlab.com","published":"2025-07-24T07:15:52.680","lastModified":"2026-06-17T08:38:46.143","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 18.0.5, all versions starting from 18.1 before 18.1.3, all versions starting from 18.2 before 18.2.1 that, under circumstances, could have allowed an unauthorized user to read deployment job logs by sending a crafted request."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde la 15.4 hasta la 18.0.5, todas las versiones desde la 18.1 hasta la 18.1.3 y todas las versiones desde la 18.2 hasta la 18.2.1 que, en determinadas circunstancias, podría haber permitido que un usuario no autorizado lea los registros de trabajos de implementación mediante el envío de una solicitud manipulada específicamente para ello."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.4","lessThan":"18.0.5","versionType":"semver","status":"affected"},{"version":"18.1","lessThan":"18.1.3","versionType":"semver","status":"affected"},{"version":"18.2","lessThan":"18.2.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-07-24T13:10:02.960645Z","id":"CVE-2025-1299","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.4","versionEndExcluding":"18.0.5","matchCriteriaId":"445E0AD2-4A54-4A29-9506-035A9CB49AF8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.4","versionEndExcluding":"18.0.5","matchCriteriaId":"329FB7F6-E717-480B-8A0E-212223662340"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.1.0","versionEndExcluding":"18.1.3","matchCriteriaId":"F6FBDC48-B16F-4DE3-8A25-650EA1B3A7E6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.1.0","versionEndExcluding":"18.1.3","matchCriteriaId":"1BD9DE80-2A4C-421F-98AC-25F160771956"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.2:*:*:*:community:*:*:*","matchCriteriaId":"C56C6B73-A79C-4B34-82FA-6451CCA9C093"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"8931BAA0-5961-46EC-BF0C-62EE4E8A7BE1"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/519696","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2969145","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-4976","sourceIdentifier":"cve@gitlab.com","published":"2025-07-24T07:15:53.963","lastModified":"2026-06-17T09:34:25.403","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions from 17.0 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that, under certain circumstances, could have allowed an attacker to access internal notes in GitLab Duo responses."},{"lang":"es","value":"Se ha descubierto un problema en GitLab EE que afecta a todas las versiones desde la 17.0 hasta la 18.0.5, la 18.1 hasta la 18.1.3 y la 18.2 hasta la 18.2.1 que, en determinadas circunstancias, podría haber permitido a un atacante acceder a notas internas en las respuestas de GitLab Duo."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.0","lessThan":"18.0.5","versionType":"semver","status":"affected"},{"version":"18.1","lessThan":"18.1.3","versionType":"semver","status":"affected"},{"version":"18.2","lessThan":"18.2.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-07-24T13:10:43.770952Z","id":"CVE-2025-4976","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-213"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"18.0.5","matchCriteriaId":"3A900441-295E-449E-8CF9-E6CF7BBF6A2E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.1.0","versionEndExcluding":"18.1.3","matchCriteriaId":"1BD9DE80-2A4C-421F-98AC-25F160771956"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"8931BAA0-5961-46EC-BF0C-62EE4E8A7BE1"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/543905","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3149956","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-7001","sourceIdentifier":"cve@gitlab.com","published":"2025-07-24T07:15:54.580","lastModified":"2026-06-17T10:04:04.547","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 15.0 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that could have allowed priviledged users to access certain resource_group information through the API which should have been unavailable."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde la 15.0 hasta la 18.0.5, la 18.1 hasta la 18.1.3 y la 18.2 hasta la 18.2.1 que podría haber permitido a usuarios privilegiados acceder a cierta información de resource_group a través de la API que no debería haber estado disponible."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.0","lessThan":"18.0.5","versionType":"semver","status":"affected"},{"version":"18.1","lessThan":"18.1.3","versionType":"semver","status":"affected"},{"version":"18.2","lessThan":"18.2.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N","baseScore":2.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-07-24T13:10:47.745728Z","id":"CVE-2025-7001","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1220"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.0.0","versionEndExcluding":"18.0.5","matchCriteriaId":"6975C4D1-A976-49E3-BB6E-028136EC33B5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.0.0","versionEndExcluding":"18.0.5","matchCriteriaId":"5432CCBF-B0AC-4C0D-AC61-6BD5D5816113"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.1.0","versionEndExcluding":"18.1.3","matchCriteriaId":"F6FBDC48-B16F-4DE3-8A25-650EA1B3A7E6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.1.0","versionEndExcluding":"18.1.3","matchCriteriaId":"1BD9DE80-2A4C-421F-98AC-25F160771956"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.2:*:*:*:community:*:*:*","matchCriteriaId":"C56C6B73-A79C-4B34-82FA-6451CCA9C093"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"8931BAA0-5961-46EC-BF0C-62EE4E8A7BE1"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/553163","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3223993","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-10219","sourceIdentifier":"cve@gitlab.com","published":"2025-08-13T18:15:26.993","lastModified":"2026-06-17T06:55:10.980","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 15.6 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that under certain conditions could have allowed authenticated users to bypass access controls and download private artifacts by accessing specific API endpoints."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde la 15.6 hasta la 18.0.6, la 18.1 hasta la 18.1.4 y la 18.2 hasta la 18.2.2 que, en determinadas condiciones, podría haber permitido a los usuarios autenticados eludir los controles de acceso y descargar artefactos privados accediendo a endpoints de API específicos."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.6","lessThan":"18.0.6","versionType":"semver","status":"affected"},{"version":"18.1","lessThan":"18.1.4","versionType":"semver","status":"affected"},{"version":"18.2","lessThan":"18.2.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-08-13T19:49:31.951441Z","id":"CVE-2024-10219","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.6.0","versionEndExcluding":"18.0.6","matchCriteriaId":"1E56D067-AD4C-4B41-85AE-7FF0688E3C65"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.6.0","versionEndExcluding":"18.0.6","matchCriteriaId":"858D1B3F-4183-4583-B3ED-9C0893F337A4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.1.0","versionEndExcluding":"18.1.4","matchCriteriaId":"1CCCECB8-5D3F-4117-A108-45900C906EBB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.1.0","versionEndExcluding":"18.1.4","matchCriteriaId":"A8A01B2F-02DE-4743-939A-F9170497ACB6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"18.2.2","matchCriteriaId":"F9A9F69D-06EC-4876-AAA3-B3BD737FBC01"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"18.2.2","matchCriteriaId":"CAFE4523-C681-44E4-A5E1-312D520EEBEE"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/500134","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2780353","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-12303","sourceIdentifier":"cve@gitlab.com","published":"2025-08-13T18:15:28.573","lastModified":"2026-06-17T06:59:27.783","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that under certain conditions could have allowed authenticated users with specific roles and permissions to delete issues including confidential ones by inviting users with a specific role."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde la 17.7 hasta la 18.0.6, la 18.1 hasta la 18.1.4 y la 18.2 hasta la 18.2.2 que, en determinadas condiciones, podría haber permitido a usuarios autenticados con roles y permisos específicos eliminar problemas, incluidos los confidenciales, invitando a usuarios con un rol específico."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.7","lessThan":"18.0.6","versionType":"semver","status":"affected"},{"version":"18.1","lessThan":"18.1.4","versionType":"semver","status":"affected"},{"version":"18.2","lessThan":"18.2.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L","baseScore":6.7,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":1.2,"impactScore":5.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:L","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":1.2,"impactScore":4.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-08-13T19:59:48.614731Z","id":"CVE-2024-12303","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-266"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.7.0","versionEndExcluding":"18.0.6","matchCriteriaId":"93B98521-FC51-45B5-B856-CE7C0291CCCE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.7.0","versionEndExcluding":"18.0.6","matchCriteriaId":"913288E2-61D4-432A-897F-B6D791AD4967"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.1.0","versionEndExcluding":"18.1.4","matchCriteriaId":"1CCCECB8-5D3F-4117-A108-45900C906EBB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.1.0","versionEndExcluding":"18.1.4","matchCriteriaId":"A8A01B2F-02DE-4743-939A-F9170497ACB6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"18.2.2","matchCriteriaId":"F9A9F69D-06EC-4876-AAA3-B3BD737FBC01"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"18.2.2","matchCriteriaId":"CAFE4523-C681-44E4-A5E1-312D520EEBEE"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/508298","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2861889","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-1477","sourceIdentifier":"cve@gitlab.com","published":"2025-08-13T18:15:28.903","lastModified":"2026-06-17T08:39:13.460","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 8.14 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed an unauthenticated user to create a denial of service condition by sending specially crafted payloads to specific integration API endpoints."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde la 8.14 hasta la 18.0.6, la 18.1 hasta la 18.1.4 y la 18.2 hasta la 18.2.2 que podría haber permitido que un usuario no autenticado creara una condición de denegación de servicio al enviar payloads especialmente manipulados a endpoints de API de integración específicos."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"8.14","lessThan":"18.0.6","versionType":"semver","status":"affected"},{"version":"18.1","lessThan":"18.1.4","versionType":"semver","status":"affected"},{"version":"18.2","lessThan":"18.2.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-08-13T20:01:12.488288Z","id":"CVE-2025-1477","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.1.4","versionEndExcluding":"18.0.6","matchCriteriaId":"4B985239-A852-4B16-918E-02D8DE295383"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.1.4","versionEndExcluding":"18.0.6","matchCriteriaId":"6BC4A434-82E1-4584-8552-A7483FEC6B43"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.1.0","versionEndExcluding":"18.1.4","matchCriteriaId":"1CCCECB8-5D3F-4117-A108-45900C906EBB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.1.0","versionEndExcluding":"18.1.4","matchCriteriaId":"A8A01B2F-02DE-4743-939A-F9170497ACB6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"18.2.2","matchCriteriaId":"F9A9F69D-06EC-4876-AAA3-B3BD737FBC01"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"18.2.2","matchCriteriaId":"CAFE4523-C681-44E4-A5E1-312D520EEBEE"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/520353","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2987614","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-2498","sourceIdentifier":"cve@gitlab.com","published":"2025-08-13T18:15:30.657","lastModified":"2026-06-17T09:07:04.050","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An improper access control in Gitlab EE affecting all versions from 12.0 prior to 18.0.6, 18.1 prior to 18.1.4, and 18.2 prior to 18.2.2 that under certain conditions could have allowed users to view assigned issues from restricted groups by bypassing IP restrictions."},{"lang":"es","value":"Un control de acceso inadecuado en Gitlab EE que afecta a todas las versiones desde la 12.0 anterior a la 18.0.6, la 18.1 anterior a la 18.1.4 y la 18.2 anterior a la 18.2.2 que, bajo ciertas condiciones, podría haber permitido a los usuarios ver problemas asignados de grupos restringidos eludiendo las restricciones de IP."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"12.0","lessThan":"18.0.6","versionType":"semver","status":"affected"},{"version":"18.1","lessThan":"18.1.4","versionType":"semver","status":"affected"},{"version":"18.2","lessThan":"18.2.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":3.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-08-13T20:02:18.781705Z","id":"CVE-2025-2498","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1220"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.0.0","versionEndExcluding":"18.0.6","matchCriteriaId":"90380151-3766-4585-9C6C-7EE4D236A04F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.1.0","versionEndExcluding":"18.1.4","matchCriteriaId":"A8A01B2F-02DE-4743-939A-F9170497ACB6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"18.2.2","matchCriteriaId":"CAFE4523-C681-44E4-A5E1-312D520EEBEE"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/525515","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3037722","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-2614","sourceIdentifier":"cve@gitlab.com","published":"2025-08-13T18:15:30.843","lastModified":"2026-06-17T09:07:17.247","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 11.6 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed an authenticated user to cause a denial of service condition by creating specially crafted content that consumes excessive server resources when processed."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde la 11.6 hasta la 18.0.6, la 18.1 hasta la 18.1.4 y la 18.2 hasta la 18.2.2 que podría haber permitido que un usuario autenticado provocara una condición de denegación de servicio al crear contenido especialmente manipulado que consume recursos excesivos del servidor cuando se procesa."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"11.6","lessThan":"18.0.6","versionType":"semver","status":"affected"},{"version":"18.1","lessThan":"18.1.4","versionType":"semver","status":"affected"},{"version":"18.2","lessThan":"18.2.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-08-13T18:31:08.700923Z","id":"CVE-2025-2614","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"18.0.6","matchCriteriaId":"1D7A8F5E-562F-41E5-A5CD-3DAC3E883EB6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.6.0","versionEndExcluding":"18.0.6","matchCriteriaId":"8DEFE29F-85AE-4630-9675-2C455A572ECF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.1.0","versionEndExcluding":"18.1.4","matchCriteriaId":"1CCCECB8-5D3F-4117-A108-45900C906EBB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.1.0","versionEndExcluding":"18.1.4","matchCriteriaId":"A8A01B2F-02DE-4743-939A-F9170497ACB6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"18.2.2","matchCriteriaId":"F9A9F69D-06EC-4876-AAA3-B3BD737FBC01"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"18.2.2","matchCriteriaId":"CAFE4523-C681-44E4-A5E1-312D520EEBEE"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/526349","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3015894","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-2937","sourceIdentifier":"cve@gitlab.com","published":"2025-08-13T18:15:31.010","lastModified":"2026-06-17T09:07:53.110","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 13.2 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed authenticated users to create a denial of service condition by sending specially crafted markdown payloads to the Wiki feature."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde la 13.2 hasta la 18.0.6, la 18.1 hasta la 18.1.4 y la 18.2 hasta la 18.2.2 que podría haber permitido a los usuarios autenticados crear una condición de denegación de servicio mediante el envío de payloads de Markdown especialmente manipulados a la función Wiki."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"13.2","lessThan":"18.0.6","versionType":"semver","status":"affected"},{"version":"18.1","lessThan":"18.1.4","versionType":"semver","status":"affected"},{"version":"18.2","lessThan":"18.2.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-08-13T20:03:13.135846Z","id":"CVE-2025-2937","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1333"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"18.0.6","matchCriteriaId":"CC3DB3A6-96D0-48C8-B3F6-0B50D8C27B74"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"18.0.6","matchCriteriaId":"84BCDB8A-DF5F-4497-9640-131F9E3C9A42"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.1.0","versionEndExcluding":"18.1.4","matchCriteriaId":"1CCCECB8-5D3F-4117-A108-45900C906EBB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.1.0","versionEndExcluding":"18.1.4","matchCriteriaId":"A8A01B2F-02DE-4743-939A-F9170497ACB6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"18.2.2","matchCriteriaId":"F9A9F69D-06EC-4876-AAA3-B3BD737FBC01"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"18.2.2","matchCriteriaId":"CAFE4523-C681-44E4-A5E1-312D520EEBEE"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/528995","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3058879","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-5819","sourceIdentifier":"cve@gitlab.com","published":"2025-08-13T18:15:32.330","lastModified":"2026-06-17T09:48:48.530","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 15.7 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed authenticated users with developer access to obtain ID tokens for protected branches under certain circumstances."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde la 15.7 hasta la 17.11.6, la 18.0 hasta la 18.0.4 y la 18.1 hasta la 18.1.2 que podría haber permitido a usuarios autenticados con acceso de desarrollador obtener tokens de identificación para ramas protegidas en determinadas circunstancias."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.7","lessThan":"18.0.6","versionType":"semver","status":"affected"},{"version":"18.1","lessThan":"18.1.4","versionType":"semver","status":"affected"},{"version":"18.2","lessThan":"18.2.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N","baseScore":5.0,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-08-13T20:04:14.647573Z","id":"CVE-2025-5819","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-732"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.7.0","versionEndExcluding":"17.11.6","matchCriteriaId":"E189D5F9-07AA-4D2B-AE92-B3ED70347DBF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.7.0","versionEndExcluding":"17.11.6","matchCriteriaId":"E288E668-62BD-41DC-B9D9-3FCEC3A1C251"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.0.0","versionEndExcluding":"18.0.4","matchCriteriaId":"A4839A98-785F-41DD-A6A1-51476E823CFE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.0.0","versionEndExcluding":"18.0.4","matchCriteriaId":"4F27FCAE-C2B3-489C-AEDB-BA19DD32DE7A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.1.0","versionEndExcluding":"18.1.2","matchCriteriaId":"BE71AB34-398E-4A9B-A90C-63B1CD883426"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.1.0","versionEndExcluding":"18.1.2","matchCriteriaId":"163718AE-806A-4D9C-ADA1-30FBFA87C317"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/548165","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3137660","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-6186","sourceIdentifier":"cve@gitlab.com","published":"2025-08-13T18:15:32.533","lastModified":"2026-06-17T10:01:20.760","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed authenticated users to achieve account takeover by injecting malicious HTML into work item names."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde la 18.1 hasta la 18.1.4 y desde la 18.2 hasta la 18.2.2 que podría haber permitido a usuarios autenticados tomar el control de la cuenta inyectando HTML malicioso en los nombres de los elementos de trabajo."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.1","lessThan":"18.1.4","versionType":"semver","status":"affected"},{"version":"18.2","lessThan":"18.2.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-08-13T20:36:42.623448Z","id":"CVE-2025-6186","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.1.0","versionEndExcluding":"18.1.4","matchCriteriaId":"1CCCECB8-5D3F-4117-A108-45900C906EBB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.1.0","versionEndExcluding":"18.1.4","matchCriteriaId":"A8A01B2F-02DE-4743-939A-F9170497ACB6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"18.2.2","matchCriteriaId":"F9A9F69D-06EC-4876-AAA3-B3BD737FBC01"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"18.2.2","matchCriteriaId":"CAFE4523-C681-44E4-A5E1-312D520EEBEE"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/549844","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3189522","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-7734","sourceIdentifier":"cve@gitlab.com","published":"2025-08-13T18:15:32.703","lastModified":"2026-06-17T10:05:33.220","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 14.2 before 18.0.6, 18.1 before 18.1.4 and 18.2 before 18.2.2 that, under certain conditions, could have allowed a successful attacker to execute actions on behalf of users by injecting malicious content."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde la 14.2 hasta la 18.0.6, la 18.1 hasta la 18.1.4 y la 18.2 hasta la 18.2.2 que, en determinadas condiciones, podría haber permitido a un atacante exitoso ejecutar acciones en nombre de los usuarios inyectando contenido malicioso."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"14.2","lessThan":"18.0.6","versionType":"semver","status":"affected"},{"version":"18.1","lessThan":"18.1.4","versionType":"semver","status":"affected"},{"version":"18.2","lessThan":"18.2.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-08-13T20:35:14.741869Z","id":"CVE-2025-7734","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"18.0.6","matchCriteriaId":"93CBEA62-4805-4407-B9F2-AC98A3BD4776"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"18.0.6","matchCriteriaId":"386CE102-ADC9-4031-BB4A-3CCC43668D01"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.1.0","versionEndExcluding":"18.1.4","matchCriteriaId":"1CCCECB8-5D3F-4117-A108-45900C906EBB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.1.0","versionEndExcluding":"18.1.4","matchCriteriaId":"A8A01B2F-02DE-4743-939A-F9170497ACB6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"18.2.2","matchCriteriaId":"F9A9F69D-06EC-4876-AAA3-B3BD737FBC01"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"18.2.2","matchCriteriaId":"CAFE4523-C681-44E4-A5E1-312D520EEBEE"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/556090","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3247096","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-7739","sourceIdentifier":"cve@gitlab.com","published":"2025-08-13T18:15:32.883","lastModified":"2026-06-17T10:05:33.673","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 18.2 before 18.2.2 that, under certain conditions, could have allowed authenticated users to achieve stored cross-site scripting by injecting malicious HTML content in scoped label descriptions."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde la 18.2 anterior a la 18.2.2 y que, en determinadas condiciones, podría haber permitido a usuarios autenticados lograr Cross-Site Scripting almacenado mediante la inyección de contenido HTML malicioso en las descripciones de etiquetas con alcance."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.2","lessThan":"18.2.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-08-13T20:36:10.445096Z","id":"CVE-2025-7739","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"18.2.2","matchCriteriaId":"F9A9F69D-06EC-4876-AAA3-B3BD737FBC01"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"18.2.2","matchCriteriaId":"CAFE4523-C681-44E4-A5E1-312D520EEBEE"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/556111","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3255849","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-8770","sourceIdentifier":"cve@gitlab.com","published":"2025-08-13T18:15:33.250","lastModified":"2026-06-17T10:07:35.677","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions from 18.0 prior to 18.0.6, 18.1 prior to 18.1.4, and 18.2 prior to 18.2.2 that could have allowed authenticated users with specific access to bypass merge request approval policies by manipulating approval rule identifiers."},{"lang":"es","value":"Se ha descubierto un problema en GitLab EE que afecta a todas las versiones desde la 18.0 anterior a la 18.0.6, la 18.1 anterior a la 18.1.4 y la 18.2 anterior a la 18.2.2 que podría haber permitido a usuarios autenticados con acceso específico eludir las políticas de aprobación de solicitudes de fusión manipulando los identificadores de las reglas de aprobación."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.0","lessThan":"18.0.6","versionType":"semver","status":"affected"},{"version":"18.1","lessThan":"18.1.4","versionType":"semver","status":"affected"},{"version":"18.2","lessThan":"18.2.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-08-13T20:05:13.795438Z","id":"CVE-2025-8770","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-639"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.0.0","versionEndExcluding":"18.0.6","matchCriteriaId":"8732ABE4-1363-4DB4-8205-EF2C8D393B94"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.1.0","versionEndExcluding":"18.1.4","matchCriteriaId":"A8A01B2F-02DE-4743-939A-F9170497ACB6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"18.2.2","matchCriteriaId":"CAFE4523-C681-44E4-A5E1-312D520EEBEE"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/549105","source":"cve@gitlab.com","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2025-2246","sourceIdentifier":"cve@gitlab.com","published":"2025-08-27T20:15:31.877","lastModified":"2026-06-17T09:06:36.933","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that could have allowed unauthenticated users to access sensitive manual CI/CD variables by querying the GraphQL API."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones anteriores a la 18.1.5, 18.2 anteriores a la 18.2.5 y 18.3 anteriores a la 18.3.1 que podría haber permitido a usuarios no autenticados acceder a variables manuales confidenciales de CI/CD consultando la API GraphQL."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"0","lessThan":"18.1.5","versionType":"semver","status":"affected"},{"version":"18.2","lessThan":"18.2.5","versionType":"semver","status":"affected"},{"version":"18.3","lessThan":"18.3.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N","baseScore":5.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-08-27T19:49:50.314158Z","id":"CVE-2025-2246","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"18.1.5","matchCriteriaId":"5B784A4E-56A5-4FB4-8E87-13810490F090"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"18.1.5","matchCriteriaId":"98D3EC94-0875-425C-97C4-2E495CB9735B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"18.2.5","matchCriteriaId":"7D318F06-A01A-4C04-A5CE-00347F7201C9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"18.2.5","matchCriteriaId":"450C862F-1130-40E3-9A99-F04001558803"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.3.0:*:*:*:community:*:*:*","matchCriteriaId":"079AC183-AA7D-47D4-BE44-55A04C85426F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.3.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"5BA9E943-C8C4-4181-A0BF-5DADFE88413D"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/524592","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3026559","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-3601","sourceIdentifier":"cve@gitlab.com","published":"2025-08-27T20:15:32.123","lastModified":"2026-06-17T09:20:16.753","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 8.15 before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that could have could have allowed an authenticated user to cause a Denial of Service (DoS) condition by submitting URLs that generate excessively large responses."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde la 8.15 hasta la 18.1.5, la 18.2 hasta la 18.2.5 y la 18.3 hasta la 18.3.1 que podría haber permitido que un usuario autenticado provocara una condición de denegación de servicio (DoS) al enviar URL que generan respuestas excesivamente grandes."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"8.15","lessThan":"18.1.5","versionType":"semver","status":"affected"},{"version":"18.2","lessThan":"18.2.5","versionType":"semver","status":"affected"},{"version":"18.3","lessThan":"18.3.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-08-27T19:53:57.127888Z","id":"CVE-2025-3601","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.15.0","versionEndExcluding":"18.1.5","matchCriteriaId":"53B03500-CCAE-4A0F-B3B0-73F449C5E382"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.15.0","versionEndExcluding":"18.1.5","matchCriteriaId":"38CEAF45-3E99-4235-9D39-445ABFCB6414"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"18.2.5","matchCriteriaId":"7D318F06-A01A-4C04-A5CE-00347F7201C9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"18.2.5","matchCriteriaId":"450C862F-1130-40E3-9A99-F04001558803"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.3.0:*:*:*:community:*:*:*","matchCriteriaId":"079AC183-AA7D-47D4-BE44-55A04C85426F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.3.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"5BA9E943-C8C4-4181-A0BF-5DADFE88413D"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/536034","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3050155","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-4225","sourceIdentifier":"cve@gitlab.com","published":"2025-08-27T20:15:32.360","lastModified":"2026-06-17T09:32:48.210","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 14.1 before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that that under certain conditions could have allowed an unauthenticated attacker to cause a denial-of-service condition affecting all users by sending specially crafted GraphQL requests."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde la 14.1 hasta la 18.1.5, la 18.2 hasta la 18.2.5 y la 18.3 hasta la 18.3.1 que, en determinadas condiciones, podría haber permitido que un atacante no autenticado provocara una condición de denegación de servicio que afectara a todos los usuarios mediante el envío de solicitudes GraphQL especialmente manipuladas."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"14.1","lessThan":"18.1.5","versionType":"semver","status":"affected"},{"version":"18.2","lessThan":"18.2.5","versionType":"semver","status":"affected"},{"version":"18.3","lessThan":"18.3.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-08-27T19:50:21.485585Z","id":"CVE-2025-4225","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"18.1.5","matchCriteriaId":"799F546A-AFFC-4C2D-A04E-33054148A4F7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"18.1.5","matchCriteriaId":"C8F16E25-E2DD-45F9-B7D4-4617178BAB3A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"18.2.5","matchCriteriaId":"7D318F06-A01A-4C04-A5CE-00347F7201C9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"18.2.5","matchCriteriaId":"450C862F-1130-40E3-9A99-F04001558803"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.3.0:*:*:*:community:*:*:*","matchCriteriaId":"079AC183-AA7D-47D4-BE44-55A04C85426F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.3.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"5BA9E943-C8C4-4181-A0BF-5DADFE88413D"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/538983","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3100624","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-5101","sourceIdentifier":"cve@gitlab.com","published":"2025-08-27T20:15:34.303","lastModified":"2026-06-17T09:47:11.977","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that under certain conditions could have allowed an authenticated attacker to distribute malicious code that appears harmless in the web interface by taking advantage of ambiguity between branches and tags during repository imports."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones anteriores a la 18.1.5, 18.2 anteriores a la 18.2.5 y 18.3 anteriores a la 18.3.1 que, en determinadas condiciones, podría haber permitido a un atacante autenticado distribuir código malicioso que parece inofensivo en la interfaz web aprovechando la ambigüedad entre ramas y etiquetas durante las importaciones del repositorio."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"0","lessThan":"18.1.5","versionType":"semver","status":"affected"},{"version":"18.2","lessThan":"18.2.5","versionType":"semver","status":"affected"},{"version":"18.3","lessThan":"18.3.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:N/I:H/A:N","baseScore":5.0,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":0.6,"impactScore":4.0}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-08-27T19:53:27.843157Z","id":"CVE-2025-5101","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-94"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"18.1.5","matchCriteriaId":"5B784A4E-56A5-4FB4-8E87-13810490F090"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"18.1.5","matchCriteriaId":"98D3EC94-0875-425C-97C4-2E495CB9735B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"18.2.5","matchCriteriaId":"7D318F06-A01A-4C04-A5CE-00347F7201C9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"18.2.5","matchCriteriaId":"450C862F-1130-40E3-9A99-F04001558803"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.3.0:*:*:*:community:*:*:*","matchCriteriaId":"079AC183-AA7D-47D4-BE44-55A04C85426F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.3.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"5BA9E943-C8C4-4181-A0BF-5DADFE88413D"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/545165","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3124199","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-10094","sourceIdentifier":"cve@gitlab.com","published":"2025-09-12T05:15:31.127","lastModified":"2026-06-17T08:27:40.647","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 10.7 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed authenticated users to disrupt access to token listings and related administrative operations by creating tokens with excessively large names."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"10.7","lessThan":"18.1.6","versionType":"semver","status":"affected"},{"version":"18.2","lessThan":"18.2.6","versionType":"semver","status":"affected"},{"version":"18.3","lessThan":"18.3.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-09-12T13:05:04.221834Z","id":"CVE-2025-10094","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1284"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.7.0","versionEndExcluding":"18.1.6","matchCriteriaId":"94BD5D04-0974-4191-88D9-C012FB6E7FE3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.7.0","versionEndExcluding":"18.1.6","matchCriteriaId":"C952B2BB-FB17-4E6F-B9DE-17201BFAF34D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"18.2.6","matchCriteriaId":"0AE72006-E61F-4311-85EC-6A66CEB965BF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"18.2.6","matchCriteriaId":"08696B68-9433-4D5C-9B89-8C27B560EAAC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.3.0","versionEndExcluding":"18.3.2","matchCriteriaId":"CBCE9083-14B2-4CB3-958F-A5A434802971"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.3.0","versionEndExcluding":"18.3.2","matchCriteriaId":"D53E3D75-7E79-43CE-8A5B-91A8FA2B293E"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2025/09/10/patch-release-gitlab-18-3-2-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/528469","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3049089","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-1250","sourceIdentifier":"cve@gitlab.com","published":"2025-09-12T06:15:42.080","lastModified":"2026-06-17T08:38:40.827","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 15.0 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed an authenticated user to stall background job processing by sending specially crafted commit messages, merge request descriptions, or notes."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.0","lessThan":"18.1.6","versionType":"semver","status":"affected"},{"version":"18.2","lessThan":"18.2.6","versionType":"semver","status":"affected"},{"version":"18.3","lessThan":"18.3.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-09-12T17:19:54.754145Z","id":"CVE-2025-1250","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.0.0","versionEndExcluding":"18.1.6","matchCriteriaId":"B6968457-514A-4C8B-BAF7-43C4E8E7C539"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.0.0","versionEndExcluding":"18.1.6","matchCriteriaId":"9A2D8FCA-1F5A-442E-BF1F-EB62AFB657EE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"18.2.6","matchCriteriaId":"0AE72006-E61F-4311-85EC-6A66CEB965BF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"18.2.6","matchCriteriaId":"08696B68-9433-4D5C-9B89-8C27B560EAAC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.3.0","versionEndExcluding":"18.3.2","matchCriteriaId":"CBCE9083-14B2-4CB3-958F-A5A434802971"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.3.0","versionEndExcluding":"18.3.2","matchCriteriaId":"D53E3D75-7E79-43CE-8A5B-91A8FA2B293E"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2025/09/10/patch-release-gitlab-18-3-2-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/519335","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2903896","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-2256","sourceIdentifier":"cve@gitlab.com","published":"2025-09-12T06:15:42.340","lastModified":"2026-06-17T09:06:38.377","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 7.12 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed unauthorized users to render the GitLab instance unresponsive to legitimate users by sending multiple concurrent large SAML responses."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"7.12","lessThan":"18.1.6","versionType":"semver","status":"affected"},{"version":"18.2","lessThan":"18.2.6","versionType":"semver","status":"affected"},{"version":"18.3","lessThan":"18.3.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-09-12T17:19:23.671886Z","id":"CVE-2025-2256","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1284"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"7.12.0","versionEndExcluding":"18.1.6","matchCriteriaId":"2DA1D9DE-488C-494C-9429-1782CFD0BC60"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"7.12.0","versionEndExcluding":"18.1.6","matchCriteriaId":"6EF9F050-955A-4E5A-9A27-3993063AD779"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"18.2.6","matchCriteriaId":"0AE72006-E61F-4311-85EC-6A66CEB965BF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"18.2.6","matchCriteriaId":"08696B68-9433-4D5C-9B89-8C27B560EAAC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.3.0","versionEndExcluding":"18.3.2","matchCriteriaId":"CBCE9083-14B2-4CB3-958F-A5A434802971"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.3.0","versionEndExcluding":"18.3.2","matchCriteriaId":"D53E3D75-7E79-43CE-8A5B-91A8FA2B293E"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2025/09/10/patch-release-gitlab-18-3-2-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/524633","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3019485","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-6454","sourceIdentifier":"cve@gitlab.com","published":"2025-09-12T06:15:42.990","lastModified":"2026-06-17T10:01:55.720","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 16.11 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed authenticated users to make unintended internal requests through proxy environments by injecting crafted sequences."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.11","lessThan":"18.1.6","versionType":"semver","status":"affected"},{"version":"18.2","lessThan":"18.2.6","versionType":"semver","status":"affected"},{"version":"18.3","lessThan":"18.3.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":8.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":6.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-09-12T17:18:49.673424Z","id":"CVE-2025-6454","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.11.0","versionEndExcluding":"18.1.6","matchCriteriaId":"1BB011EE-CB96-4C65-A9AC-39A9444F02B7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.11.0","versionEndExcluding":"18.1.6","matchCriteriaId":"04DCF212-BB94-4ED9-8A26-EB3E9D887FDC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"18.2.6","matchCriteriaId":"0AE72006-E61F-4311-85EC-6A66CEB965BF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"18.2.6","matchCriteriaId":"08696B68-9433-4D5C-9B89-8C27B560EAAC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.3.0","versionEndExcluding":"18.3.2","matchCriteriaId":"CBCE9083-14B2-4CB3-958F-A5A434802971"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.3.0","versionEndExcluding":"18.3.2","matchCriteriaId":"D53E3D75-7E79-43CE-8A5B-91A8FA2B293E"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2025/09/10/patch-release-gitlab-18-3-2-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/550766","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3162711","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-6769","sourceIdentifier":"cve@gitlab.com","published":"2025-09-12T06:15:43.227","lastModified":"2026-06-17T10:02:32.273","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 15.1 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed authenticated users to view administrator-only maintenance notes by accessing runner details through specific interfaces."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.1","lessThan":"18.1.6","versionType":"semver","status":"affected"},{"version":"18.2","lessThan":"18.2.6","versionType":"semver","status":"affected"},{"version":"18.3","lessThan":"18.3.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-09-12T17:18:03.759605Z","id":"CVE-2025-6769","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-497"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.1.0","versionEndExcluding":"18.1.6","matchCriteriaId":"2D4A77B7-2F1E-4CD1-ADEB-5537BB553E75"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.1.0","versionEndExcluding":"18.1.6","matchCriteriaId":"16F89186-9D6B-4094-AAB6-69D4E0BDBDA6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"18.2.6","matchCriteriaId":"0AE72006-E61F-4311-85EC-6A66CEB965BF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"18.2.6","matchCriteriaId":"08696B68-9433-4D5C-9B89-8C27B560EAAC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.3.0","versionEndExcluding":"18.3.2","matchCriteriaId":"CBCE9083-14B2-4CB3-958F-A5A434802971"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.3.0","versionEndExcluding":"18.3.2","matchCriteriaId":"D53E3D75-7E79-43CE-8A5B-91A8FA2B293E"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2025/09/10/patch-release-gitlab-18-3-2-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/551957","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3173328","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-7337","sourceIdentifier":"cve@gitlab.com","published":"2025-09-12T06:15:43.440","lastModified":"2026-06-17T10:04:44.967","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 7.8 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed an authenticated user with Developer-level access to cause a persistent denial of service affecting all users on a GitLab instance by uploading large files."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"7.8","lessThan":"18.1.6","versionType":"semver","status":"affected"},{"version":"18.2","lessThan":"18.2.6","versionType":"semver","status":"affected"},{"version":"18.3","lessThan":"18.3.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-09-12T15:53:00.428750Z","id":"CVE-2025-7337","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"7.8.0","versionEndExcluding":"18.1.6","matchCriteriaId":"2B228CD5-3972-4200-810A-284A5E076501"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"7.8.0","versionEndExcluding":"18.1.6","matchCriteriaId":"8F95FD40-5E51-4D14-9F55-EC57FC3B38FC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"18.2.6","matchCriteriaId":"0AE72006-E61F-4311-85EC-6A66CEB965BF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"18.2.6","matchCriteriaId":"08696B68-9433-4D5C-9B89-8C27B560EAAC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.3.0","versionEndExcluding":"18.3.2","matchCriteriaId":"CBCE9083-14B2-4CB3-958F-A5A434802971"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.3.0","versionEndExcluding":"18.3.2","matchCriteriaId":"D53E3D75-7E79-43CE-8A5B-91A8FA2B293E"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2025/09/10/patch-release-gitlab-18-3-2-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/554062","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3161756","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-10858","sourceIdentifier":"cve@gitlab.com","published":"2025-09-26T09:15:30.797","lastModified":"2026-06-17T08:29:10.190","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab CE/EE affecting all versions before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that allows unauthenticated users to cause a Denial of Service (DoS) condition while uploading specifically crafted large JSON files."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"0","lessThan":"18.2.7","versionType":"semver","status":"affected"},{"version":"18.3","lessThan":"18.3.3","versionType":"semver","status":"affected"},{"version":"18.4","lessThan":"18.4.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-09-26T15:32:43.476400Z","id":"CVE-2025-10858","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionEndExcluding":"18.2.7","matchCriteriaId":"EBAF4883-2E25-491F-92A5-20CFD060CE2B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"18.2.7","matchCriteriaId":"57E06FB3-0B50-4D99-8767-C2FF6F38DD52"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.3.0","versionEndExcluding":"18.3.3","matchCriteriaId":"75F843E1-B1EB-44F7-9966-9874F512A487"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.3.0","versionEndExcluding":"18.3.3","matchCriteriaId":"FEDB2960-F05D-4510-ACD3-05F16E621C6B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.4.0:*:*:*:community:*:*:*","matchCriteriaId":"C0DA83D6-F16D-47B4-B817-1591FB60E5E6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.4.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"6976AFEA-CD46-41A2-B52D-67FA8D4481D5"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/570034","source":"cve@gitlab.com","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2025-10867","sourceIdentifier":"cve@gitlab.com","published":"2025-09-26T09:15:31.000","lastModified":"2026-06-17T08:29:10.813","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 18.1 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that could have allowed an authenticated user to create a denial-of-service condition by exploiting an unprotected GraphQL API through repeated requests."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.1","lessThan":"18.2.7","versionType":"semver","status":"affected"},{"version":"18.3","lessThan":"18.3.3","versionType":"semver","status":"affected"},{"version":"18.4","lessThan":"18.4.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L","baseScore":3.5,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.1,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-09-26T15:33:16.173172Z","id":"CVE-2025-10867","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.1.0","versionEndExcluding":"18.2.7","matchCriteriaId":"D395161B-7D1B-48ED-B431-A579B88456C1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.1.0","versionEndExcluding":"18.2.7","matchCriteriaId":"2444171B-C61A-41E1-A5A1-D9323B5C3639"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.3.0","versionEndExcluding":"18.3.3","matchCriteriaId":"75F843E1-B1EB-44F7-9966-9874F512A487"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.3.0","versionEndExcluding":"18.3.3","matchCriteriaId":"FEDB2960-F05D-4510-ACD3-05F16E621C6B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.4.0:*:*:*:community:*:*:*","matchCriteriaId":"C0DA83D6-F16D-47B4-B817-1591FB60E5E6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.4.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"6976AFEA-CD46-41A2-B52D-67FA8D4481D5"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/517757","source":"cve@gitlab.com","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2025-10871","sourceIdentifier":"cve@gitlab.com","published":"2025-09-26T09:15:31.193","lastModified":"2026-06-17T08:29:11.270","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions from 16.6 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1. Project Maintainers can exploit a vulnerability where they can assign custom roles to users with permissions exceeding their own, effectively granting themselves elevated privileges."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.6","lessThan":"18.2.7","versionType":"semver","status":"affected"},{"version":"18.3","lessThan":"18.3.3","versionType":"semver","status":"affected"},{"version":"18.4","lessThan":"18.4.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L","baseScore":3.8,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":1.2,"impactScore":2.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-09-27T03:55:26.598432Z","id":"CVE-2025-10871","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.6.0","versionEndExcluding":"18.2.7","matchCriteriaId":"76C5C554-F9E7-4EBA-AA66-5C3DAA1F4CF2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.6.0","versionEndExcluding":"18.2.7","matchCriteriaId":"61099C09-E411-4624-9CC6-7A314340A8E8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.3.0","versionEndExcluding":"18.3.3","matchCriteriaId":"75F843E1-B1EB-44F7-9966-9874F512A487"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.3.0","versionEndExcluding":"18.3.3","matchCriteriaId":"FEDB2960-F05D-4510-ACD3-05F16E621C6B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.4.0:*:*:*:community:*:*:*","matchCriteriaId":"C0DA83D6-F16D-47B4-B817-1591FB60E5E6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.4.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"6976AFEA-CD46-41A2-B52D-67FA8D4481D5"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/569482","source":"cve@gitlab.com","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2025-7691","sourceIdentifier":"cve@gitlab.com","published":"2025-09-26T09:15:48.810","lastModified":"2026-06-17T10:05:28.527","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A privilege escalation issue has been discovered in GitLab EE affecting all versions from 16.6 prior to 18.2.7, 18.3 prior to 18.3.3, and 18.4 prior to 18.4.1 that could have allowed a developer with specific group management permissions to escalate their privileges and obtain unauthorized access to additional system capabilities."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.6","lessThan":"18.2.7","versionType":"semver","status":"affected"},{"version":"18.3","lessThan":"18.3.3","versionType":"semver","status":"affected"},{"version":"18.4","lessThan":"18.4.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-09-27T03:55:25.765550Z","id":"CVE-2025-7691","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-267"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.6.0","versionEndExcluding":"18.2.7","matchCriteriaId":"76C5C554-F9E7-4EBA-AA66-5C3DAA1F4CF2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.6.0","versionEndExcluding":"18.2.7","matchCriteriaId":"61099C09-E411-4624-9CC6-7A314340A8E8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.3.0","versionEndExcluding":"18.3.3","matchCriteriaId":"75F843E1-B1EB-44F7-9966-9874F512A487"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.3.0","versionEndExcluding":"18.3.3","matchCriteriaId":"FEDB2960-F05D-4510-ACD3-05F16E621C6B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.4.0:*:*:*:community:*:*:*","matchCriteriaId":"C0DA83D6-F16D-47B4-B817-1591FB60E5E6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.4.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"6976AFEA-CD46-41A2-B52D-67FA8D4481D5"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/555786","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3200469","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-9642","sourceIdentifier":"cve@gitlab.com","published":"2025-09-26T09:15:49.003","lastModified":"2026-06-17T10:09:26.043","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 14.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that could allow an attacker to inject malicious content that may lead to account takeover."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"14.10","lessThan":"18.2.7","versionType":"semver","status":"affected"},{"version":"18.3","lessThan":"18.3.3","versionType":"semver","status":"affected"},{"version":"18.4","lessThan":"18.4.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","baseScore":9.6,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":6.0}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-09-26T13:14:09.988553Z","id":"CVE-2025-9642","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.10.0","versionEndExcluding":"18.2.7","matchCriteriaId":"CB7D996F-1439-4F11-B694-95C7F7103E56"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.10.0","versionEndExcluding":"18.2.7","matchCriteriaId":"56F1A8B6-897F-4E31-A08A-FE9C08D1E435"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.3.0","versionEndExcluding":"18.3.3","matchCriteriaId":"75F843E1-B1EB-44F7-9966-9874F512A487"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.3.0","versionEndExcluding":"18.3.3","matchCriteriaId":"FEDB2960-F05D-4510-ACD3-05F16E621C6B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.4.0:*:*:*:community:*:*:*","matchCriteriaId":"C0DA83D6-F16D-47B4-B817-1591FB60E5E6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.4.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"6976AFEA-CD46-41A2-B52D-67FA8D4481D5"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/566505","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3297413","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-9958","sourceIdentifier":"cve@gitlab.com","published":"2025-09-26T09:15:49.180","lastModified":"2026-06-17T10:10:09.347","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 14.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1, that could have allowed Guest users to access sensitive information stored in virtual registry configurations."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"14.10","lessThan":"18.2.7","versionType":"semver","status":"affected"},{"version":"18.3","lessThan":"18.3.3","versionType":"semver","status":"affected"},{"version":"18.4","lessThan":"18.4.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","baseScore":7.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":4.0}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-09-26T13:15:38.977851Z","id":"CVE-2025-9958","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-201"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.10.0","versionEndExcluding":"18.2.7","matchCriteriaId":"CB7D996F-1439-4F11-B694-95C7F7103E56"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.10.0","versionEndExcluding":"18.2.7","matchCriteriaId":"56F1A8B6-897F-4E31-A08A-FE9C08D1E435"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.3.0","versionEndExcluding":"18.3.3","matchCriteriaId":"75F843E1-B1EB-44F7-9966-9874F512A487"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.3.0","versionEndExcluding":"18.3.3","matchCriteriaId":"FEDB2960-F05D-4510-ACD3-05F16E621C6B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.4.0:*:*:*:community:*:*:*","matchCriteriaId":"C0DA83D6-F16D-47B4-B817-1591FB60E5E6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.4.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"6976AFEA-CD46-41A2-B52D-67FA8D4481D5"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/567777","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3323573","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-10868","sourceIdentifier":"cve@gitlab.com","published":"2025-09-26T10:15:46.750","lastModified":"2026-06-17T08:29:10.927","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 17.4 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 where certain string conversion methods exhibit performance degradation with large inputs."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.4","lessThan":"18.2.7","versionType":"semver","status":"affected"},{"version":"18.3","lessThan":"18.3.3","versionType":"semver","status":"affected"},{"version":"18.4","lessThan":"18.4.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L","baseScore":3.5,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.1,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-09-26T13:12:37.785268Z","id":"CVE-2025-10868","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-840"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.4.0","versionEndExcluding":"18.2.7","matchCriteriaId":"1DEDF54B-B041-49AA-A4FD-0307E5A9628D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.4.0","versionEndExcluding":"18.2.7","matchCriteriaId":"D8C6A4C3-C43D-46F7-BD4B-4C82F64E37EA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.3.0","versionEndExcluding":"18.3.3","matchCriteriaId":"75F843E1-B1EB-44F7-9966-9874F512A487"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.3.0","versionEndExcluding":"18.3.3","matchCriteriaId":"FEDB2960-F05D-4510-ACD3-05F16E621C6B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.4.0:*:*:*:community:*:*:*","matchCriteriaId":"C0DA83D6-F16D-47B4-B817-1591FB60E5E6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.4.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"6976AFEA-CD46-41A2-B52D-67FA8D4481D5"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/526482","source":"cve@gitlab.com","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2025-11042","sourceIdentifier":"cve@gitlab.com","published":"2025-09-26T10:15:47.003","lastModified":"2026-06-17T08:29:31.180","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab CE/EE affecting all versions starting from 17.2 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1, that allows an attacker to cause uncontrolled CPU consumption, potentially leading to a Denial of Service (DoS) condition while using specific GraphQL queries."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.2","lessThan":"18.2.7","versionType":"semver","status":"affected"},{"version":"18.3","lessThan":"18.3.3","versionType":"semver","status":"affected"},{"version":"18.4","lessThan":"18.4.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-09-26T13:04:44.869141Z","id":"CVE-2025-11042","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"18.2.7","matchCriteriaId":"5C0F16AA-FAD3-429B-B729-040FDB47AEC9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.2.0","versionEndExcluding":"18.2.7","matchCriteriaId":"34300E2B-BB31-464C-84C5-C6557AB12BAA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.3.0","versionEndExcluding":"18.3.3","matchCriteriaId":"75F843E1-B1EB-44F7-9966-9874F512A487"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.3.0","versionEndExcluding":"18.3.3","matchCriteriaId":"FEDB2960-F05D-4510-ACD3-05F16E621C6B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.4.0:*:*:*:community:*:*:*","matchCriteriaId":"C0DA83D6-F16D-47B4-B817-1591FB60E5E6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.4.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"6976AFEA-CD46-41A2-B52D-67FA8D4481D5"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/550374","source":"cve@gitlab.com","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2025-5069","sourceIdentifier":"cve@gitlab.com","published":"2025-09-26T10:15:47.217","lastModified":"2026-06-17T09:47:08.253","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 17.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that could have allowed an authenticated user to gain unauthorized access to confidential issues by creating a project with an identical name to the victim's project."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.10","lessThan":"18.2.7","versionType":"semver","status":"affected"},{"version":"18.3","lessThan":"18.3.3","versionType":"semver","status":"affected"},{"version":"18.4","lessThan":"18.4.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N","baseScore":3.5,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-09-26T13:11:58.588643Z","id":"CVE-2025-5069","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-708"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.10.0","versionEndExcluding":"18.2.7","matchCriteriaId":"118E2D95-7225-4156-9090-319AEB4C03D2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.10.0","versionEndExcluding":"18.2.7","matchCriteriaId":"4FABCE43-579A-4277-83E5-334086CF11C3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.3.0","versionEndExcluding":"18.3.3","matchCriteriaId":"75F843E1-B1EB-44F7-9966-9874F512A487"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.3.0","versionEndExcluding":"18.3.3","matchCriteriaId":"FEDB2960-F05D-4510-ACD3-05F16E621C6B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.4.0:*:*:*:community:*:*:*","matchCriteriaId":"C0DA83D6-F16D-47B4-B817-1591FB60E5E6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.4.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"6976AFEA-CD46-41A2-B52D-67FA8D4481D5"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/544926","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3019236","source":"cve@gitlab.com","tags":["Issue Tracking","Permissions Required"]}]}},{"cve":{"id":"CVE-2025-8014","sourceIdentifier":"cve@gitlab.com","published":"2025-09-27T17:15:33.987","lastModified":"2026-06-17T10:06:08.663","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Denial of Service issue in GraphQL endpoints in Gitlab EE/CE affecting all versions from 11.10 prior to 18.2.7, 18.3 prior to 18.3.3, and 18.4 prior to 18.4.1 allows unauthenticated users to potentially bypass query complexity limits leading to resource exhaustion and service disruption."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"11.10","lessThan":"18.2.7","versionType":"semver","status":"affected"},{"version":"18.3","lessThan":"18.3.3","versionType":"semver","status":"affected"},{"version":"18.4","lessThan":"18.4.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-09-30T17:27:09.194434Z","id":"CVE-2025-8014","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.10.0","versionEndExcluding":"18.2.7","matchCriteriaId":"93BFA3A3-74FF-4A3C-A852-47222A68EEB4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.10.0","versionEndExcluding":"18.2.7","matchCriteriaId":"318545D2-1C74-4698-8414-212C8D6BA4BF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.3.0","versionEndExcluding":"18.3.3","matchCriteriaId":"75F843E1-B1EB-44F7-9966-9874F512A487"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.3.0","versionEndExcluding":"18.3.3","matchCriteriaId":"FEDB2960-F05D-4510-ACD3-05F16E621C6B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.4.0:*:*:*:community:*:*:*","matchCriteriaId":"C0DA83D6-F16D-47B4-B817-1591FB60E5E6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.4.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"6976AFEA-CD46-41A2-B52D-67FA8D4481D5"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/556838","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3228134","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-10004","sourceIdentifier":"cve@gitlab.com","published":"2025-10-09T12:15:34.570","lastModified":"2026-06-17T08:27:30.313","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.12 to 18.2.8, 18.3 to 18.3.4, and 18.4 to 18.4.2 that could make the GitLab instance unresponsive or severely degraded by sending crafted GraphQL queries requesting large repository blobs."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"13.12","lessThan":"18.2.8","versionType":"semver","status":"affected"},{"version":"18.3","lessThan":"18.3.4","versionType":"semver","status":"affected"},{"version":"18.4","lessThan":"18.4.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-10-09T13:15:06.752510Z","id":"CVE-2025-10004","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.12.0","versionEndExcluding":"18.2.8","matchCriteriaId":"BC727177-F9EF-438A-94B6-2BBCB78C4776"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.12.0","versionEndExcluding":"18.2.8","matchCriteriaId":"20F1A1DC-3585-492D-8FDF-71739290C905"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.3.0","versionEndExcluding":"18.3.4","matchCriteriaId":"536C1DFE-B81E-4E5E-A979-EBB8AEB62F4C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.3.0","versionEndExcluding":"18.3.4","matchCriteriaId":"15A762DA-E645-404C-B831-A63171FF3EF2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.4.0","versionEndExcluding":"18.4.2","matchCriteriaId":"A0684F06-FCCA-400A-AB87-BB9B9F906187"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.4.0","versionEndExcluding":"18.4.2","matchCriteriaId":"719CBD84-A5F7-4332-8C37-D68474A2FB70"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2025/10/08/patch-release-gitlab-18-4-2-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/568121","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3026555","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-11340","sourceIdentifier":"cve@gitlab.com","published":"2025-10-09T12:15:35.233","lastModified":"2026-06-17T08:30:15.610","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 to 18.3.4, 18.4 to 18.4.2 that, under certain conditions, could have allowed authenticated users with read-only API tokens to perform unauthorized write operations on vulnerability records by exploiting incorrectly scoped GraphQL mutations."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.3","lessThan":"18.3.4","versionType":"semver","status":"affected"},{"version":"18.4","lessThan":"18.4.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N","baseScore":7.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":4.0}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-10-09T13:42:36.367153Z","id":"CVE-2025-11340","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.3.0","versionEndExcluding":"18.3.4","matchCriteriaId":"536C1DFE-B81E-4E5E-A979-EBB8AEB62F4C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.3.0","versionEndExcluding":"18.3.4","matchCriteriaId":"15A762DA-E645-404C-B831-A63171FF3EF2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.4.0","versionEndExcluding":"18.4.2","matchCriteriaId":"A0684F06-FCCA-400A-AB87-BB9B9F906187"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.4.0","versionEndExcluding":"18.4.2","matchCriteriaId":"719CBD84-A5F7-4332-8C37-D68474A2FB70"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2025/10/08/patch-release-gitlab-18-4-2-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/567847","source":"cve@gitlab.com","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2025-2934","sourceIdentifier":"cve@gitlab.com","published":"2025-10-09T12:15:35.477","lastModified":"2026-06-17T09:07:52.897","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 5.2 prior to 18.2.8, 18.3 prior to 18.3.4, and 18.4 prior to 18.4.2 that could have allowed an authenticated attacker to create a denial of service condition by configuring malicious webhook endpoints that send crafted HTTP responses."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"5.2","lessThan":"18.2.8","versionType":"semver","status":"affected"},{"version":"18.3","lessThan":"18.3.4","versionType":"semver","status":"affected"},{"version":"18.4","lessThan":"18.4.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-10-09T13:48:42.834321Z","id":"CVE-2025-2934","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"5.2.0","versionEndExcluding":"18.2.8","matchCriteriaId":"EE108845-3479-4BAE-AD0E-C6C04E77CF96"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"5.2.0","versionEndExcluding":"18.2.8","matchCriteriaId":"7108DAFA-241C-4361-981F-27A33F59A9AA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.3.0","versionEndExcluding":"18.3.4","matchCriteriaId":"536C1DFE-B81E-4E5E-A979-EBB8AEB62F4C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.3.0","versionEndExcluding":"18.3.4","matchCriteriaId":"15A762DA-E645-404C-B831-A63171FF3EF2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.4.0","versionEndExcluding":"18.4.2","matchCriteriaId":"A0684F06-FCCA-400A-AB87-BB9B9F906187"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.4.0","versionEndExcluding":"18.4.2","matchCriteriaId":"719CBD84-A5F7-4332-8C37-D68474A2FB70"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2025/10/08/patch-release-gitlab-18-4-2-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/528979","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3058791","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-10497","sourceIdentifier":"cve@gitlab.com","published":"2025-10-27T00:15:39.650","lastModified":"2026-06-17T08:28:26.273","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an unauthenticated attacker to cause a denial of service condition by sending specially crafted payloads."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.10","lessThan":"18.3.5","versionType":"semver","status":"affected"},{"version":"18.4","lessThan":"18.4.3","versionType":"semver","status":"affected"},{"version":"18.5","lessThan":"18.5.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-10-28T15:02:41.745901Z","id":"CVE-2025-10497","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.10.0","versionEndExcluding":"18.3.5","matchCriteriaId":"4A07627F-FE09-440A-854E-D5456FFA132F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.10.0","versionEndExcluding":"18.3.5","matchCriteriaId":"6B7E6DED-6510-4DFF-A2AA-000518999F0B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.4.0","versionEndExcluding":"18.4.3","matchCriteriaId":"7B4DC1E2-0920-4A1B-8AE8-89B7FDF0897A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.4.0","versionEndExcluding":"18.4.3","matchCriteriaId":"425AEB81-EA04-4702-99F8-B623614F6901"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.5.0:*:*:*:community:*:*:*","matchCriteriaId":"3D74D76F-A787-40A8-A20F-C48C48983B10"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.5.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"CCF08EA3-6D3E-4388-BA9D-A992B771998F"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2025/10/22/patch-release-gitlab-18-5-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/570336","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3338151","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-11447","sourceIdentifier":"cve@gitlab.com","published":"2025-10-27T00:15:40.460","lastModified":"2026-06-17T08:30:28.743","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.0 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an unauthenticated attacker to cause a denial of service condition by sending GraphQL requests with crafted JSON payloads."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"11.0","lessThan":"18.3.5","versionType":"semver","status":"affected"},{"version":"18.4","lessThan":"18.4.3","versionType":"semver","status":"affected"},{"version":"18.5","lessThan":"18.5.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-10-28T14:58:29.737927Z","id":"CVE-2025-11447","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"18.3.5","matchCriteriaId":"D44F410C-9878-4F55-BC05-0BC217AB6FA2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"18.3.5","matchCriteriaId":"D74E050B-0AD8-45BE-AAA1-54E01DE6A217"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.4.0","versionEndExcluding":"18.4.3","matchCriteriaId":"7B4DC1E2-0920-4A1B-8AE8-89B7FDF0897A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.4.0","versionEndExcluding":"18.4.3","matchCriteriaId":"425AEB81-EA04-4702-99F8-B623614F6901"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.5.0:*:*:*:community:*:*:*","matchCriteriaId":"3D74D76F-A787-40A8-A20F-C48C48983B10"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.5.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"CCF08EA3-6D3E-4388-BA9D-A992B771998F"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2025/10/22/patch-release-gitlab-18-5-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/574858","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3367019","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-11971","sourceIdentifier":"cve@gitlab.com","published":"2025-10-27T00:15:40.617","lastModified":"2026-06-17T08:31:30.360","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 10.6 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an authenticated attacker to trigger unauthorized pipeline executions by manipulating commits."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"10.6","lessThan":"18.3.5","versionType":"semver","status":"affected"},{"version":"18.4","lessThan":"18.4.3","versionType":"semver","status":"affected"},{"version":"18.5","lessThan":"18.5.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:L/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.3,"impactScore":4.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-10-28T15:00:39.599768Z","id":"CVE-2025-11971","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.6.0","versionEndExcluding":"18.3.5","matchCriteriaId":"57F24E53-00FA-466E-9854-27417F4F8884"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.4.0","versionEndExcluding":"18.4.3","matchCriteriaId":"425AEB81-EA04-4702-99F8-B623614F6901"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.5.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"CCF08EA3-6D3E-4388-BA9D-A992B771998F"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2025/10/22/patch-release-gitlab-18-5-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/566587","source":"cve@gitlab.com","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2025-11974","sourceIdentifier":"cve@gitlab.com","published":"2025-10-27T00:15:40.780","lastModified":"2026-06-17T08:31:30.673","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.7 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an unauthenticated attacker to create a denial of service condition by uploading large files to specific API endpoints."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"11.7","lessThan":"18.3.5","versionType":"semver","status":"affected"},{"version":"18.4","lessThan":"18.4.3","versionType":"semver","status":"affected"},{"version":"18.5","lessThan":"18.5.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-10-28T14:59:43.807990Z","id":"CVE-2025-11974","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"18.3.5","matchCriteriaId":"8A214F13-315E-4707-888F-24C3E1E7E425"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.7.0","versionEndExcluding":"18.3.5","matchCriteriaId":"D7BE13D6-9FEC-4C4F-9F66-C7C86164FFEF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.4.0","versionEndExcluding":"18.4.3","matchCriteriaId":"7B4DC1E2-0920-4A1B-8AE8-89B7FDF0897A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.4.0","versionEndExcluding":"18.4.3","matchCriteriaId":"425AEB81-EA04-4702-99F8-B623614F6901"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.5.0:*:*:*:community:*:*:*","matchCriteriaId":"3D74D76F-A787-40A8-A20F-C48C48983B10"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.5.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"CCF08EA3-6D3E-4388-BA9D-A992B771998F"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2025/10/22/patch-release-gitlab-18-5-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/571761","source":"cve@gitlab.com","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2025-11989","sourceIdentifier":"cve@gitlab.com","published":"2025-10-27T00:15:40.927","lastModified":"2026-06-17T08:31:32.030","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 17.6.0 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an authenticated attacker to execute unauthorized quick actions by including malicious commands in specific descriptions."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.6.0","lessThan":"18.3.5","versionType":"semver","status":"affected"},{"version":"18.4","lessThan":"18.4.3","versionType":"semver","status":"affected"},{"version":"18.5","lessThan":"18.5.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N","baseScore":3.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":2.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-10-28T14:44:38.686241Z","id":"CVE-2025-11989","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.6.0","versionEndExcluding":"18.3.5","matchCriteriaId":"090E4997-CCB2-48AC-9796-56FBE599958D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.4.0","versionEndExcluding":"18.4.3","matchCriteriaId":"425AEB81-EA04-4702-99F8-B623614F6901"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.5.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"CCF08EA3-6D3E-4388-BA9D-A992B771998F"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2025/10/22/patch-release-gitlab-18-5-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/security/gitlab/-/issues/1426","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-6601","sourceIdentifier":"cve@gitlab.com","published":"2025-10-27T00:15:41.100","lastModified":"2026-06-17T10:02:13.740","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.4.3, and 18.5 before 18.5.1 that under certain conditions could have allowed authenticated users to gain unauthorized project access by exploiting the access request approval workflow."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.4","lessThan":"18.4.3","versionType":"semver","status":"affected"},{"version":"18.5","lessThan":"18.5.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N","baseScore":2.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-10-28T15:17:52.854652Z","id":"CVE-2025-6601","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-840"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.4.0","versionEndExcluding":"18.4.3","matchCriteriaId":"425AEB81-EA04-4702-99F8-B623614F6901"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.5.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"CCF08EA3-6D3E-4388-BA9D-A992B771998F"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2025/10/22/patch-release-gitlab-18-5-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/551267","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3209641","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-11702","sourceIdentifier":"cve@gitlab.com","published":"2025-10-29T07:15:37.713","lastModified":"2026-06-17T08:31:01.323","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in EE affecting all versions from 17.1 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an authenticated attacker with specific permissions to hijack project runners from other projects."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.1","lessThan":"18.3.5","versionType":"semver","status":"affected"},{"version":"18.4","lessThan":"18.4.3","versionType":"semver","status":"affected"},{"version":"18.5","lessThan":"18.5.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":8.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":6.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-10-30T03:56:02.159676Z","id":"CVE-2025-11702","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"18.3.5","matchCriteriaId":"DC5B6FC6-90E4-4A5F-A950-2C7942FD05D4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.4.0","versionEndExcluding":"18.4.3","matchCriteriaId":"425AEB81-EA04-4702-99F8-B623614F6901"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.5.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"CCF08EA3-6D3E-4388-BA9D-A992B771998F"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2025/10/22/patch-release-gitlab-18-5-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/576900","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3356284","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-11865","sourceIdentifier":"cve@gitlab.com","published":"2025-11-15T08:15:43.547","lastModified":"2026-06-17T08:31:19.053","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions from 18.1 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that, under certain circumstances, could have allowed an attacker to remove Duo flows of another user."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.1","lessThan":"18.3.6","versionType":"semver","status":"affected"},{"version":"18.4","lessThan":"18.4.4","versionType":"semver","status":"affected"},{"version":"18.5","lessThan":"18.5.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-11-17T20:12:00.898155Z","id":"CVE-2025-11865","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.1.0","versionEndExcluding":"18.3.6","matchCriteriaId":"0AC48ED5-5EF8-477F-A9F9-E08BE928EC6A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.4.0","versionEndExcluding":"18.4.4","matchCriteriaId":"6D0A238D-1278-4D05-86F5-4C323E0CFE36"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.5.0","versionEndExcluding":"18.5.2","matchCriteriaId":"B2A3A57F-C750-4C92-8C2B-C5FCF1D70F4F"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2025/11/12/patch-release-gitlab-18-5-2-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/561399","source":"cve@gitlab.com","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2025-11990","sourceIdentifier":"cve@gitlab.com","published":"2025-11-15T08:15:45.620","lastModified":"2026-06-17T08:31:32.140","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated user to gain CSRF tokens by exploiting improper input validation in repository references combined with redirect handling weaknesses."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.4","lessThan":"18.4.4","versionType":"semver","status":"affected"},{"version":"18.5","lessThan":"18.5.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N","baseScore":3.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N","baseScore":3.5,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-11-17T20:11:06.587307Z","id":"CVE-2025-11990","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-177"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-22"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.4.0","versionEndExcluding":"18.4.4","matchCriteriaId":"6D0A238D-1278-4D05-86F5-4C323E0CFE36"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.5.0","versionEndExcluding":"18.5.2","matchCriteriaId":"B2A3A57F-C750-4C92-8C2B-C5FCF1D70F4F"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2025/11/12/patch-release-gitlab-18-5-2-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/577850","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3257843","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-2615","sourceIdentifier":"cve@gitlab.com","published":"2025-11-15T08:15:45.820","lastModified":"2026-06-17T09:07:17.350","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.7  before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2, that could have allowed a blocked user to access sensitive information by establishing GraphQL subscriptions through WebSocket connections."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.7","lessThan":"18.3.6","versionType":"semver","status":"affected"},{"version":"18.4","lessThan":"18.4.4","versionType":"semver","status":"affected"},{"version":"18.5","lessThan":"18.5.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-11-17T20:16:22.591689Z","id":"CVE-2025-2615","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-201"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.7.0","versionEndExcluding":"18.3.6","matchCriteriaId":"3A389C8A-1460-43EC-9B93-2FEE62D6ABF1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.7.0","versionEndExcluding":"18.3.6","matchCriteriaId":"54B0B363-735C-4D9C-B775-BFAD2B28145B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.4.0","versionEndExcluding":"18.4.4","matchCriteriaId":"36824F52-C9A0-4FB3-91F3-05593E3551E8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.4.0","versionEndExcluding":"18.4.4","matchCriteriaId":"6D0A238D-1278-4D05-86F5-4C323E0CFE36"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.5.0","versionEndExcluding":"18.5.2","matchCriteriaId":"7E85D20B-EEE1-4CC9-B50A-4040972287D8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.5.0","versionEndExcluding":"18.5.2","matchCriteriaId":"B2A3A57F-C750-4C92-8C2B-C5FCF1D70F4F"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2025/11/12/patch-release-gitlab-18-5-2-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/526360","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3049150","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-6171","sourceIdentifier":"cve@gitlab.com","published":"2025-11-15T08:15:46.060","lastModified":"2026-06-17T10:01:19.097","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.2 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated attacker with reporter access to view branch names and pipeline details by accessing the packages API endpoint even when repository access was disabled."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"13.2","lessThan":"18.3.6","versionType":"semver","status":"affected"},{"version":"18.4","lessThan":"18.4.4","versionType":"semver","status":"affected"},{"version":"18.5","lessThan":"18.5.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-11-17T20:14:58.505069Z","id":"CVE-2025-6171","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"18.3.6","matchCriteriaId":"5D9621B6-120A-4697-95AF-A79BE88C0971"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"18.3.6","matchCriteriaId":"A5F24C1A-3D89-40FA-806E-A48A941D3424"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.4.0","versionEndExcluding":"18.4.4","matchCriteriaId":"36824F52-C9A0-4FB3-91F3-05593E3551E8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.4.0","versionEndExcluding":"18.4.4","matchCriteriaId":"6D0A238D-1278-4D05-86F5-4C323E0CFE36"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.5.0","versionEndExcluding":"18.5.2","matchCriteriaId":"7E85D20B-EEE1-4CC9-B50A-4040972287D8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.5.0","versionEndExcluding":"18.5.2","matchCriteriaId":"B2A3A57F-C750-4C92-8C2B-C5FCF1D70F4F"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2025/11/12/patch-release-gitlab-18-5-2-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/549730","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3183740","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-6945","sourceIdentifier":"cve@gitlab.com","published":"2025-11-15T08:15:46.280","lastModified":"2026-06-17T10:02:55.187","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 17.8 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated attacker to leak sensitive information from confidential issues by injecting hidden prompts into merge request comments."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.8","lessThan":"18.3.6","versionType":"semver","status":"affected"},{"version":"18.4","lessThan":"18.4.4","versionType":"semver","status":"affected"},{"version":"18.5","lessThan":"18.5.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N","baseScore":3.5,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-11-17T20:15:58.405498Z","id":"CVE-2025-6945","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-77"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.9.0","versionEndExcluding":"18.3.6","matchCriteriaId":"F7F1402F-B9C8-4697-932D-AC37CE78F39B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.4.0","versionEndExcluding":"18.4.4","matchCriteriaId":"6D0A238D-1278-4D05-86F5-4C323E0CFE36"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.5.0","versionEndExcluding":"18.5.2","matchCriteriaId":"B2A3A57F-C750-4C92-8C2B-C5FCF1D70F4F"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2025/11/12/patch-release-gitlab-18-5-2-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/552611","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3173458","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-7000","sourceIdentifier":"cve@gitlab.com","published":"2025-11-15T08:15:46.487","lastModified":"2026-06-17T10:04:04.437","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions  from 17.6  before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2, that, under specific conditions, could have allowed unauthorized users to view confidential branch names by accessing project issues with related merge requests."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.6","lessThan":"18.3.6","versionType":"semver","status":"affected"},{"version":"18.4","lessThan":"18.4.4","versionType":"semver","status":"affected"},{"version":"18.5","lessThan":"18.5.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-11-17T20:14:01.215076Z","id":"CVE-2025-7000","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-201"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.6.0","versionEndExcluding":"18.3.6","matchCriteriaId":"4398F785-F443-44A2-9191-768F48B10579"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.6.0","versionEndExcluding":"18.3.6","matchCriteriaId":"1272563C-FE27-48BE-9666-065197613AE2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.4.0","versionEndExcluding":"18.4.4","matchCriteriaId":"36824F52-C9A0-4FB3-91F3-05593E3551E8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.4.0","versionEndExcluding":"18.4.4","matchCriteriaId":"6D0A238D-1278-4D05-86F5-4C323E0CFE36"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.5.0","versionEndExcluding":"18.5.2","matchCriteriaId":"7E85D20B-EEE1-4CC9-B50A-4040972287D8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.5.0","versionEndExcluding":"18.5.2","matchCriteriaId":"B2A3A57F-C750-4C92-8C2B-C5FCF1D70F4F"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2025/11/12/patch-release-gitlab-18-5-2-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/553129","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3214025","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-7736","sourceIdentifier":"cve@gitlab.com","published":"2025-11-15T08:15:48.077","lastModified":"2026-06-17T10:05:33.447","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.9 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated attacker to bypass access control restrictions and view GitLab Pages content intended only for project members by authenticating through OAuth providers."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.9","lessThan":"18.3.6","versionType":"semver","status":"affected"},{"version":"18.4","lessThan":"18.4.4","versionType":"semver","status":"affected"},{"version":"18.5","lessThan":"18.5.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":3.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-11-17T20:13:09.443311Z","id":"CVE-2025-7736","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.9.0","versionEndExcluding":"18.3.6","matchCriteriaId":"C9A06CF5-C97F-4DB8-BCE3-2F695904B363"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.9.0","versionEndExcluding":"18.3.6","matchCriteriaId":"F7F1402F-B9C8-4697-932D-AC37CE78F39B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.4.0","versionEndExcluding":"18.4.4","matchCriteriaId":"36824F52-C9A0-4FB3-91F3-05593E3551E8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.4.0","versionEndExcluding":"18.4.4","matchCriteriaId":"6D0A238D-1278-4D05-86F5-4C323E0CFE36"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.5.0","versionEndExcluding":"18.5.2","matchCriteriaId":"7E85D20B-EEE1-4CC9-B50A-4040972287D8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.5.0","versionEndExcluding":"18.5.2","matchCriteriaId":"B2A3A57F-C750-4C92-8C2B-C5FCF1D70F4F"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2025/11/12/patch-release-gitlab-18-5-2-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/556098","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3250156","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-12983","sourceIdentifier":"cve@gitlab.com","published":"2025-11-15T09:15:41.950","lastModified":"2026-06-17T08:33:19.463","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.9 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated attacker to cause a denial of service condition by submitting specially crafted markdown content with nested formatting patterns."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.9","lessThan":"18.3.6","versionType":"semver","status":"affected"},{"version":"18.4","lessThan":"18.4.4","versionType":"semver","status":"affected"},{"version":"18.5","lessThan":"18.5.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:L","baseScore":3.5,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":1.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-11-17T20:17:26.750315Z","id":"CVE-2025-12983","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-789"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.9.0","versionEndExcluding":"18.3.6","matchCriteriaId":"B097C4A0-D3E7-4EE7-8533-30CE2CC51381"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.9.0","versionEndExcluding":"18.3.6","matchCriteriaId":"3073B463-3C6C-456E-8EC6-6E1CA4B3489C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.4.0","versionEndExcluding":"18.4.4","matchCriteriaId":"36824F52-C9A0-4FB3-91F3-05593E3551E8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.4.0","versionEndExcluding":"18.4.4","matchCriteriaId":"6D0A238D-1278-4D05-86F5-4C323E0CFE36"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.5.0","versionEndExcluding":"18.5.2","matchCriteriaId":"7E85D20B-EEE1-4CC9-B50A-4040972287D8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.5.0","versionEndExcluding":"18.5.2","matchCriteriaId":"B2A3A57F-C750-4C92-8C2B-C5FCF1D70F4F"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2025/11/12/patch-release-gitlab-18-5-2-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/296257","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3419588","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-9825","sourceIdentifier":"cve@gitlab.com","published":"2025-11-21T06:15:48.620","lastModified":"2026-06-17T10:09:50.890","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 to 18.2.8, 18.3 before 18.3.4, and 18.4 before 18.4.2 that could have allowed authenticated users without project membership to view sensitive manual CI/CD variables by querying the GraphQL API."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"13.7","lessThan":"18.2.8","versionType":"semver","status":"affected"},{"version":"18.3","lessThan":"18.3.4","versionType":"semver","status":"affected"},{"version":"18.4","lessThan":"18.4.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N","baseScore":5.0,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-11-24T17:00:45.624444Z","id":"CVE-2025-9825","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"18.2.8","matchCriteriaId":"07B861F7-963F-412E-98DC-D0A43D8533CB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"18.2.8","matchCriteriaId":"DF4CBB30-E636-443D-B121-7F409543F160"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.3.0","versionEndExcluding":"18.3.4","matchCriteriaId":"536C1DFE-B81E-4E5E-A979-EBB8AEB62F4C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.3.0","versionEndExcluding":"18.3.4","matchCriteriaId":"15A762DA-E645-404C-B831-A63171FF3EF2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.4.0","versionEndExcluding":"18.4.2","matchCriteriaId":"A0684F06-FCCA-400A-AB87-BB9B9F906187"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.4.0","versionEndExcluding":"18.4.2","matchCriteriaId":"719CBD84-A5F7-4332-8C37-D68474A2FB70"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2025/10/08/patch-release-gitlab-18-4-2-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/567301","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/3319800","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-12571","sourceIdentifier":"cve@gitlab.com","published":"2025-11-26T20:15:47.943","lastModified":"2026-06-17T08:32:35.833","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that could have allowed an unauthenticated user to cause a Denial of Service condition by sending specifically crafted requests containing malicious JSON payloads."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.10","lessThan":"18.4.5","versionType":"semver","status":"affected"},{"version":"18.5","lessThan":"18.5.3","versionType":"semver","status":"affected"},{"version":"18.6","lessThan":"18.6.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-11-28T14:41:27.256515Z","id":"CVE-2025-12571","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.10.0","versionEndExcluding":"18.4.5","matchCriteriaId":"60BC6173-DBA9-4C2B-A659-78F8221C9FD8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.10.0","versionEndExcluding":"18.4.5","matchCriteriaId":"3043D7D0-EFF5-4DC6-8C4F-081D5227CFEE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.5.0","versionEndExcluding":"18.5.3","matchCriteriaId":"A2361C72-A29E-47BB-A3FD-E4D656AF820F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.5.0","versionEndExcluding":"18.5.3","matchCriteriaId":"1B00EBAB-22CC-4350-AED2-60C7F78C0A8F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.6.0:*:*:*:community:*:*:*","matchCriteriaId":"E53003CF-149D-45C9-8574-B57FDE1F1612"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.6.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"200F0D66-67E2-4C9B-98C5-2F57FF5D7611"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2025/11/26/patch-release-gitlab-18-6-1-released/","source":"cve@gitlab.com"},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/579168","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3362239","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-12653","sourceIdentifier":"cve@gitlab.com","published":"2025-11-26T20:15:49.023","lastModified":"2026-06-17T08:32:44.860","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that under specific conditions could have allowed an unauthenticated user to join arbitrary organizations by changing headers on some requests."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.3","lessThan":"18.4.5","versionType":"semver","status":"affected"},{"version":"18.5","lessThan":"18.5.3","versionType":"semver","status":"affected"},{"version":"18.6","lessThan":"18.6.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-11-28T14:41:33.855824Z","id":"CVE-2025-12653","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-290"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.3.0","versionEndExcluding":"18.4.5","matchCriteriaId":"D158EE55-B264-47D6-9FEF-5E047E9F777D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.3.0","versionEndExcluding":"18.4.5","matchCriteriaId":"9EFADCA0-3C50-4E66-8189-AE419FA8EBC1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.5.0","versionEndExcluding":"18.5.3","matchCriteriaId":"A2361C72-A29E-47BB-A3FD-E4D656AF820F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.5.0","versionEndExcluding":"18.5.3","matchCriteriaId":"1B00EBAB-22CC-4350-AED2-60C7F78C0A8F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.6.0:*:*:*:community:*:*:*","matchCriteriaId":"E53003CF-149D-45C9-8574-B57FDE1F1612"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.6.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"200F0D66-67E2-4C9B-98C5-2F57FF5D7611"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2025/11/26/patch-release-gitlab-18-6-1-released/","source":"cve@gitlab.com"},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/579372","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3370245","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-13611","sourceIdentifier":"cve@gitlab.com","published":"2025-11-26T20:15:49.193","lastModified":"2026-06-17T08:34:26.757","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.2 before 18.5.5 and 18.6 before 18.6.3 that could have allowed an authenticated user with access to certain logs to obtain sensitive tokens under specific conditions."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"13.2","lessThan":"18.5.5","versionType":"semver","status":"affected"},{"version":"18.6","lessThan":"18.6.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N","baseScore":2.0,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":0.5,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-11-28T14:39:50.968616Z","id":"CVE-2025-13611","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-532"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"18.4.5","matchCriteriaId":"0C7C8770-E3A1-4096-BFBE-3CD85BFD8B73"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"18.4.5","matchCriteriaId":"C483D310-F8C0-47E8-A363-841F52D913FA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.5.0","versionEndExcluding":"18.5.3","matchCriteriaId":"A2361C72-A29E-47BB-A3FD-E4D656AF820F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.5.0","versionEndExcluding":"18.5.3","matchCriteriaId":"1B00EBAB-22CC-4350-AED2-60C7F78C0A8F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.6.0:*:*:*:community:*:*:*","matchCriteriaId":"E53003CF-149D-45C9-8574-B57FDE1F1612"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.6.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"200F0D66-67E2-4C9B-98C5-2F57FF5D7611"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/01/07/patch-release-gitlab-18-7-1-released/","source":"cve@gitlab.com"},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/545947","source":"cve@gitlab.com","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2025-6195","sourceIdentifier":"cve@gitlab.com","published":"2025-11-26T20:15:50.090","lastModified":"2026-06-17T10:01:21.740","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 13.7 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that could have allowed an authenticated user to view information from security reports under certain configuration conditions."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"13.7","lessThan":"18.4.5","versionType":"semver","status":"affected"},{"version":"18.5","lessThan":"18.5.3","versionType":"semver","status":"affected"},{"version":"18.6","lessThan":"18.6.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-11-28T14:39:47.777226Z","id":"CVE-2025-6195","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-425"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"18.4.5","matchCriteriaId":"8D33C1A9-DEAF-4651-B0B1-99C444EFA4C0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.5.0","versionEndExcluding":"18.5.3","matchCriteriaId":"1B00EBAB-22CC-4350-AED2-60C7F78C0A8F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.6.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"200F0D66-67E2-4C9B-98C5-2F57FF5D7611"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2025/11/26/patch-release-gitlab-18-6-1-released/","source":"cve@gitlab.com"},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/549937","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3155693","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-7449","sourceIdentifier":"cve@gitlab.com","published":"2025-11-26T20:15:50.477","lastModified":"2026-06-17T10:04:58.730","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that could have allowed an authenticated user with specific permissions to cause a denial of service condition through HTTP response processing."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"8.3","lessThan":"18.4.5","versionType":"semver","status":"affected"},{"version":"18.5","lessThan":"18.5.3","versionType":"semver","status":"affected"},{"version":"18.6","lessThan":"18.6.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-11-28T14:39:49.262333Z","id":"CVE-2025-7449","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.3.0","versionEndExcluding":"18.4.5","matchCriteriaId":"D7A50453-90B1-4BD3-8E6A-78DF483A9EA9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.3.0","versionEndExcluding":"18.4.5","matchCriteriaId":"983B9717-8305-4156-A0F5-517331B41325"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.5.0","versionEndExcluding":"18.5.3","matchCriteriaId":"A2361C72-A29E-47BB-A3FD-E4D656AF820F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.5.0","versionEndExcluding":"18.5.3","matchCriteriaId":"1B00EBAB-22CC-4350-AED2-60C7F78C0A8F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.6.0:*:*:*:community:*:*:*","matchCriteriaId":"E53003CF-149D-45C9-8574-B57FDE1F1612"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.6.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"200F0D66-67E2-4C9B-98C5-2F57FF5D7611"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2025/11/26/patch-release-gitlab-18-6-1-released/","source":"cve@gitlab.com"},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/554938","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3215054","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2024-9183","sourceIdentifier":"cve@gitlab.com","published":"2025-12-05T17:16:01.280","lastModified":"2026-06-17T08:24:06.050","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 prior to 18.4.5, 18.5 prior to 18.5.3, and 18.6 prior to 18.6.1 that could have allowed an authenticated user to obtain credentials from higher-privileged users and perform actions in their context under specific conditions."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.4","lessThan":"18.4.5","versionType":"semver","status":"affected"},{"version":"18.5","lessThan":"18.5.3","versionType":"semver","status":"affected"},{"version":"18.6","lessThan":"18.6.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":7.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.3,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-12-09T04:55:54.162192Z","id":"CVE-2024-9183","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-367"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.4.0","versionEndExcluding":"18.4.5","matchCriteriaId":"DEDB4B48-0099-4637-969F-235A829B2BED"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.4.0","versionEndExcluding":"18.4.5","matchCriteriaId":"AA760629-3160-48B1-8AB1-1BB422606F99"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.5.0","versionEndExcluding":"18.5.3","matchCriteriaId":"A2361C72-A29E-47BB-A3FD-E4D656AF820F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.5.0","versionEndExcluding":"18.5.3","matchCriteriaId":"1B00EBAB-22CC-4350-AED2-60C7F78C0A8F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.6.0","versionEndExcluding":"18.6.1","matchCriteriaId":"5A989D8B-F856-41FF-9821-D02D734917B2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.6.0","versionEndExcluding":"18.6.1","matchCriteriaId":"1CEE76F2-C907-49F8-947D-A00385AD4193"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2025/11/26/patch-release-gitlab-18-6-1-released/","source":"cve@gitlab.com"},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/494478","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2707421","source":"cve@gitlab.com","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2025-12562","sourceIdentifier":"cve@gitlab.com","published":"2025-12-11T04:15:58.467","lastModified":"2026-06-17T08:32:35.393","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an unauthenticated user to create a denial of service condition by sending crafted GraphQL queries that bypass query complexity limits."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"11.10","lessThan":"18.4.6","versionType":"semver","status":"affected"},{"version":"18.5","lessThan":"18.5.4","versionType":"semver","status":"affected"},{"version":"18.6","lessThan":"18.6.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-12-11T15:16:34.922734Z","id":"CVE-2025-12562","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.10.0","versionEndExcluding":"18.4.6","matchCriteriaId":"747FE9B2-8B67-4960-9370-2D5AB5E68090"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.10.0","versionEndExcluding":"18.4.6","matchCriteriaId":"EA6AD140-F16F-4AB1-83E8-528C5841B5D9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.5.0","versionEndExcluding":"18.5.4","matchCriteriaId":"457DB333-60BE-44CD-A674-216AB658E14E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.5.0","versionEndExcluding":"18.5.4","matchCriteriaId":"910967DB-0A8C-4436-9D9E-37BD610E7367"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.6.0","versionEndExcluding":"18.6.2","matchCriteriaId":"919A2588-3EA1-4E15-B47E-61B3E14B2781"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.6.0","versionEndExcluding":"18.6.2","matchCriteriaId":"6343A083-3E1C-4551-B230-76CABC3FDD67"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2025/12/10/patch-release-gitlab-18-6-2-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/579152","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3360710","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-12716","sourceIdentifier":"cve@gitlab.com","published":"2025-12-11T04:15:58.627","lastModified":"2026-06-17T08:32:50.587","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that, under certain conditions could have allowed an authenticated user to perform unauthorized actions on behalf of another user by creating wiki pages with malicious content."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.4","lessThan":"18.4.6","versionType":"semver","status":"affected"},{"version":"18.5","lessThan":"18.5.4","versionType":"semver","status":"affected"},{"version":"18.6","lessThan":"18.6.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":5.8}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-12-12T04:55:49.020373Z","id":"CVE-2025-12716","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.4.0","versionEndExcluding":"18.4.6","matchCriteriaId":"86FB8BCE-912E-4928-90CC-7CDCB627C4B6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.4.0","versionEndExcluding":"18.4.6","matchCriteriaId":"15A0C3ED-8A16-4D8C-8C98-05F6394F9EF0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.5.0","versionEndExcluding":"18.5.4","matchCriteriaId":"457DB333-60BE-44CD-A674-216AB658E14E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.5.0","versionEndExcluding":"18.5.4","matchCriteriaId":"910967DB-0A8C-4436-9D9E-37BD610E7367"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.6.0","versionEndExcluding":"18.6.2","matchCriteriaId":"919A2588-3EA1-4E15-B47E-61B3E14B2781"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.6.0","versionEndExcluding":"18.6.2","matchCriteriaId":"6343A083-3E1C-4551-B230-76CABC3FDD67"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2025/12/10/patch-release-gitlab-18-6-2-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/579548","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3405832","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-13978","sourceIdentifier":"cve@gitlab.com","published":"2025-12-11T04:15:58.790","lastModified":"2026-06-17T08:35:06.323","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.5 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to discover the names of private projects they do not have access through API requests."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.5","lessThan":"18.4.6","versionType":"semver","status":"affected"},{"version":"18.5","lessThan":"18.5.4","versionType":"semver","status":"affected"},{"version":"18.6","lessThan":"18.6.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-12-11T15:21:06.520961Z","id":"CVE-2025-13978","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-209"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.5.0","versionEndExcluding":"18.4.6","matchCriteriaId":"90486772-2F3B-4776-A4E4-16AF7489F134"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.5.0","versionEndExcluding":"18.4.6","matchCriteriaId":"7CC8E0F0-93B9-4D75-8BD5-42C4E7510B04"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.5.0","versionEndExcluding":"18.5.4","matchCriteriaId":"457DB333-60BE-44CD-A674-216AB658E14E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.5.0","versionEndExcluding":"18.5.4","matchCriteriaId":"910967DB-0A8C-4436-9D9E-37BD610E7367"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.6.0","versionEndExcluding":"18.6.2","matchCriteriaId":"919A2588-3EA1-4E15-B47E-61B3E14B2781"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.6.0","versionEndExcluding":"18.6.2","matchCriteriaId":"6343A083-3E1C-4551-B230-76CABC3FDD67"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2025/12/10/patch-release-gitlab-18-6-2-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/566960","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/566960","source":"cve@gitlab.com","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2025-14157","sourceIdentifier":"cve@gitlab.com","published":"2025-12-11T04:15:58.947","lastModified":"2026-06-17T08:35:25.687","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 6.3 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to cause a Denial of Service condition by sending crafted API calls with large content parameters."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"6.3","lessThan":"18.4.6","versionType":"semver","status":"affected"},{"version":"18.5","lessThan":"18.5.4","versionType":"semver","status":"affected"},{"version":"18.6","lessThan":"18.6.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-12-11T15:27:21.202826Z","id":"CVE-2025-14157","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"6.3.0","versionEndExcluding":"18.4.6","matchCriteriaId":"01ACB49B-CBA3-4902-A183-F15B9E2155CF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"6.3.0","versionEndExcluding":"18.4.6","matchCriteriaId":"1393246E-BD13-45EB-A366-F79C8BB68324"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.5.0","versionEndExcluding":"18.5.4","matchCriteriaId":"457DB333-60BE-44CD-A674-216AB658E14E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.5.0","versionEndExcluding":"18.5.4","matchCriteriaId":"910967DB-0A8C-4436-9D9E-37BD610E7367"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.6.0","versionEndExcluding":"18.6.2","matchCriteriaId":"919A2588-3EA1-4E15-B47E-61B3E14B2781"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.6.0","versionEndExcluding":"18.6.2","matchCriteriaId":"6343A083-3E1C-4551-B230-76CABC3FDD67"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2025/12/10/patch-release-gitlab-18-6-2-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/574324","source":"cve@gitlab.com","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2025-11247","sourceIdentifier":"cve@gitlab.com","published":"2025-12-11T05:16:35.773","lastModified":"2026-06-17T08:29:56.790","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 13.2 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to disclose sensitive information from private projects by executing specifically crafted GraphQL queries."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"13.2","lessThan":"18.4.6","versionType":"semver","status":"affected"},{"version":"18.5","lessThan":"18.5.4","versionType":"semver","status":"affected"},{"version":"18.6","lessThan":"18.6.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-12-11T15:00:49.568417Z","id":"CVE-2025-11247","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-639"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.2.0","versionEndExcluding":"18.4.6","matchCriteriaId":"46208CB0-DFB0-4246-AAB2-64B8C0394EB6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.5.0","versionEndExcluding":"18.5.4","matchCriteriaId":"910967DB-0A8C-4436-9D9E-37BD610E7367"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.6.0","versionEndExcluding":"18.6.2","matchCriteriaId":"6343A083-3E1C-4551-B230-76CABC3FDD67"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2025/12/10/patch-release-gitlab-18-6-2-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/573766","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3307422","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-11984","sourceIdentifier":"cve@gitlab.com","published":"2025-12-11T05:16:36.970","lastModified":"2026-06-17T08:31:31.517","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.1 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to bypass WebAuthn two-factor authentication by manipulating the session state under certain conditions."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"13.1","lessThan":"18.4.6","versionType":"semver","status":"affected"},{"version":"18.5","lessThan":"18.5.4","versionType":"semver","status":"affected"},{"version":"18.6","lessThan":"18.6.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","baseScore":6.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-12-12T04:55:47.783484Z","id":"CVE-2025-11984","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-288"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"18.4.6","matchCriteriaId":"4667E86F-2DF6-49B4-8C36-E35016B74EB2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"18.4.6","matchCriteriaId":"91CE9ABE-A1FD-4B90-98C7-F058ADA5302E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.5.0","versionEndExcluding":"18.5.4","matchCriteriaId":"457DB333-60BE-44CD-A674-216AB658E14E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.5.0","versionEndExcluding":"18.5.4","matchCriteriaId":"910967DB-0A8C-4436-9D9E-37BD610E7367"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.6.0","versionEndExcluding":"18.6.2","matchCriteriaId":"919A2588-3EA1-4E15-B47E-61B3E14B2781"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.6.0","versionEndExcluding":"18.6.2","matchCriteriaId":"6343A083-3E1C-4551-B230-76CABC3FDD67"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2025/12/10/patch-release-gitlab-18-6-2-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/577847","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3322714","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-4097","sourceIdentifier":"cve@gitlab.com","published":"2025-12-11T05:16:37.153","lastModified":"2026-06-17T09:32:29.893","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to cause a denial of service condition by uploading specially crafted images."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"11.10","lessThan":"18.4.6","versionType":"semver","status":"affected"},{"version":"18.5","lessThan":"18.5.4","versionType":"semver","status":"affected"},{"version":"18.6","lessThan":"18.6.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-12-11T14:57:42.008192Z","id":"CVE-2025-4097","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.10.0","versionEndExcluding":"18.4.6","matchCriteriaId":"747FE9B2-8B67-4960-9370-2D5AB5E68090"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.10.0","versionEndExcluding":"18.4.6","matchCriteriaId":"EA6AD140-F16F-4AB1-83E8-528C5841B5D9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.5.0","versionEndExcluding":"18.5.4","matchCriteriaId":"457DB333-60BE-44CD-A674-216AB658E14E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.5.0","versionEndExcluding":"18.5.4","matchCriteriaId":"910967DB-0A8C-4436-9D9E-37BD610E7367"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.6.0","versionEndExcluding":"18.6.2","matchCriteriaId":"919A2588-3EA1-4E15-B47E-61B3E14B2781"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.6.0","versionEndExcluding":"18.6.2","matchCriteriaId":"6343A083-3E1C-4551-B230-76CABC3FDD67"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2025/12/10/patch-release-gitlab-18-6-2-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/538192","source":"cve@gitlab.com","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2025-8405","sourceIdentifier":"cve@gitlab.com","published":"2025-12-11T05:16:38.447","lastModified":"2026-06-17T10:06:53.947","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated a security issue in GitLab CE/EE affecting all versions from 17.1 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to perform unauthorized actions on behalf of other users by injecting malicious HTML into vulnerability code flow displays."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.1","lessThan":"18.4.6","versionType":"semver","status":"affected"},{"version":"18.5","lessThan":"18.5.4","versionType":"semver","status":"affected"},{"version":"18.6","lessThan":"18.6.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":7.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.3,"impactScore":5.8}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-12-12T04:55:46.627334Z","id":"CVE-2025-8405","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-116"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"18.4.6","matchCriteriaId":"8B96998F-2DA2-48A0-A574-C192E218F193"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"18.4.6","matchCriteriaId":"293FA588-D122-4DCC-BD11-47FE16216D5F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.5.0","versionEndExcluding":"18.5.4","matchCriteriaId":"457DB333-60BE-44CD-A674-216AB658E14E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.5.0","versionEndExcluding":"18.5.4","matchCriteriaId":"910967DB-0A8C-4436-9D9E-37BD610E7367"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.6.0","versionEndExcluding":"18.6.2","matchCriteriaId":"919A2588-3EA1-4E15-B47E-61B3E14B2781"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.6.0","versionEndExcluding":"18.6.2","matchCriteriaId":"6343A083-3E1C-4551-B230-76CABC3FDD67"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2025/12/10/patch-release-gitlab-18-6-2-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/558214","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3270940","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-12029","sourceIdentifier":"cve@gitlab.com","published":"2025-12-11T08:15:47.853","lastModified":"2026-06-17T08:31:35.720","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have, under certain circumstances, allowed an unauthenticated user to perform unauthorized actions on behalf of another user by injecting malicious external scripts into the Swagger UI.\""}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.11","lessThan":"18.4.6","versionType":"semver","status":"affected"},{"version":"18.5","lessThan":"18.5.4","versionType":"semver","status":"affected"},{"version":"18.6","lessThan":"18.6.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N","baseScore":8.0,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":5.8}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-12-12T04:55:45.314598Z","id":"CVE-2025-12029","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.11.0","versionEndExcluding":"18.4.6","matchCriteriaId":"91412C68-DC13-44A6-B63E-77899AA6AF82"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.11.0","versionEndExcluding":"18.4.6","matchCriteriaId":"B3283CA0-78EA-4D53-92B4-B3DBF4BDB430"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.5.0","versionEndExcluding":"18.5.4","matchCriteriaId":"457DB333-60BE-44CD-A674-216AB658E14E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.5.0","versionEndExcluding":"18.5.4","matchCriteriaId":"910967DB-0A8C-4436-9D9E-37BD610E7367"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.6.0","versionEndExcluding":"18.6.2","matchCriteriaId":"919A2588-3EA1-4E15-B47E-61B3E14B2781"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.6.0","versionEndExcluding":"18.6.2","matchCriteriaId":"6343A083-3E1C-4551-B230-76CABC3FDD67"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2025/12/10/patch-release-gitlab-18-6-2-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/577975","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3317485","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-12734","sourceIdentifier":"cve@gitlab.com","published":"2025-12-11T08:15:51.110","lastModified":"2026-06-17T08:32:52.040","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.6 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to, under certain conditions, render content in dialogs to other users by injecting malicious HTML content into merge request titles."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.6","lessThan":"18.4.6","versionType":"semver","status":"affected"},{"version":"18.5","lessThan":"18.5.4","versionType":"semver","status":"affected"},{"version":"18.6","lessThan":"18.6.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N","baseScore":3.5,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-12-11T14:42:27.723320Z","id":"CVE-2025-12734","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-116"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.6.0","versionEndExcluding":"18.4.6","matchCriteriaId":"C612892E-D034-429C-BE38-2D7DDFA62F02"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.6.0","versionEndExcluding":"18.4.6","matchCriteriaId":"43AAB62F-9E83-4BBD-85C1-37F85DAA5AC9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.5.0","versionEndExcluding":"18.5.4","matchCriteriaId":"457DB333-60BE-44CD-A674-216AB658E14E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.5.0","versionEndExcluding":"18.5.4","matchCriteriaId":"910967DB-0A8C-4436-9D9E-37BD610E7367"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.6.0","versionEndExcluding":"18.6.2","matchCriteriaId":"919A2588-3EA1-4E15-B47E-61B3E14B2781"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.6.0","versionEndExcluding":"18.6.2","matchCriteriaId":"6343A083-3E1C-4551-B230-76CABC3FDD67"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2025/12/10/patch-release-gitlab-18-6-2-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/579573","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3379381","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-10569","sourceIdentifier":"cve@gitlab.com","published":"2026-01-09T10:15:44.590","lastModified":"2026-06-17T08:28:32.353","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to create a denial of service condition by providing crafted responses to external API calls."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab CE/EE que afecta a todas las versiones a partir de la 8.3 y anteriores a la 18.5.5, a partir de la 18.6 y anteriores a la 18.6.3, y a partir de la 18.7 y anteriores a la 18.7.1, que podría haber permitido a un usuario autenticado crear una condición de denegación de servicio al proporcionar respuestas manipuladas a llamadas a la API externa."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"8.3","lessThan":"18.5.5","versionType":"semver","status":"affected"},{"version":"18.6","lessThan":"18.6.3","versionType":"semver","status":"affected"},{"version":"18.7","lessThan":"18.7.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-01-09T19:06:16.538778Z","id":"CVE-2025-10569","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.3.0","versionEndExcluding":"18.5.5","matchCriteriaId":"3999AD0C-23F6-4C47-987A-29CB856B2FF6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.3.0","versionEndExcluding":"18.5.5","matchCriteriaId":"550B88BE-89ED-4609-8BAC-AAB7F33E46A3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.6.0","versionEndExcluding":"18.6.3","matchCriteriaId":"2B9B2E1D-016E-45CF-80CD-7CC77A5B5576"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.6.0","versionEndExcluding":"18.6.3","matchCriteriaId":"75013646-70F2-467E-B79E-9301338AB853"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.7.0:*:*:*:community:*:*:*","matchCriteriaId":"D5EB2CAA-6B1C-4780-B872-82947A098FED"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.7.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"9B955F55-086B-4EDF-A9E6-5B9E68600494"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/01/07/patch-release-gitlab-18-7-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/570528","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3284689","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-11246","sourceIdentifier":"cve@gitlab.com","published":"2026-01-09T10:15:44.813","lastModified":"2026-06-17T08:29:56.683","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.4 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user with specific permissions to remove all project runners from unrelated projects by manipulating GraphQL runner associations."},{"lang":"es","value":"GitLab ha subsanado un problema en GitLab CE/EE que afectaba a todas las versiones desde la 15.4 anteriores a la 18.5.5, la 18.6 anteriores a la 18.6.3, y la 18.7 anteriores a la 18.7.1 que podría haber permitido a un usuario autenticado con permisos específicos eliminar todos los runners de proyecto de proyectos no relacionados manipulando las asociaciones de runners de GraphQL."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.4","lessThan":"18.5.5","versionType":"semver","status":"affected"},{"version":"18.6","lessThan":"18.6.3","versionType":"semver","status":"affected"},{"version":"18.7","lessThan":"18.7.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-01-09T19:13:10.460170Z","id":"CVE-2025-11246","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1220"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.4.0","versionEndExcluding":"18.5.5","matchCriteriaId":"0B94F85D-1CEF-4FD8-83C5-C615CA06E89E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.4.0","versionEndExcluding":"18.5.5","matchCriteriaId":"710E0DA4-F7DB-45E7-AE69-62BCB86DC5EA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.6.0","versionEndExcluding":"18.6.3","matchCriteriaId":"2B9B2E1D-016E-45CF-80CD-7CC77A5B5576"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.6.0","versionEndExcluding":"18.6.3","matchCriteriaId":"75013646-70F2-467E-B79E-9301338AB853"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.7.0:*:*:*:community:*:*:*","matchCriteriaId":"D5EB2CAA-6B1C-4780-B872-82947A098FED"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.7.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"9B955F55-086B-4EDF-A9E6-5B9E68600494"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/01/07/patch-release-gitlab-18-7-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/573728","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3292475","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-13761","sourceIdentifier":"cve@gitlab.com","published":"2026-01-09T10:15:45.280","lastModified":"2026-07-15T02:17:16.040","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an unauthenticated user to execute arbitrary code in the context of an  authenticated user's browser by convincing the legitimate user to visit a specially crafted webpage."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab CE/EE que afectaba a todas las versiones desde la 18.6 antes de la 18.6.3, y la 18.7 antes de la 18.7.1 que podría haber permitido a un usuario no autenticado ejecutar código arbitrario en el contexto del navegador de un usuario autenticado al convencer al usuario legítimo de visitar una página web especialmente diseñada."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.6","lessThan":"18.6.3","versionType":"semver","status":"affected"},{"version":"18.7","lessThan":"18.7.1","versionType":"semver","status":"affected"}]}]},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","affectedData":[{"vendor":"Red Hat","product":"OpenShift Pipelines","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-pipelines/pipelines-console-plugin-rhel9","cpes":["cpe:/a:redhat:openshift_pipelines:1"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift4/ose-console","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift4/ose-console-rhel9","cpes":["cpe:/a:redhat:openshift:4"]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N","baseScore":8.0,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","baseScore":9.6,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":6.0},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N","baseScore":8.0,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":5.8}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-01-10T04:55:47.594734Z","id":"CVE-2025-13761","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.6.0","versionEndExcluding":"18.6.3","matchCriteriaId":"2B9B2E1D-016E-45CF-80CD-7CC77A5B5576"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.6.0","versionEndExcluding":"18.6.3","matchCriteriaId":"75013646-70F2-467E-B79E-9301338AB853"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.7.0:*:*:*:community:*:*:*","matchCriteriaId":"D5EB2CAA-6B1C-4780-B872-82947A098FED"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.7.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"9B955F55-086B-4EDF-A9E6-5B9E68600494"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/01/07/patch-release-gitlab-18-7-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/582237","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3441368","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://access.redhat.com/security/cve/CVE-2025-13761","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2428218","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-13761.json","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}]}},{"cve":{"id":"CVE-2025-13772","sourceIdentifier":"cve@gitlab.com","published":"2026-01-09T10:15:45.450","lastModified":"2026-07-15T02:17:16.253","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to access and utilize AI model settings from unauthorized namespaces by manipulating namespace identifiers in API requests."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab EE que afectaba a todas las versiones desde la 18.4 antes de la 18.5.5, la 18.6 antes de la 18.6.3 y la 18.7 antes de la 18.7.1 que podría haber permitido a un usuario autenticado acceder y utilizar la configuración del modelo de IA desde espacios de nombres no autorizados manipulando identificadores de espacios de nombres en solicitudes de API."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.4","lessThan":"18.5.5","versionType":"semver","status":"affected"},{"version":"18.6","lessThan":"18.6.3","versionType":"semver","status":"affected"},{"version":"18.7","lessThan":"18.7.1","versionType":"semver","status":"affected"}]}]},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","affectedData":[{"vendor":"Red Hat","product":"OpenShift Pipelines","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-pipelines/pipelines-console-plugin-rhel9","cpes":["cpe:/a:redhat:openshift_pipelines:1"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift4/ose-console","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift4/ose-console-rhel9","cpes":["cpe:/a:redhat:openshift:4"]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":4.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":4.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-01-09T19:13:05.972319Z","id":"CVE-2025-13772","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.4.0","versionEndExcluding":"18.5.5","matchCriteriaId":"285DA1C9-F1D1-49F5-9C2A-41E6798DFD44"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.6.0","versionEndExcluding":"18.6.3","matchCriteriaId":"75013646-70F2-467E-B79E-9301338AB853"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.7.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"9B955F55-086B-4EDF-A9E6-5B9E68600494"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/01/07/patch-release-gitlab-18-7-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/581268","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://access.redhat.com/security/cve/CVE-2025-13772","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2428224","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-13772.json","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}]}},{"cve":{"id":"CVE-2025-13781","sourceIdentifier":"cve@gitlab.com","published":"2026-01-09T10:15:45.613","lastModified":"2026-06-17T08:34:44.610","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 18.5 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to modify instance-wide AI feature provider settings by exploiting missing authorization checks in GraphQL mutations."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab EE que afecta a todas las versiones desde la 18.5 antes de la 18.5.5, la 18.6 antes de la 18.6.3, y la 18.7 antes de la 18.7.1 que podría haber permitido a un usuario autenticado modificar la configuración del proveedor de características de IA a nivel de instancia explotando la falta de comprobaciones de autorización en las mutaciones de GraphQL."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.5","lessThan":"18.5.5","versionType":"semver","status":"affected"},{"version":"18.6","lessThan":"18.6.3","versionType":"semver","status":"affected"},{"version":"18.7","lessThan":"18.7.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-01-09T19:12:40.834326Z","id":"CVE-2025-13781","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.5.0","versionEndExcluding":"18.5.5","matchCriteriaId":"722A4635-08B2-4A53-903A-E9D2A670B5FB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.6.0","versionEndExcluding":"18.6.3","matchCriteriaId":"75013646-70F2-467E-B79E-9301338AB853"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.7.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"9B955F55-086B-4EDF-A9E6-5B9E68600494"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/01/07/patch-release-gitlab-18-7-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/578756","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3400940","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-3950","sourceIdentifier":"cve@gitlab.com","published":"2026-01-09T10:15:46.310","lastModified":"2026-06-17T09:20:58.977","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.3 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed a user to leak certain information by referencing specially crafted images that bypass asset proxy protection."},{"lang":"es","value":"GitLab ha solucionado un problema en GitLab CE/EE que afectaba a todas las versiones desde la 10.3 anteriores a la 18.5.5, la 18.6 anteriores a la 18.6.3 y la 18.7 anteriores a la 18.7.1 que podría haber permitido a un usuario filtrar cierta información al referenciar imágenes especialmente diseñadas que eluden la protección de proxy de activos."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"10.3","lessThan":"18.5.5","versionType":"semver","status":"affected"},{"version":"18.6","lessThan":"18.6.3","versionType":"semver","status":"affected"},{"version":"18.7","lessThan":"18.7.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N","baseScore":3.5,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-01-09T14:39:11.325169Z","id":"CVE-2025-3950","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-359"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.3.0","versionEndExcluding":"18.5.5","matchCriteriaId":"B364C44F-E8AE-46C6-AFF9-344B61B531D4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.3.0","versionEndExcluding":"18.5.5","matchCriteriaId":"23F20E77-0F2B-4AD3-9186-9E25B96B7796"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.6.0","versionEndExcluding":"18.6.3","matchCriteriaId":"2B9B2E1D-016E-45CF-80CD-7CC77A5B5576"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.6.0","versionEndExcluding":"18.6.3","matchCriteriaId":"75013646-70F2-467E-B79E-9301338AB853"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.7.0","versionEndExcluding":"18.7.1","matchCriteriaId":"4FB8EB8C-1F4F-47E6-B1EB-5686613B75F9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.7.0","versionEndExcluding":"18.7.1","matchCriteriaId":"C43A7C18-65D0-4731-88A8-6BF6A33A1435"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/01/07/patch-release-gitlab-18-7-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/537697","source":"cve@gitlab.com","tags":["Broken Link","Issue Tracking"]},{"url":"https://hackerone.com/reports/3106477","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-9222","sourceIdentifier":"cve@gitlab.com","published":"2026-01-09T10:15:47.037","lastModified":"2026-07-15T02:17:54.580","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2.2 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to achieve stored cross-site scripting by exploiting GitLab Flavored Markdown."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab CE/EE que afectaba a todas las versiones desde la 18.2.2 antes de la 18.5.5, la 18.6 antes de la 18.6.3 y la 18.7 antes de la 18.7.1 que podría haber permitido a un usuario autenticado lograr cross-site scripting almacenado explotando GitLab Flavored Markdown."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.2.2","lessThan":"18.5.5","versionType":"semver","status":"affected"},{"version":"18.6","lessThan":"18.6.3","versionType":"semver","status":"affected"},{"version":"18.7","lessThan":"18.7.1","versionType":"semver","status":"affected"}]}]},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","affectedData":[{"vendor":"Red Hat","product":"OpenShift Pipelines","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-pipelines/pipelines-console-plugin-rhel9","cpes":["cpe:/a:redhat:openshift_pipelines:1"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift4/ose-console","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift4/ose-console-rhel9","cpes":["cpe:/a:redhat:openshift:4"]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":5.8}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-01-10T04:55:48.752414Z","id":"CVE-2025-9222","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.2.2","versionEndExcluding":"18.5.5","matchCriteriaId":"B56DB4CC-3DB3-42BB-B205-1DF5A9A6F9B6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.2.2","versionEndExcluding":"18.5.5","matchCriteriaId":"7683DD33-0FA1-46A0-ACB7-4F2309FCB2E7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.6.0","versionEndExcluding":"18.6.3","matchCriteriaId":"2B9B2E1D-016E-45CF-80CD-7CC77A5B5576"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.6.0","versionEndExcluding":"18.6.3","matchCriteriaId":"75013646-70F2-467E-B79E-9301338AB853"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.7.0:*:*:*:community:*:*:*","matchCriteriaId":"D5EB2CAA-6B1C-4780-B872-82947A098FED"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.7.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"9B955F55-086B-4EDF-A9E6-5B9E68600494"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/01/07/patch-release-gitlab-18-7-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/562561","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3297483","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://access.redhat.com/security/cve/CVE-2025-9222","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2428222","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-9222.json","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}]}},{"cve":{"id":"CVE-2025-11224","sourceIdentifier":"cve@gitlab.com","published":"2026-01-14T19:16:40.943","lastModified":"2026-06-17T08:29:53.340","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.10 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated user to execute stored cross-site scripting through improper input validation in the Kubernetes proxy functionality."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab CE/EE que afectaba a todas las versiones desde la 15.10 anterior a la 18.3.6, la 18.4 anterior a la 18.4.4, y la 18.5 anterior a la 18.5.2 que podría haber permitido a un usuario autenticado ejecutar cross-site scripting almacenado mediante una validación de entrada incorrecta en la funcionalidad de proxy de Kubernetes."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.10","lessThan":"18.3.6","versionType":"semver","status":"affected"},{"version":"18.4","lessThan":"18.4.4","versionType":"semver","status":"affected"},{"version":"18.5","lessThan":"18.5.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":7.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.3,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-01-15T04:56:07.486786Z","id":"CVE-2025-11224","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.10.0","versionEndExcluding":"18.3.6","matchCriteriaId":"46F0D894-F6E6-4E6B-A171-C520C019C033"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.10.0","versionEndExcluding":"18.3.6","matchCriteriaId":"65019DB4-32C0-49D1-BFE0-5A91FE346ED8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.4.0","versionEndExcluding":"18.4.4","matchCriteriaId":"36824F52-C9A0-4FB3-91F3-05593E3551E8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.4.0","versionEndExcluding":"18.4.4","matchCriteriaId":"6D0A238D-1278-4D05-86F5-4C323E0CFE36"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.5.0","versionEndExcluding":"18.5.2","matchCriteriaId":"7E85D20B-EEE1-4CC9-B50A-4040972287D8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.5.0","versionEndExcluding":"18.5.2","matchCriteriaId":"B2A3A57F-C750-4C92-8C2B-C5FCF1D70F4F"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2025/11/12/patch-release-gitlab-18-5-2-released/","source":"cve@gitlab.com","tags":["Patch","Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/573223","source":"cve@gitlab.com","tags":["Broken Link","Issue Tracking"]},{"url":"https://hackerone.com/reports/3277291","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-13335","sourceIdentifier":"cve@gitlab.com","published":"2026-01-22T10:16:06.480","lastModified":"2026-06-17T08:33:57.180","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that under certain circumstances could have allowed an authenticated user to create a denial of service condition by configuring malformed Wiki documents that bypass cycle detection."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab CE/EE que afecta a todas las versiones desde la 17.1 anterior a la 18.6.4, la 18.7 anterior a la 18.7.2 y la 18.8 anterior a la 18.8.2 que bajo ciertas circunstancias podría haber permitido a un usuario autenticado crear una condición de denegación de servicio al configurar documentos Wiki malformados que eluden la detección de ciclos."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.1","lessThan":"18.6.4","versionType":"semver","status":"affected"},{"version":"18.7","lessThan":"18.7.2","versionType":"semver","status":"affected"},{"version":"18.8","lessThan":"18.8.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-01-22T14:12:23.821798Z","id":"CVE-2025-13335","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-835"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"18.6.4","matchCriteriaId":"3267E7C6-D6A7-4E5C-A533-70B5527BC509"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"18.6.4","matchCriteriaId":"6DE836E5-E9D9-4C53-86E6-8369FBC84278"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.7.0","versionEndExcluding":"18.7.2","matchCriteriaId":"7E36C974-4A52-424A-8758-E45B750C013E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.7.0","versionEndExcluding":"18.7.2","matchCriteriaId":"F71560B5-1000-45F1-8A5C-078D6C3D03E6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.2","matchCriteriaId":"582D13A9-DEEE-4E3F-BFC5-61F270C99B86"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.2","matchCriteriaId":"760BBB79-D5BD-4871-8522-3C2C7E65767B"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/01/21/patch-release-gitlab-18-8-2-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/581060","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3418023","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-13927","sourceIdentifier":"cve@gitlab.com","published":"2026-01-22T15:16:47.453","lastModified":"2026-06-17T08:34:59.697","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.9 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could have allowed an unauthenticated user to create a denial of service condition by sending crafted requests with malformed authentication data."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab CE/EE que afecta a todas las versiones desde la 11.9 (anteriores a la 18.6.4), las versiones 18.7 (anteriores a la 18.7.2) y las versiones 18.8 (anteriores a la 18.8.2) que podría haber permitido a un usuario no autenticado crear una condición de denegación de servicio mediante el envío de solicitudes especialmente diseñadas con datos de autenticación malformados."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"11.9","lessThan":"18.6.4","versionType":"semver","status":"affected"},{"version":"18.7","lessThan":"18.7.2","versionType":"semver","status":"affected"},{"version":"18.8","lessThan":"18.8.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-01-22T15:27:18.219798Z","id":"CVE-2025-13927","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.9.0","versionEndExcluding":"18.6.4","matchCriteriaId":"E8BB9DB9-9C9A-450E-A8B6-2C01F9DEB420"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.9.0","versionEndExcluding":"18.6.4","matchCriteriaId":"0A2FCA01-DEC6-402D-9738-9F157067AE88"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.7.0","versionEndExcluding":"18.7.2","matchCriteriaId":"7E36C974-4A52-424A-8758-E45B750C013E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.7.0","versionEndExcluding":"18.7.2","matchCriteriaId":"F71560B5-1000-45F1-8A5C-078D6C3D03E6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.2","matchCriteriaId":"582D13A9-DEEE-4E3F-BFC5-61F270C99B86"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.2","matchCriteriaId":"760BBB79-D5BD-4871-8522-3C2C7E65767B"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/01/21/patch-release-gitlab-18-8-2-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/582737","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3439683","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-13928","sourceIdentifier":"cve@gitlab.com","published":"2026-01-22T15:16:47.603","lastModified":"2026-06-17T08:34:59.807","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.7 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could have allowed an unauthenticated user to cause a denial of service condition by exploiting incorrect authorization validation in API endpoints."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab CE/EE que afectaba a todas las versiones desde la 17.7 antes de la 18.6.4, la 18.7 antes de la 18.7.2 y la 18.8 antes de la 18.8.2, el cual podría haber permitido a un usuario no autenticado causar una condición de denegación de servicio al explotar una validación de autorización incorrecta en los puntos finales de la API."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.7","lessThan":"18.6.4","versionType":"semver","status":"affected"},{"version":"18.7","lessThan":"18.7.2","versionType":"semver","status":"affected"},{"version":"18.8","lessThan":"18.8.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-01-22T15:26:29.067732Z","id":"CVE-2025-13928","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.7.0","versionEndExcluding":"18.6.4","matchCriteriaId":"53C19D00-8774-4DB1-8AFB-8C9596DC70F3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.7.0","versionEndExcluding":"18.6.4","matchCriteriaId":"F87D62E6-4EB4-4E17-9CEA-E23219785C8E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.7.0","versionEndExcluding":"18.7.2","matchCriteriaId":"7E36C974-4A52-424A-8758-E45B750C013E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.7.0","versionEndExcluding":"18.7.2","matchCriteriaId":"F71560B5-1000-45F1-8A5C-078D6C3D03E6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.2","matchCriteriaId":"582D13A9-DEEE-4E3F-BFC5-61F270C99B86"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.2","matchCriteriaId":"760BBB79-D5BD-4871-8522-3C2C7E65767B"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/01/21/patch-release-gitlab-18-8-2-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/582736","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3439441","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-0723","sourceIdentifier":"cve@gitlab.com","published":"2026-01-22T15:16:50.030","lastModified":"2026-06-17T10:11:15.997","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could have allowed an individual with existing knowledge of a victim's credential ID to bypass two-factor authentication by submitting forged device responses."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab CE/EE que afecta a todas las versiones desde la 18.6 anterior a la 18.6.4, la 18.7 anterior a la 18.7.2, y la 18.8 anterior a la 18.8.2 que podría haber permitido a un individuo con conocimiento existente del ID de credencial de una víctima omitir la autenticación de dos factores al enviar respuestas de dispositivo falsificadas."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.6","lessThan":"18.6.4","versionType":"semver","status":"affected"},{"version":"18.7","lessThan":"18.7.2","versionType":"semver","status":"affected"},{"version":"18.8","lessThan":"18.8.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","baseScore":7.4,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-01-23T04:55:20.746057Z","id":"CVE-2026-0723","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-252"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.6.0","versionEndExcluding":"18.6.4","matchCriteriaId":"DCFE3D48-36BA-44C2-8F0D-38CFDB1A366D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.6.0","versionEndExcluding":"18.6.4","matchCriteriaId":"1ED8B99B-2F16-48A4-A538-7FE3A8DBF3D3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.7.0","versionEndExcluding":"18.7.2","matchCriteriaId":"7E36C974-4A52-424A-8758-E45B750C013E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.7.0","versionEndExcluding":"18.7.2","matchCriteriaId":"F71560B5-1000-45F1-8A5C-078D6C3D03E6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.2","matchCriteriaId":"582D13A9-DEEE-4E3F-BFC5-61F270C99B86"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.2","matchCriteriaId":"760BBB79-D5BD-4871-8522-3C2C7E65767B"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/01/21/patch-release-gitlab-18-8-2-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/585333","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3476052","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-1102","sourceIdentifier":"cve@gitlab.com","published":"2026-01-22T15:16:50.227","lastModified":"2026-06-17T10:14:59.740","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.3 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could have allowed an unauthenticated user to create a denial of service condition by sending repeated malformed SSH authentication requests."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab CE/EE que afecta a todas las versiones desde la 12.3 anterior a la 18.6.4, la 18.7 anterior a la 18.7.2, y la 18.8 anterior a la 18.8.2 que podría haber permitido a un usuario no autenticado crear una condición de denegación de servicio enviando repetidas solicitudes de autenticación SSH malformadas."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"12.3","lessThan":"18.6.4","versionType":"semver","status":"affected"},{"version":"18.7","lessThan":"18.7.2","versionType":"semver","status":"affected"},{"version":"18.8","lessThan":"18.8.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-01-22T15:29:28.337756Z","id":"CVE-2026-1102","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.3.0","versionEndExcluding":"18.6.4","matchCriteriaId":"D2396DAD-8F31-4CD8-83AB-B8B862BAB422"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.3.0","versionEndExcluding":"18.6.4","matchCriteriaId":"48A3D878-F753-4137-8CAB-8CD570DC000D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.7.0","versionEndExcluding":"18.7.2","matchCriteriaId":"7E36C974-4A52-424A-8758-E45B750C013E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.7.0","versionEndExcluding":"18.7.2","matchCriteriaId":"F71560B5-1000-45F1-8A5C-078D6C3D03E6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.2","matchCriteriaId":"582D13A9-DEEE-4E3F-BFC5-61F270C99B86"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.2","matchCriteriaId":"760BBB79-D5BD-4871-8522-3C2C7E65767B"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/01/21/patch-release-gitlab-18-8-2-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/579746","source":"cve@gitlab.com","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2026-1751","sourceIdentifier":"cve@gitlab.com","published":"2026-02-02T10:16:06.693","lastModified":"2026-06-17T10:16:27.357","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability has been discovered in GitLab CE/EE affecting all versions starting with 16.8 before 18.5.0 that could have allowed unauthorized edits to merge request approval rules under certain conditions."},{"lang":"es","value":"Se ha descubierto una vulnerabilidad en GitLab CE/EE que afecta a todas las versiones a partir de la 16.8 y anteriores a la 18.5.0 que podría haber permitido ediciones no autorizadas en las reglas de aprobación de solicitudes de fusión bajo ciertas condiciones."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.8","lessThan":"18.5.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N","baseScore":3.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-02-02T13:24:03.135088Z","id":"CVE-2026-1751","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.8.0","versionEndExcluding":"18.5.0","matchCriteriaId":"B89CF163-DA6E-40E4-9D46-FE5B05B208A9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.8.0","versionEndExcluding":"18.5.0","matchCriteriaId":"1BF55EB1-AFA1-45BD-B17B-127F49377C54"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/519340","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/2980839","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-12073","sourceIdentifier":"cve@gitlab.com","published":"2026-02-11T12:16:02.653","lastModified":"2026-06-17T08:31:40.253","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.0 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions, could have allowed an authenticated user to perform server-side request forgery against internal services by bypassing protections in the Git repository import functionality."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab CE/EE que afecta a todas las versiones desde la 18.0 anterior a la 18.6.6, la 18.7 anterior a la 18.7.4 y la 18.8 anterior a la 18.8.4 que, bajo ciertas condiciones, podría haber permitido a un usuario autenticado realizar falsificación de petición del lado del servidor contra servicios internos al eludir las protecciones en la funcionalidad de importación de repositorios Git."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.0","lessThan":"18.6.6","versionType":"semver","status":"affected"},{"version":"18.7","lessThan":"18.7.4","versionType":"semver","status":"affected"},{"version":"18.8","lessThan":"18.8.4","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-02-11T15:14:41.464783Z","id":"CVE-2025-12073","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.0.0","versionEndExcluding":"18.6.6","matchCriteriaId":"A6995F46-E7F4-4CD7-8BE9-97521A614682"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.0.0","versionEndExcluding":"18.6.6","matchCriteriaId":"D31A584F-34EF-4754-9119-0EF1E11D9E3B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.7.0","versionEndExcluding":"18.7.4","matchCriteriaId":"EB4484C1-2D91-48A6-B396-4F16DC598828"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.7.0","versionEndExcluding":"18.7.4","matchCriteriaId":"DA7B13F4-05B9-436E-A1DC-6C65DB7B44FE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.4","matchCriteriaId":"BCEB62DB-0D85-4A21-99C4-6235CA97A795"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.4","matchCriteriaId":"6D01D64A-0619-427D-B351-4101FC257674"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/02/10/patch-release-gitlab-18-8-4-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/578091","source":"cve@gitlab.com","tags":["Broken Link","Issue Tracking"]},{"url":"https://hackerone.com/reports/3314987","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-12575","sourceIdentifier":"cve@gitlab.com","published":"2026-02-11T12:16:02.833","lastModified":"2026-06-17T08:32:36.177","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 18.0 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user with certain permissions to make unauthorized requests to internal network services through the GitLab server."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab EE que afecta a todas las versiones desde la 18.0 antes de la 18.6.6, la 18.7 antes de la 18.7.4, y la 18.8 antes de la 18.8.4 que, bajo ciertas condiciones, podría haber permitido a un usuario autenticado con ciertos permisos realizar solicitudes no autorizadas a servicios de red internos a través del servidor de GitLab."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.0","lessThan":"18.6.6","versionType":"semver","status":"affected"},{"version":"18.7","lessThan":"18.7.4","versionType":"semver","status":"affected"},{"version":"18.8","lessThan":"18.8.4","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-02-11T15:15:19.004878Z","id":"CVE-2025-12575","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.0.0","versionEndExcluding":"18.6.6","matchCriteriaId":"D31A584F-34EF-4754-9119-0EF1E11D9E3B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.7.0","versionEndExcluding":"18.7.4","matchCriteriaId":"DA7B13F4-05B9-436E-A1DC-6C65DB7B44FE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.4","matchCriteriaId":"6D01D64A-0619-427D-B351-4101FC257674"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/02/10/patch-release-gitlab-18-8-4-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/579171","source":"cve@gitlab.com","tags":["Broken Link","Issue Tracking"]},{"url":"https://hackerone.com/reports/3397752","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-14560","sourceIdentifier":"cve@gitlab.com","published":"2026-02-11T12:16:02.980","lastModified":"2026-06-17T08:36:10.440","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to perform unauthorized actions on behalf of another user by injecting malicious content into vulnerability code flow."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab CE/EE que afecta a todas las versiones desde la 17.1 antes de la 18.6.6, la 18.7 antes de la 18.7.4, y la 18.8 antes de la 18.8.4 que, bajo ciertas condiciones, podría haber permitido a un usuario autenticado realizar acciones no autorizadas en nombre de otro usuario mediante la inyección de contenido malicioso en el flujo de código de vulnerabilidad."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.1","lessThan":"18.6.6","versionType":"semver","status":"affected"},{"version":"18.7","lessThan":"18.7.4","versionType":"semver","status":"affected"},{"version":"18.8","lessThan":"18.8.4","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-02-12T04:55:14.485001Z","id":"CVE-2025-14560","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"18.6.6","matchCriteriaId":"4A5FF9F9-8610-4F08-A465-D96C0B8701D3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"18.6.6","matchCriteriaId":"24D755DC-3644-4F4C-9C7A-AAD65953B42C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.7.0","versionEndExcluding":"18.7.4","matchCriteriaId":"EB4484C1-2D91-48A6-B396-4F16DC598828"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.7.0","versionEndExcluding":"18.7.4","matchCriteriaId":"DA7B13F4-05B9-436E-A1DC-6C65DB7B44FE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.4","matchCriteriaId":"BCEB62DB-0D85-4A21-99C4-6235CA97A795"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.4","matchCriteriaId":"6D01D64A-0619-427D-B351-4101FC257674"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/02/10/patch-release-gitlab-18-8-4-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/583861","source":"cve@gitlab.com","tags":["Broken Link","Issue Tracking"]},{"url":"https://hackerone.com/reports/3461083","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-14592","sourceIdentifier":"cve@gitlab.com","published":"2026-02-11T12:16:03.123","lastModified":"2026-06-17T08:36:14.073","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to perform unauthorized operations by submitting GraphQL mutations through the GLQL API endpoint."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab CE/EE que afecta a todas las versiones desde la 18.6 anterior a la 18.6.6, la 18.7 anterior a la 18.7.4, y la 18.8 anterior a la 18.8.4 que, bajo ciertas condiciones, podría haber permitido a un usuario autenticado realizar operaciones no autorizadas al enviar mutaciones GraphQL a través del endpoint de la API GLQL."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.6","lessThan":"18.6.6","versionType":"semver","status":"affected"},{"version":"18.7","lessThan":"18.7.4","versionType":"semver","status":"affected"},{"version":"18.8","lessThan":"18.8.4","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":3.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-02-11T15:17:57.751398Z","id":"CVE-2025-14592","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.6.0","versionEndExcluding":"18.6.6","matchCriteriaId":"C3F7C278-FF2A-49DE-AE73-6B94C9833230"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.6.0","versionEndExcluding":"18.6.6","matchCriteriaId":"22C1B676-A5D2-40E7-8399-CFB9BCEEDE92"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.7.0","versionEndExcluding":"18.7.4","matchCriteriaId":"EB4484C1-2D91-48A6-B396-4F16DC598828"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.7.0","versionEndExcluding":"18.7.4","matchCriteriaId":"DA7B13F4-05B9-436E-A1DC-6C65DB7B44FE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.4","matchCriteriaId":"BCEB62DB-0D85-4A21-99C4-6235CA97A795"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.4","matchCriteriaId":"6D01D64A-0619-427D-B351-4101FC257674"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/02/10/patch-release-gitlab-18-8-4-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/583961","source":"cve@gitlab.com","tags":["Broken Link","Issue Tracking"]},{"url":"https://hackerone.com/reports/3451435","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-14594","sourceIdentifier":"cve@gitlab.com","published":"2026-02-11T12:16:03.267","lastModified":"2026-06-17T08:36:14.293","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.11 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to view certain pipeline values by querying the API."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab CE/EE que afecta a todas las versiones desde la 17.11 anterior a la 18.6.6, la 18.7 anterior a la 18.7.4 y la 18.8 anterior a la 18.8.4 que, bajo ciertas condiciones, podría haber permitido a un usuario autenticado ver ciertos valores de pipeline consultando la API."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.11","lessThan":"18.6.6","versionType":"semver","status":"affected"},{"version":"18.7","lessThan":"18.7.4","versionType":"semver","status":"affected"},{"version":"18.8","lessThan":"18.8.4","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N","baseScore":3.5,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-02-11T15:17:08.503125Z","id":"CVE-2025-14594","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-639"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.11.0","versionEndExcluding":"18.6.6","matchCriteriaId":"AF06A284-B383-4743-82AD-86423E1BD046"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.11.0","versionEndExcluding":"18.6.6","matchCriteriaId":"5B0B8E2D-A5C9-42C6-B227-78CAF2A37BCC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.7.0","versionEndExcluding":"18.7.4","matchCriteriaId":"EB4484C1-2D91-48A6-B396-4F16DC598828"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.7.0","versionEndExcluding":"18.7.4","matchCriteriaId":"DA7B13F4-05B9-436E-A1DC-6C65DB7B44FE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.4","matchCriteriaId":"BCEB62DB-0D85-4A21-99C4-6235CA97A795"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.4","matchCriteriaId":"6D01D64A-0619-427D-B351-4101FC257674"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/02/10/patch-release-gitlab-18-8-4-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/583967","source":"cve@gitlab.com","tags":["Broken Link","Issue Tracking"]},{"url":"https://hackerone.com/reports/3457591","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-7659","sourceIdentifier":"cve@gitlab.com","published":"2026-02-11T12:16:03.533","lastModified":"2026-06-17T10:05:25.690","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an unauthenticated user to steal tokens and access private repositories by abusing incomplete validation in the Web IDE."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab CE/EE que afectaba a todas las versiones desde la 18.2 anteriores a la 18.6.6, la 18.7 anteriores a la 18.7.4, y la 18.8 anteriores a la 18.8.4 que podría haber permitido a un usuario no autenticado robar tokens y acceder a repositorios privados al abusar de una validación incompleta en el Web IDE."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.2","lessThan":"18.6.6","versionType":"semver","status":"affected"},{"version":"18.7","lessThan":"18.7.4","versionType":"semver","status":"affected"},{"version":"18.8","lessThan":"18.8.4","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N","baseScore":8.0,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-02-12T04:55:15.349180Z","id":"CVE-2025-7659","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-346"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"18.6.6","matchCriteriaId":"4491F6C1-0D9C-4BD1-A438-676C0D9F5A87"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"18.6.6","matchCriteriaId":"E22ACD3B-62F8-48A5-B6F9-F0A232B62DA7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.7.0","versionEndExcluding":"18.7.4","matchCriteriaId":"EB4484C1-2D91-48A6-B396-4F16DC598828"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.7.0","versionEndExcluding":"18.7.4","matchCriteriaId":"DA7B13F4-05B9-436E-A1DC-6C65DB7B44FE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.4","matchCriteriaId":"BCEB62DB-0D85-4A21-99C4-6235CA97A795"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.4","matchCriteriaId":"6D01D64A-0619-427D-B351-4101FC257674"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/02/10/patch-release-gitlab-18-8-4-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/555440","source":"cve@gitlab.com","tags":["Broken Link","Issue Tracking"]},{"url":"https://hackerone.com/reports/3234976","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-8099","sourceIdentifier":"cve@gitlab.com","published":"2026-02-11T12:16:03.687","lastModified":"2026-06-17T10:06:18.297","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.8 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions, could have allowed an unauthenticated user to cause denial of service by sending repeated GraphQL queries."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab CE/EE que afecta a todas las versiones desde la 10.8 anterior a la 18.6.6, la 18.7 anterior a la 18.7.4, y la 18.8 anterior a la 18.8.4 que, bajo ciertas condiciones, podría haber permitido a un usuario no autenticado causar denegación de servicio mediante el envío de consultas GraphQL repetidas."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"10.8","lessThan":"18.6.6","versionType":"semver","status":"affected"},{"version":"18.7","lessThan":"18.7.4","versionType":"semver","status":"affected"},{"version":"18.8","lessThan":"18.8.4","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-02-11T15:14:00.732270Z","id":"CVE-2025-8099","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.8.0","versionEndExcluding":"18.6.6","matchCriteriaId":"B9C58B39-E105-46CB-BD1C-7C2E9AAA7131"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.8.0","versionEndExcluding":"18.6.6","matchCriteriaId":"E84B82CA-EFD2-44F6-9CDA-6F2BA1B5EC2E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.7.0","versionEndExcluding":"18.7.4","matchCriteriaId":"EB4484C1-2D91-48A6-B396-4F16DC598828"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.7.0","versionEndExcluding":"18.7.4","matchCriteriaId":"DA7B13F4-05B9-436E-A1DC-6C65DB7B44FE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.4","matchCriteriaId":"BCEB62DB-0D85-4A21-99C4-6235CA97A795"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.4","matchCriteriaId":"6D01D64A-0619-427D-B351-4101FC257674"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/02/10/patch-release-gitlab-18-8-4-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/557165","source":"cve@gitlab.com","tags":["Broken Link","Issue Tracking"]},{"url":"https://hackerone.com/reports/3240210","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-0595","sourceIdentifier":"cve@gitlab.com","published":"2026-02-11T12:16:03.830","lastModified":"2026-06-17T10:11:01.340","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.9 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to add unauthorized email addresses to victim accounts through HTML injection in test case titles."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab CE/EE que afecta a todas las versiones desde la 13.9 anteriores a la 18.6.6, la 18.7 anteriores a la 18.7.4, y la 18.8 anteriores a la 18.8.4 que, bajo ciertas condiciones, podría haber permitido a un usuario autenticado añadir direcciones de correo electrónico no autorizadas a cuentas de víctimas mediante inyección HTML en los títulos de los casos de prueba."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"13.9","lessThan":"18.6.6","versionType":"semver","status":"affected"},{"version":"18.7","lessThan":"18.7.4","versionType":"semver","status":"affected"},{"version":"18.8","lessThan":"18.8.4","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-02-12T04:55:13.715164Z","id":"CVE-2026-0595","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.9.0","versionEndExcluding":"18.6.6","matchCriteriaId":"BC9EE0EC-1D82-438C-B3DC-3AA8CDAC6AFB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.9.0","versionEndExcluding":"18.6.6","matchCriteriaId":"B9610056-FED6-4ED5-8830-06E56C125CFD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.7.0","versionEndExcluding":"18.7.4","matchCriteriaId":"EB4484C1-2D91-48A6-B396-4F16DC598828"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.7.0","versionEndExcluding":"18.7.4","matchCriteriaId":"DA7B13F4-05B9-436E-A1DC-6C65DB7B44FE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.4","matchCriteriaId":"BCEB62DB-0D85-4A21-99C4-6235CA97A795"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.4","matchCriteriaId":"6D01D64A-0619-427D-B351-4101FC257674"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/02/10/patch-release-gitlab-18-8-4-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/584975","source":"cve@gitlab.com","tags":["Broken Link","Issue Tracking"]},{"url":"https://hackerone.com/reports/3486862","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-0958","sourceIdentifier":"cve@gitlab.com","published":"2026-02-11T12:16:03.970","lastModified":"2026-06-17T10:11:41.333","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an unauthenticated user to cause denial of service through memory or CPU exhaustion by bypassing JSON validation middleware limits."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab CE/EE que afecta a todas las versiones desde la 18.4 antes de la 18.6.6, la 18.7 antes de la 18.7.4, y la 18.8 antes de la 18.8.4 que podría haber permitido a un usuario no autenticado causar denegación de servicio mediante el agotamiento de memoria o CPU al eludir los límites del middleware de validación JSON."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.4","lessThan":"18.6.6","versionType":"semver","status":"affected"},{"version":"18.7","lessThan":"18.7.4","versionType":"semver","status":"affected"},{"version":"18.8","lessThan":"18.8.4","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-02-11T15:19:34.582283Z","id":"CVE-2026-0958","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-436"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.4.0","versionEndExcluding":"18.6.6","matchCriteriaId":"88188F05-EAB5-43C6-8145-37B6842B8DDE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.4.0","versionEndExcluding":"18.6.6","matchCriteriaId":"9CB95D09-FBC9-4FBA-B7BA-88755C4FA18E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.7.0","versionEndExcluding":"18.7.4","matchCriteriaId":"EB4484C1-2D91-48A6-B396-4F16DC598828"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.7.0","versionEndExcluding":"18.7.4","matchCriteriaId":"DA7B13F4-05B9-436E-A1DC-6C65DB7B44FE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.4","matchCriteriaId":"BCEB62DB-0D85-4A21-99C4-6235CA97A795"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.4","matchCriteriaId":"6D01D64A-0619-427D-B351-4101FC257674"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/02/10/patch-release-gitlab-18-8-4-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/586202","source":"cve@gitlab.com","tags":["Broken Link","Issue Tracking"]},{"url":"https://hackerone.com/reports/3463363","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-1080","sourceIdentifier":"cve@gitlab.com","published":"2026-02-11T12:16:04.120","lastModified":"2026-06-17T10:14:57.687","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 16.7 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to access iteration data from private descendant groups by querying the iterations API endpoint."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab EE que afectaba a todas las versiones desde la 16.7 anterior a la 18.6.6, la 18.7 anterior a la 18.7.4, y la 18.8 anterior a la 18.8.4 que, bajo ciertas condiciones, podría haber permitido a un usuario autenticado acceder a datos de iteración de grupos descendientes privados al consultar el endpoint de la API de iteraciones."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.7","lessThan":"18.6.6","versionType":"semver","status":"affected"},{"version":"18.7","lessThan":"18.7.4","versionType":"semver","status":"affected"},{"version":"18.8","lessThan":"18.8.4","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-02-11T15:35:19.935747Z","id":"CVE-2026-1080","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-639"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.7.0","versionEndExcluding":"18.6.6","matchCriteriaId":"9C40909F-AEAD-4AC0-AD12-082D2E389042"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.7.0","versionEndExcluding":"18.7.4","matchCriteriaId":"DA7B13F4-05B9-436E-A1DC-6C65DB7B44FE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.4","matchCriteriaId":"6D01D64A-0619-427D-B351-4101FC257674"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/02/10/patch-release-gitlab-18-8-4-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/586477","source":"cve@gitlab.com","tags":["Broken Link","Issue Tracking"]},{"url":"https://hackerone.com/reports/3484568","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-1094","sourceIdentifier":"cve@gitlab.com","published":"2026-02-11T12:16:04.263","lastModified":"2026-06-17T10:14:59.030","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 18.8.4 that could have allowed an authenticated developer to hide specially crafted file changes from the WebUI."},{"lang":"es","value":"GitLab ha corregido un problema en GitLab CE/EE que afectaba a todas las versiones desde la 18.8 anteriores a la 18.8.4 que podría haber permitido a un desarrollador autenticado ocultar cambios de archivo especialmente diseñados desde la WebUI."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitaly:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.8","lessThan":"18.8.4","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N","baseScore":4.6,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-02-11T21:18:29.521757Z","id":"CVE-2026-1094","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1289"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.4","matchCriteriaId":"BCEB62DB-0D85-4A21-99C4-6235CA97A795"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.4","matchCriteriaId":"6D01D64A-0619-427D-B351-4101FC257674"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/02/10/patch-release-gitlab-18-8-4-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/586483","source":"cve@gitlab.com","tags":["Broken Link","Issue Tracking"]},{"url":"https://hackerone.com/reports/3502519","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-1282","sourceIdentifier":"cve@gitlab.com","published":"2026-02-11T12:16:04.403","lastModified":"2026-06-17T10:15:26.900","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an authenticated user to inject malicious content into project labels titles."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab CE/EE que afectaba a todas las versiones desde la 18.6 y anteriores a la 18.6.6, la 18.7 y anteriores a la 18.7.4, y la 18.8 y anteriores a la 18.8.4 que podría haber permitido a un usuario autenticado inyectar contenido malicioso en los títulos de las etiquetas de proyecto."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.6","lessThan":"18.6.6","versionType":"semver","status":"affected"},{"version":"18.7","lessThan":"18.7.4","versionType":"semver","status":"affected"},{"version":"18.8","lessThan":"18.8.4","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N","baseScore":3.5,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-02-11T21:17:39.718106Z","id":"CVE-2026-1282","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-80"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.6.0","versionEndExcluding":"18.6.6","matchCriteriaId":"C3F7C278-FF2A-49DE-AE73-6B94C9833230"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.6.0","versionEndExcluding":"18.6.6","matchCriteriaId":"22C1B676-A5D2-40E7-8399-CFB9BCEEDE92"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.7.0","versionEndExcluding":"18.7.4","matchCriteriaId":"EB4484C1-2D91-48A6-B396-4F16DC598828"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.7.0","versionEndExcluding":"18.7.4","matchCriteriaId":"DA7B13F4-05B9-436E-A1DC-6C65DB7B44FE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.4","matchCriteriaId":"BCEB62DB-0D85-4A21-99C4-6235CA97A795"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.4","matchCriteriaId":"6D01D64A-0619-427D-B351-4101FC257674"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/02/10/patch-release-gitlab-18-8-4-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/587106","source":"cve@gitlab.com","tags":["Broken Link","Issue Tracking"]},{"url":"https://hackerone.com/reports/3505596","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-1387","sourceIdentifier":"cve@gitlab.com","published":"2026-02-11T12:16:04.547","lastModified":"2026-06-17T10:15:41.383","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 15.6 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an authenticated user to cause Denial of Service by uploading a malicious file and repeatedly querying it through GraphQl."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab EE que afecta a todas las versiones desde la 15.6 anterior a la 18.6.6, la 18.7 anterior a la 18.7.4, y la 18.8 anterior a la 18.8.4 que podría haber permitido a un usuario autenticado causar una denegación de servicio al subir un archivo malicioso y consultarlo repetidamente a través de GraphQl."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.6","lessThan":"18.6.6","versionType":"semver","status":"affected"},{"version":"18.7","lessThan":"18.7.4","versionType":"semver","status":"affected"},{"version":"18.8","lessThan":"18.8.4","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-02-11T21:17:22.725712Z","id":"CVE-2026-1387","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.6.0","versionEndExcluding":"18.6.6","matchCriteriaId":"3F0CFD5D-2A9D-49FD-A315-392CB1E1277F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.7.0","versionEndExcluding":"18.7.4","matchCriteriaId":"DA7B13F4-05B9-436E-A1DC-6C65DB7B44FE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.4","matchCriteriaId":"6D01D64A-0619-427D-B351-4101FC257674"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/02/10/patch-release-gitlab-18-8-4-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/587546","source":"cve@gitlab.com","tags":["Broken Link","Issue Tracking"]},{"url":"https://hackerone.com/reports/3515994","source":"cve@gitlab.com","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2026-1456","sourceIdentifier":"cve@gitlab.com","published":"2026-02-11T12:16:04.703","lastModified":"2026-06-17T10:15:49.427","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an unauthenticated user to cause denial of service through CPU exhaustion by submitting specially crafted markdown files that trigger exponential processing in markdown preview."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab CE/EE que afectaba a todas las versiones desde la 18.7 hasta las anteriores a la 18.7.4, y desde la 18.8 hasta las anteriores a la 18.8.4, que podría haber permitido a un usuario no autenticado causar denegación de servicio mediante el agotamiento de la CPU al enviar archivos markdown especialmente diseñados que desencadenan un procesamiento exponencial en la vista previa de markdown."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.7","lessThan":"18.7.4","versionType":"semver","status":"affected"},{"version":"18.8","lessThan":"18.8.4","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-02-11T15:38:41.451429Z","id":"CVE-2026-1456","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.7.0","versionEndExcluding":"18.7.4","matchCriteriaId":"EB4484C1-2D91-48A6-B396-4F16DC598828"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.7.0","versionEndExcluding":"18.7.4","matchCriteriaId":"DA7B13F4-05B9-436E-A1DC-6C65DB7B44FE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.4","matchCriteriaId":"BCEB62DB-0D85-4A21-99C4-6235CA97A795"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.4","matchCriteriaId":"6D01D64A-0619-427D-B351-4101FC257674"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/02/10/patch-release-gitlab-18-8-4-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/587688","source":"cve@gitlab.com","tags":["Broken Link","Issue Tracking"]},{"url":"https://hackerone.com/reports/3517928","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-1458","sourceIdentifier":"cve@gitlab.com","published":"2026-02-11T12:16:04.847","lastModified":"2026-06-17T10:15:49.660","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.0 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an unauthenticated user to cause denial of service by uploading malicious files."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab CE/EE que afecta a todas las versiones desde la 8.0 anterior a la 18.6.6, la 18.7 anterior a la 18.7.4 y la 18.8 anterior a la 18.8.4 que, bajo ciertas condiciones, podría haber permitido a un usuario no autenticado causar denegación de servicio mediante la carga de archivos maliciosos."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"8.0","lessThan":"18.6.6","versionType":"semver","status":"affected"},{"version":"18.7","lessThan":"18.7.4","versionType":"semver","status":"affected"},{"version":"18.8","lessThan":"18.8.4","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-02-11T15:41:27.857876Z","id":"CVE-2026-1458","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-434"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.0.0","versionEndExcluding":"18.6.6","matchCriteriaId":"536DCE5F-60B9-4F67-A63C-C6C3FD29EEC2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.0.0","versionEndExcluding":"18.6.6","matchCriteriaId":"E8F97391-D686-4732-A9DE-1F8FC39E1778"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.7.0","versionEndExcluding":"18.7.4","matchCriteriaId":"EB4484C1-2D91-48A6-B396-4F16DC598828"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.7.0","versionEndExcluding":"18.7.4","matchCriteriaId":"DA7B13F4-05B9-436E-A1DC-6C65DB7B44FE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.4","matchCriteriaId":"BCEB62DB-0D85-4A21-99C4-6235CA97A795"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.4","matchCriteriaId":"6D01D64A-0619-427D-B351-4101FC257674"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/02/10/patch-release-gitlab-18-8-4-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/587698","source":"cve@gitlab.com","tags":["Broken Link","Issue Tracking"]},{"url":"https://hackerone.com/reports/3517644","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-14103","sourceIdentifier":"cve@gitlab.com","published":"2026-02-25T20:20:07.867","lastModified":"2026-06-17T08:35:19.723","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.7 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an unauthorized user with Developer-role permissions to set pipeline variables for manually triggered jobs under certain conditions."},{"lang":"es","value":"GitLab ha subsanado un problema en GitLab CE/EE que afectaba a todas las versiones desde la 17.7 hasta las anteriores a la 18.7.5, la 18.8 hasta las anteriores a la 18.8.5, y la 18.9 hasta las anteriores a la 18.9.1, que podría haber permitido a un usuario no autorizado con permisos de rol de Desarrollador establecer variables de pipeline para trabajos activados manualmente bajo ciertas condiciones."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.7","lessThan":"18.7.5","versionType":"semver","status":"affected"},{"version":"18.8","lessThan":"18.8.5","versionType":"semver","status":"affected"},{"version":"18.9","lessThan":"18.9.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-02-25T20:52:13.471320Z","id":"CVE-2025-14103","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.7.0","versionEndExcluding":"18.7.5","matchCriteriaId":"F17BFE73-05C5-4A5B-8FBE-42234A9E3060"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.7.0","versionEndExcluding":"18.7.5","matchCriteriaId":"9A0A808B-74B7-40A7-8546-D85F0D204716"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.5","matchCriteriaId":"432C7223-F8B6-4EBA-84E2-2BB8A0F367D2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.5","matchCriteriaId":"630677C7-21EB-4E91-BB15-4610DCD22F98"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.9.0:*:*:*:community:*:*:*","matchCriteriaId":"795727F0-1B38-483F-BEE8-FB252EE57AC9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.9.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"73CCBA34-57C3-454D-A898-5D216EE1D5E9"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/02/25/patch-release-gitlab-18-9-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/583053","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3448317","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-3525","sourceIdentifier":"cve@gitlab.com","published":"2026-02-25T20:21:29.250","lastModified":"2026-06-17T09:20:06.623","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.0 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have, under certain circumstances, allowed an authenticated user with certain access to cause Denial of Service by creating specially crafted CI triggers via the API."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab CE/EE que afectaba a todas las versiones desde la 9.0 anterior a la 18.7.5, la 18.8 anterior a la 18.8.5 y la 18.9 anterior a la 18.9.1 que podría haber permitido, bajo ciertas circunstancias, a un usuario autenticado con cierto acceso causar una denegación de servicio mediante la creación de disparadores CI especialmente diseñados a través de la API."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"9.0","lessThan":"18.7.5","versionType":"semver","status":"affected"},{"version":"18.8","lessThan":"18.8.5","versionType":"semver","status":"affected"},{"version":"18.9","lessThan":"18.9.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-02-25T20:51:04.906901Z","id":"CVE-2025-3525","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"9.0.0","versionEndExcluding":"18.7.5","matchCriteriaId":"AD56310F-63C7-4161-A1DB-0A9895EEE314"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"9.0.0","versionEndExcluding":"18.7.5","matchCriteriaId":"E2FA2554-3520-4994-A17C-B7084E490851"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.5","matchCriteriaId":"432C7223-F8B6-4EBA-84E2-2BB8A0F367D2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.5","matchCriteriaId":"630677C7-21EB-4E91-BB15-4610DCD22F98"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.9.0:*:*:*:community:*:*:*","matchCriteriaId":"795727F0-1B38-483F-BEE8-FB252EE57AC9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.9.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"73CCBA34-57C3-454D-A898-5D216EE1D5E9"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/02/25/patch-release-gitlab-18-9-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/535662","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3045257","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-14511","sourceIdentifier":"cve@gitlab.com","published":"2026-02-25T21:16:30.453","lastModified":"2026-06-17T08:36:02.680","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an unauthenticated user to cause denial of service by sending specially crafted files to the container registry event endpoint under certain conditions."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab CE/EE que afecta a todas las versiones desde la 12.2 y anteriores a la 18.7.5, la 18.8 y anteriores a la 18.8.5, y la 18.9 y anteriores a la 18.9.1 que podría haber permitido a un usuario no autenticado causar una denegación de servicio mediante el envío de archivos especialmente diseñados al endpoint de eventos del registro de contenedores bajo ciertas condiciones."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"12.2","lessThan":"18.7.5","versionType":"semver","status":"affected"},{"version":"18.8","lessThan":"18.8.5","versionType":"semver","status":"affected"},{"version":"18.9","lessThan":"18.9.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-02-26T15:57:09.873853Z","id":"CVE-2025-14511","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1284"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"18.7.5","matchCriteriaId":"3FCA09B5-DE4F-4CF1-8767-8599885BF0B0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"18.7.5","matchCriteriaId":"AB66DB61-383F-4EBC-84BE-1D93F75B0297"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.5","matchCriteriaId":"432C7223-F8B6-4EBA-84E2-2BB8A0F367D2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.5","matchCriteriaId":"630677C7-21EB-4E91-BB15-4610DCD22F98"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.9.0:*:*:*:community:*:*:*","matchCriteriaId":"795727F0-1B38-483F-BEE8-FB252EE57AC9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.9.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"73CCBA34-57C3-454D-A898-5D216EE1D5E9"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/02/25/patch-release-gitlab-18-9-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/583717","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3452200","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-0752","sourceIdentifier":"cve@gitlab.com","published":"2026-02-25T21:16:36.330","lastModified":"2026-06-17T10:11:19.260","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that under certain circumstances, could have allowed an unauthenticated user to inject arbitrary scripts into the Mermaid sandbox UI."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab CE/EE que afecta a todas las versiones desde la 16.2 antes de la 18.7.5, la 18.8 antes de la 18.8.5, y la 18.9 antes de la 18.9.1 que, bajo ciertas circunstancias, podría haber permitido a un usuario no autenticado inyectar scripts arbitrarios en la interfaz de usuario del sandbox de Mermaid."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.2","lessThan":"18.7.5","versionType":"semver","status":"affected"},{"version":"18.8","lessThan":"18.8.5","versionType":"semver","status":"affected"},{"version":"18.9","lessThan":"18.9.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N","baseScore":8.0,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-02-26T04:56:17.540008Z","id":"CVE-2026-0752","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.2.0","versionEndExcluding":"18.7.5","matchCriteriaId":"25E75F2D-2A23-454A-AD0E-0E0491F7FE35"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.2.0","versionEndExcluding":"18.7.5","matchCriteriaId":"634BAAAB-E10B-4B31-A467-74EEAD7DD2B2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.5","matchCriteriaId":"432C7223-F8B6-4EBA-84E2-2BB8A0F367D2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.5","matchCriteriaId":"630677C7-21EB-4E91-BB15-4610DCD22F98"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.9.0:*:*:*:community:*:*:*","matchCriteriaId":"795727F0-1B38-483F-BEE8-FB252EE57AC9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.9.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"73CCBA34-57C3-454D-A898-5D216EE1D5E9"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/02/25/patch-release-gitlab-18-9-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/585371","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3473276","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-1388","sourceIdentifier":"cve@gitlab.com","published":"2026-02-25T21:16:36.500","lastModified":"2026-06-17T10:15:41.497","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an unauthenticated user to cause regular expression denial of service by sending specially crafted input to a merge request endpoint under certain conditions."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab CE/EE que afecta a todas las versiones desde la 9.2 anterior a la 18.7.5, la 18.8 anterior a la 18.8.5, y la 18.9 anterior a la 18.9.1 que podría haber permitido a un usuario no autenticado causar una denegación de servicio por expresión regular mediante el envío de una entrada especialmente diseñada a un endpoint de solicitud de fusión bajo ciertas condiciones."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"9.2","lessThan":"18.7.5","versionType":"semver","status":"affected"},{"version":"18.8","lessThan":"18.8.5","versionType":"semver","status":"affected"},{"version":"18.9","lessThan":"18.9.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-02-26T15:07:20.663791Z","id":"CVE-2026-1388","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1333"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"9.2.0","versionEndExcluding":"18.7.5","matchCriteriaId":"B12C34F6-2CBC-47AD-AD96-69D58B92FD0F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"9.2.0","versionEndExcluding":"18.7.5","matchCriteriaId":"367ECB06-C074-4051-854C-04B62268A024"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.5","matchCriteriaId":"432C7223-F8B6-4EBA-84E2-2BB8A0F367D2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.5","matchCriteriaId":"630677C7-21EB-4E91-BB15-4610DCD22F98"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.9.0:*:*:*:community:*:*:*","matchCriteriaId":"795727F0-1B38-483F-BEE8-FB252EE57AC9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.9.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"73CCBA34-57C3-454D-A898-5D216EE1D5E9"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/02/25/patch-release-gitlab-18-9-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/587560","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3482893","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-1662","sourceIdentifier":"cve@gitlab.com","published":"2026-02-25T21:16:36.670","lastModified":"2026-06-17T10:16:16.363","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.4 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an unauthenticated user to cause Denial of Service by sending specially crafted requests to the Jira events endpoint."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab CE/EE que afecta a todas las versiones desde la 14.4 y anteriores a la 18.7.5, la 18.8 y anteriores a la 18.8.5, y la 18.9 y anteriores a la 18.9.1 que podría haber permitido a un usuario no autenticado causar denegación de servicio mediante el envío de solicitudes especialmente diseñadas al endpoint de eventos de Jira."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"14.4","lessThan":"18.7.5","versionType":"semver","status":"affected"},{"version":"18.8","lessThan":"18.8.5","versionType":"semver","status":"affected"},{"version":"18.9","lessThan":"18.9.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-02-26T15:10:25.803586Z","id":"CVE-2026-1662","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.4.0","versionEndExcluding":"18.7.5","matchCriteriaId":"F90F606F-E507-49C1-9736-4CC4B738F9CD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.4.0","versionEndExcluding":"18.7.5","matchCriteriaId":"65AAA10B-37E8-435F-AF35-45BE7E471767"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.5","matchCriteriaId":"432C7223-F8B6-4EBA-84E2-2BB8A0F367D2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.5","matchCriteriaId":"630677C7-21EB-4E91-BB15-4610DCD22F98"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.9.0:*:*:*:community:*:*:*","matchCriteriaId":"795727F0-1B38-483F-BEE8-FB252EE57AC9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.9.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"73CCBA34-57C3-454D-A898-5D216EE1D5E9"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/02/25/patch-release-gitlab-18-9-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/588206","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3519694","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-1725","sourceIdentifier":"cve@gitlab.com","published":"2026-02-25T21:16:36.833","lastModified":"2026-06-17T10:16:24.213","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting versions from 18.9 before 18.9.1 that could have under certain conditions, allowed an unauthenticated user to cause denial of service by sending specially crafted requests to a CI jobs API endpoint."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab CE/EE que afectaba a las versiones desde la 18.9 antes de la 18.9.1 que, bajo ciertas condiciones, podría haber permitido a un usuario no autenticado causar una denegación de servicio enviando solicitudes especialmente diseñadas a un endpoint de la API de trabajos de CI."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.9","lessThan":"18.9.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-02-26T15:42:17.687008Z","id":"CVE-2026-1725","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.9.0:*:*:*:community:*:*:*","matchCriteriaId":"795727F0-1B38-483F-BEE8-FB252EE57AC9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.9.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"73CCBA34-57C3-454D-A898-5D216EE1D5E9"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/02/25/patch-release-gitlab-18-9-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/588338","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3519773","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-1747","sourceIdentifier":"cve@gitlab.com","published":"2026-02-25T21:16:36.993","lastModified":"2026-06-17T10:16:26.953","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 17.11 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that, under certain conditions, could have allowed Developer-role users with insufficient privileges to make unauthorized modifications to protected Conan packages."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab EE que afectaba a todas las versiones desde la 17.11 anteriores a la 18.7.5, la 18.8 anteriores a la 18.8.5, y la 18.9 anteriores a la 18.9.1 que, bajo ciertas condiciones, podría haber permitido a usuarios con rol de Desarrollador con privilegios insuficientes realizar modificaciones no autorizadas a paquetes Conan protegidos."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.11","lessThan":"18.7.5","versionType":"semver","status":"affected"},{"version":"18.8","lessThan":"18.8.5","versionType":"semver","status":"affected"},{"version":"18.9","lessThan":"18.9.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-02-26T15:38:24.259525Z","id":"CVE-2026-1747","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-288"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.11.0","versionEndExcluding":"18.7.5","matchCriteriaId":"A9505ACB-A00F-4F5C-92D1-15F6C8A91924"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.11.0","versionEndExcluding":"18.7.5","matchCriteriaId":"62456409-25CE-4B6B-A0A4-FF6BFDC693F2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.5","matchCriteriaId":"432C7223-F8B6-4EBA-84E2-2BB8A0F367D2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.5","matchCriteriaId":"630677C7-21EB-4E91-BB15-4610DCD22F98"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.9.0:*:*:*:community:*:*:*","matchCriteriaId":"795727F0-1B38-483F-BEE8-FB252EE57AC9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.9.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"73CCBA34-57C3-454D-A898-5D216EE1D5E9"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/02/25/patch-release-gitlab-18-9-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/588385","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3533088","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-2845","sourceIdentifier":"cve@gitlab.com","published":"2026-02-25T21:16:44.547","lastModified":"2026-06-17T10:31:52.210","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab CE/EE affecting all versions from 11.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an authenticated user to cause denial of service by exploiting a Bitbucket Server import endpoint via repeatedly sending large responses."},{"lang":"es","value":"Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde la 11.2 anterior a la 18.7.5, la 18.8 anterior a la 18.8.5 y la 18.9 anterior a la 18.9.1 que podría haber permitido a un usuario autenticado causar una denegación de servicio al explotar un endpoint de importación del servidor de Bitbucket mediante el envío repetido de respuestas grandes."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"11.2","lessThan":"18.7.5","versionType":"semver","status":"affected"},{"version":"18.8","lessThan":"18.8.5","versionType":"semver","status":"affected"},{"version":"18.9","lessThan":"18.9.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-02-26T15:44:35.776720Z","id":"CVE-2026-2845","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.2.0","versionEndExcluding":"18.7.5","matchCriteriaId":"2C284DA2-89BA-4728-B503-BF3279EFE9BB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.2.0","versionEndExcluding":"18.7.5","matchCriteriaId":"5F9A1A01-1984-4982-8650-39DD7DFDBA4F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.5","matchCriteriaId":"432C7223-F8B6-4EBA-84E2-2BB8A0F367D2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.5","matchCriteriaId":"630677C7-21EB-4E91-BB15-4610DCD22F98"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.9.0:*:*:*:community:*:*:*","matchCriteriaId":"795727F0-1B38-483F-BEE8-FB252EE57AC9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.9.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"73CCBA34-57C3-454D-A898-5D216EE1D5E9"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/02/25/patch-release-gitlab-18-9-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/570554","source":"cve@gitlab.com","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2025-12576","sourceIdentifier":"cve@gitlab.com","published":"2026-03-11T16:16:18.030","lastModified":"2026-06-17T08:32:36.287","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.3 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that under certain conditions could have allowed an authenticated user to cause a denial of service due to improper handling of webhook response data."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab CE/EE que afecta a todas las versiones desde la 9.3 anterior a la 18.7.6, la 18.8 anterior a la 18.8.6, y la 18.9 anterior a la 18.9.2 que bajo ciertas condiciones podría haber permitido a un usuario autenticado causar una denegación de servicio debido a un manejo inadecuado de los datos de respuesta de los webhooks."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"9.3","lessThan":"18.7.6","versionType":"semver","status":"affected"},{"version":"18.8","lessThan":"18.8.6","versionType":"semver","status":"affected"},{"version":"18.9","lessThan":"18.9.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-11T17:11:13.401543Z","id":"CVE-2025-12576","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"9.3.0","versionEndExcluding":"18.7.6","matchCriteriaId":"A329CFCD-133E-424E-BC76-B046F35D4A32"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"9.3.0","versionEndExcluding":"18.7.6","matchCriteriaId":"738FF258-E211-4023-ADA6-9C7D78D9BE78"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.6","matchCriteriaId":"B703CB01-7F6D-4D6E-AE88-CF2F8012CA27"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.6","matchCriteriaId":"2B1F834B-A628-4894-A531-1A2A60DD58D7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.2","matchCriteriaId":"44EAE9A6-5ED9-42F6-9BBD-0E2F8072F0D9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.2","matchCriteriaId":"12A2DEC0-C471-4C98-960C-405209403AB9"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/03/11/patch-release-gitlab-18-9-2-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/579170","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3395198","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-12697","sourceIdentifier":"cve@gitlab.com","published":"2026-03-11T16:16:18.403","lastModified":"2026-06-17T08:32:49.153","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.5 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user with maintainer-role permissions to reveal Datadog API credentials under certain conditions."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab CE/EE que afecta a todas las versiones desde la 15.5 y anteriores a la 18.7.6, la 18.8 y anteriores a la 18.8.6, y la 18.9 y anteriores a la 18.9.2 que podría haber permitido a un usuario autenticado con permisos de rol de mantenedor revelar credenciales de la API de Datadog bajo ciertas condiciones."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.5","lessThan":"18.7.6","versionType":"semver","status":"affected"},{"version":"18.8","lessThan":"18.8.6","versionType":"semver","status":"affected"},{"version":"18.9","lessThan":"18.9.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N","baseScore":2.2,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":0.7,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N","baseScore":4.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":0.7,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-11T17:21:48.892140Z","id":"CVE-2025-12697","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-116"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.5.0","versionEndExcluding":"18.7.6","matchCriteriaId":"80904F84-8E1E-43FA-892A-4137F4650249"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.5.0","versionEndExcluding":"18.7.6","matchCriteriaId":"B38B4650-1C8F-4C6C-95A9-E877FF736169"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.6","matchCriteriaId":"B703CB01-7F6D-4D6E-AE88-CF2F8012CA27"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.6","matchCriteriaId":"2B1F834B-A628-4894-A531-1A2A60DD58D7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.2","matchCriteriaId":"44EAE9A6-5ED9-42F6-9BBD-0E2F8072F0D9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.2","matchCriteriaId":"12A2DEC0-C471-4C98-960C-405209403AB9"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/03/11/patch-release-gitlab-18-9-2-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/579504","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3341953","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-12704","sourceIdentifier":"cve@gitlab.com","published":"2026-03-11T16:16:18.570","lastModified":"2026-06-17T08:32:49.433","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to access Virtual Registry data in groups where they are not members due to improper authorization under certain conditions."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab EE que afecta a todas las versiones desde la 18.2 anteriores a la 18.7.6, la 18.8 anteriores a la 18.8.6 y la 18.9 anteriores a la 18.9.2 que podría haber permitido a un usuario autenticado acceder a datos del Registro Virtual en grupos de los que no son miembros debido a una autorización incorrecta bajo ciertas condiciones."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.2","lessThan":"18.7.6","versionType":"semver","status":"affected"},{"version":"18.8","lessThan":"18.8.6","versionType":"semver","status":"affected"},{"version":"18.9","lessThan":"18.9.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N","baseScore":3.5,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-12T15:42:44.887645Z","id":"CVE-2025-12704","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"18.7.6","matchCriteriaId":"61412438-52EE-435B-A300-7394252AB2E5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"18.7.6","matchCriteriaId":"87885DCB-FAAA-4D36-B81F-D95F6A366606"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.6","matchCriteriaId":"B703CB01-7F6D-4D6E-AE88-CF2F8012CA27"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.6","matchCriteriaId":"2B1F834B-A628-4894-A531-1A2A60DD58D7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.2","matchCriteriaId":"44EAE9A6-5ED9-42F6-9BBD-0E2F8072F0D9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.2","matchCriteriaId":"12A2DEC0-C471-4C98-960C-405209403AB9"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/03/11/patch-release-gitlab-18-9-2-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/579534","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3389825","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-13690","sourceIdentifier":"cve@gitlab.com","published":"2026-03-11T16:16:18.877","lastModified":"2026-06-17T08:34:35.477","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.11 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to cause a denial of service condition due to improper input validation on webhook custom header names under certain conditions."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab CE/EE que afecta a todas las versiones desde la 16.11 anterior a la 18.7.6, la 18.8 anterior a la 18.8.6 y la 18.9 anterior a la 18.9.2 que podría haber permitido a un usuario autenticado causar una condición de denegación de servicio debido a una validación de entrada incorrecta en los nombres de encabezado personalizados de los webhooks bajo ciertas condiciones."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.11","lessThan":"18.7.6","versionType":"semver","status":"affected"},{"version":"18.8","lessThan":"18.8.6","versionType":"semver","status":"affected"},{"version":"18.9","lessThan":"18.9.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-12T15:42:31.156839Z","id":"CVE-2025-13690","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.11.0","versionEndExcluding":"18.7.6","matchCriteriaId":"A7913596-C173-4DB6-ADC6-61AB59A7513C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.11.0","versionEndExcluding":"18.7.6","matchCriteriaId":"60B87D4E-DB42-4B3D-845D-9E15654EF082"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.6","matchCriteriaId":"B703CB01-7F6D-4D6E-AE88-CF2F8012CA27"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.6","matchCriteriaId":"2B1F834B-A628-4894-A531-1A2A60DD58D7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.2","matchCriteriaId":"44EAE9A6-5ED9-42F6-9BBD-0E2F8072F0D9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.2","matchCriteriaId":"12A2DEC0-C471-4C98-960C-405209403AB9"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/03/11/patch-release-gitlab-18-9-2-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/582096","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3415683","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-13929","sourceIdentifier":"cve@gitlab.com","published":"2026-03-11T16:16:19.043","lastModified":"2026-06-17T08:34:59.910","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.0 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an unauthenticated user to cause a denial of service by issuing specially crafted requests to repository archive endpoints under certain conditions."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab CE/EE que afecta a todas las versiones desde la 10.0 anterior a la 18.7.6, la 18.8 anterior a la 18.8.6 y la 18.9 anterior a la 18.9.2 que podría haber permitido a un usuario no autenticado causar una denegación de servicio mediante la emisión de solicitudes especialmente diseñadas a los puntos finales de archivo del repositorio bajo ciertas condiciones."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"10.0","lessThan":"18.7.6","versionType":"semver","status":"affected"},{"version":"18.8","lessThan":"18.8.6","versionType":"semver","status":"affected"},{"version":"18.9","lessThan":"18.9.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-12T15:42:12.319805Z","id":"CVE-2025-13929","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.0.0","versionEndExcluding":"18.7.6","matchCriteriaId":"E552588B-B0F4-40F4-98FD-394F30ABFE22"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.0.0","versionEndExcluding":"18.7.6","matchCriteriaId":"85D6F660-B145-4890-AE32-F4FEFDE35C98"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.6","matchCriteriaId":"B703CB01-7F6D-4D6E-AE88-CF2F8012CA27"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.6","matchCriteriaId":"2B1F834B-A628-4894-A531-1A2A60DD58D7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.2","matchCriteriaId":"44EAE9A6-5ED9-42F6-9BBD-0E2F8072F0D9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.2","matchCriteriaId":"12A2DEC0-C471-4C98-960C-405209403AB9"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/03/11/patch-release-gitlab-18-9-2-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/582738","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/582738","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3441004","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-14513","sourceIdentifier":"cve@gitlab.com","published":"2026-03-11T16:16:19.223","lastModified":"2026-06-17T08:36:03.040","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.11 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an unauthenticated user to cause a denial of service condition due to improper input validation when processing specially crafted JSON payloads in the protected branches API."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab CE/EE que afecta a todas las versiones desde la 16.11 anterior a la 18.7.6, la 18.8 anterior a la 18.8.6 y la 18.9 anterior a la 18.9.2 que podría haber permitido a un usuario no autenticado causar una condición de denegación de servicio debido a una validación de entrada incorrecta al procesar cargas útiles JSON especialmente diseñadas en la API de ramas protegidas."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.11","lessThan":"18.7.6","versionType":"semver","status":"affected"},{"version":"18.8","lessThan":"18.8.6","versionType":"semver","status":"affected"},{"version":"18.9","lessThan":"18.9.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-11T19:31:51.194051Z","id":"CVE-2025-14513","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1284"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.11.0","versionEndExcluding":"18.7.6","matchCriteriaId":"A7913596-C173-4DB6-ADC6-61AB59A7513C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.11.0","versionEndExcluding":"18.7.6","matchCriteriaId":"60B87D4E-DB42-4B3D-845D-9E15654EF082"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.6","matchCriteriaId":"B703CB01-7F6D-4D6E-AE88-CF2F8012CA27"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.6","matchCriteriaId":"2B1F834B-A628-4894-A531-1A2A60DD58D7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.2","matchCriteriaId":"44EAE9A6-5ED9-42F6-9BBD-0E2F8072F0D9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.2","matchCriteriaId":"12A2DEC0-C471-4C98-960C-405209403AB9"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/03/11/patch-release-gitlab-18-9-2-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/583718","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3452477","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-0602","sourceIdentifier":"cve@gitlab.com","published":"2026-03-11T16:16:22.010","lastModified":"2026-06-17T10:11:03.633","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.6 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to disclose metadata from private issues, merge requests, epics, milestones, or commits due to improper filtering in the snippet rendering process under certain circumstances."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab CE/EE que afectaba a todas las versiones desde la 15.6 anterior a la 18.7.6, la 18.8 anterior a la 18.8.6, y la 18.9 anterior a la 18.9.2 que podría haber permitido a un usuario autenticado divulgar metadatos de incidencias privadas, solicitudes de fusión, epics, hitos o commits debido a un filtrado inadecuado en el proceso de renderizado de snippets bajo ciertas circunstancias."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.6","lessThan":"18.7.6","versionType":"semver","status":"affected"},{"version":"18.8","lessThan":"18.8.6","versionType":"semver","status":"affected"},{"version":"18.9","lessThan":"18.9.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-11T19:35:24.963574Z","id":"CVE-2026-0602","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-288"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.6.0","versionEndExcluding":"18.7.6","matchCriteriaId":"F6621BA2-5B32-4ABF-A841-3BA3793C54CB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.6.0","versionEndExcluding":"18.7.6","matchCriteriaId":"43F68CF4-8DAE-4844-AA74-F94E42E2A5AB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.6","matchCriteriaId":"B703CB01-7F6D-4D6E-AE88-CF2F8012CA27"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.6","matchCriteriaId":"2B1F834B-A628-4894-A531-1A2A60DD58D7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.2","matchCriteriaId":"44EAE9A6-5ED9-42F6-9BBD-0E2F8072F0D9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.2","matchCriteriaId":"12A2DEC0-C471-4C98-960C-405209403AB9"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/03/11/patch-release-gitlab-18-9-2-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/585007","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3486504","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-1069","sourceIdentifier":"cve@gitlab.com","published":"2026-03-11T16:16:22.170","lastModified":"2026-06-17T10:14:56.660","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.9 before 18.9.2 that could have allowed an unauthenticated user to cause a denial of service by sending specially crafted GraphQL requests due to uncontrolled recursion under certain circumstances."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab CE/EE que afectaba a todas las versiones desde la 18.9 antes de la 18.9.2 que podría haber permitido a un usuario no autenticado causar una denegación de servicio mediante el envío de solicitudes GraphQL especialmente diseñadas debido a una recursión incontrolada bajo ciertas circunstancias."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.9","lessThan":"18.9.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-11T19:39:21.302747Z","id":"CVE-2026-1069","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-674"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.2","matchCriteriaId":"44EAE9A6-5ED9-42F6-9BBD-0E2F8072F0D9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.2","matchCriteriaId":"12A2DEC0-C471-4C98-960C-405209403AB9"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/03/11/patch-release-gitlab-18-9-2-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/586474","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3483687","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-1090","sourceIdentifier":"cve@gitlab.com","published":"2026-03-11T16:16:22.340","lastModified":"2026-06-17T10:14:58.693","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user, when the `markdown_placeholders` feature flag was enabled, to inject JavaScript in a browser due to improper sanitization of placeholder content in markdown processing."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab CE/EE que afecta a todas las versiones desde la 10.6 antes de la 18.7.6, la 18.8 antes de la 18.8.6, y la 18.9 antes de la 18.9.2 que podría haber permitido a un usuario autenticado, cuando la bandera de característica 'markdown_placeholders' estaba habilitada, inyectar JavaScript en un navegador debido a una sanitización inadecuada del contenido del marcador de posición en el procesamiento de markdown."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"10.6","lessThan":"18.7.6","versionType":"semver","status":"affected"},{"version":"18.8","lessThan":"18.8.6","versionType":"semver","status":"affected"},{"version":"18.9","lessThan":"18.9.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-12T03:55:35.416843Z","id":"CVE-2026-1090","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.6.0","versionEndExcluding":"18.7.6","matchCriteriaId":"0882CA9D-1946-4287-8982-D95757F43BF8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.6.0","versionEndExcluding":"18.7.6","matchCriteriaId":"E324666E-575A-4D81-B4A0-5C6070068C37"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.6","matchCriteriaId":"B703CB01-7F6D-4D6E-AE88-CF2F8012CA27"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.6","matchCriteriaId":"2B1F834B-A628-4894-A531-1A2A60DD58D7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.2","matchCriteriaId":"44EAE9A6-5ED9-42F6-9BBD-0E2F8072F0D9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.2","matchCriteriaId":"12A2DEC0-C471-4C98-960C-405209403AB9"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/03/11/patch-release-gitlab-18-9-2-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/586478","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3502450","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-1230","sourceIdentifier":"cve@gitlab.com","published":"2026-03-11T16:16:22.493","lastModified":"2026-06-17T10:15:21.943","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 1.0 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to cause repository downloads to contain different code than displayed in the web interface due to incorrect validation of branch references under certain circumstances."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab CE/EE que afecta a todas las versiones desde la 1.0 anteriores a la 18.7.6, la 18.8 anteriores a la 18.8.6, y la 18.9 anteriores a la 18.9.2 que podría haber permitido a un usuario autenticado causar que las descargas del repositorio contuvieran código diferente al mostrado en la interfaz web debido a una validación incorrecta de las referencias de rama bajo ciertas circunstancias."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"1.0","lessThan":"18.7.6","versionType":"semver","status":"affected"},{"version":"18.8","lessThan":"18.8.6","versionType":"semver","status":"affected"},{"version":"18.9","lessThan":"18.9.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N","baseScore":4.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-11T19:45:54.519929Z","id":"CVE-2026-1230","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-706"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"1.0.0","versionEndExcluding":"18.7.6","matchCriteriaId":"6C34481A-DC7A-4EA7-91DE-F7FAA6AEB890"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"1.0.0","versionEndExcluding":"18.7.6","matchCriteriaId":"33882DC3-5598-4793-BA6F-51E11724E5DC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.6","matchCriteriaId":"B703CB01-7F6D-4D6E-AE88-CF2F8012CA27"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.6","matchCriteriaId":"2B1F834B-A628-4894-A531-1A2A60DD58D7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.2","matchCriteriaId":"44EAE9A6-5ED9-42F6-9BBD-0E2F8072F0D9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.2","matchCriteriaId":"12A2DEC0-C471-4C98-960C-405209403AB9"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/03/11/patch-release-gitlab-18-9-2-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/587002","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3505165","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-1663","sourceIdentifier":"cve@gitlab.com","published":"2026-03-11T16:16:22.833","lastModified":"2026-06-17T10:16:16.510","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.4 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user with group import permissions to create labels in private projects due to improper authorization validation in the group import process under certain circumstances."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab CE/EE que afecta a todas las versiones desde la 14.4 anterior a la 18.7.6, la 18.8 anterior a la 18.8.6 y la 18.9 anterior a la 18.9.2 que podría haber permitido a un usuario autenticado con permisos de importación de grupo crear etiquetas en proyectos privados debido a una validación de autorización incorrecta en el proceso de importación de grupo bajo ciertas circunstancias."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"14.4","lessThan":"18.7.6","versionType":"semver","status":"affected"},{"version":"18.8","lessThan":"18.8.6","versionType":"semver","status":"affected"},{"version":"18.9","lessThan":"18.9.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-12T16:15:24.947201Z","id":"CVE-2026-1663","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.4.0","versionEndExcluding":"18.7.6","matchCriteriaId":"928EA20E-7DD4-4E96-ABDD-4D0C8C174BA7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.4.0","versionEndExcluding":"18.7.6","matchCriteriaId":"D0F24E02-80E9-4CD5-84DF-8D7E93B74CE5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.6","matchCriteriaId":"B703CB01-7F6D-4D6E-AE88-CF2F8012CA27"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.6","matchCriteriaId":"2B1F834B-A628-4894-A531-1A2A60DD58D7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.2","matchCriteriaId":"44EAE9A6-5ED9-42F6-9BBD-0E2F8072F0D9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.2","matchCriteriaId":"12A2DEC0-C471-4C98-960C-405209403AB9"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/03/11/patch-release-gitlab-18-9-2-released/","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/588207","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3485548","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-1732","sourceIdentifier":"cve@gitlab.com","published":"2026-03-11T16:16:22.987","lastModified":"2026-06-17T10:16:24.917","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.6 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to disclose confidential issue titles due to improper filtering under certain circumstances."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab CE/EE que afecta a todas las versiones desde la 12.6 anterior a la 18.7.6, la 18.8 anterior a la 18.8.6 y la 18.9 anterior a la 18.9.2 que podría haber permitido a un usuario autenticado divulgar títulos de problemas confidenciales debido a un filtrado inadecuado bajo ciertas circunstancias."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"12.6","lessThan":"18.7.6","versionType":"semver","status":"affected"},{"version":"18.8","lessThan":"18.8.6","versionType":"semver","status":"affected"},{"version":"18.9","lessThan":"18.9.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-12T16:10:44.686768Z","id":"CVE-2026-1732","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-212"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.6.0","versionEndExcluding":"18.7.6","matchCriteriaId":"E4CFAA41-2F3A-447B-A6AC-6A56E7E1F911"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.6.0","versionEndExcluding":"18.7.6","matchCriteriaId":"55745F59-E2D5-4961-B96F-4C2563FC1A18"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.6","matchCriteriaId":"B703CB01-7F6D-4D6E-AE88-CF2F8012CA27"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.6","matchCriteriaId":"2B1F834B-A628-4894-A531-1A2A60DD58D7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.2","matchCriteriaId":"44EAE9A6-5ED9-42F6-9BBD-0E2F8072F0D9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.2","matchCriteriaId":"12A2DEC0-C471-4C98-960C-405209403AB9"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/03/11/patch-release-gitlab-18-9-2-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/588380","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3532881","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-3848","sourceIdentifier":"cve@gitlab.com","published":"2026-03-11T16:16:47.310","lastModified":"2026-06-17T10:44:20.487","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.11 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to make unintended internal requests through proxy environments under certain conditions due to improper input validation in import functionality."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab CE/EE que afecta a todas las versiones desde la 8.11 anterior a la 18.7.6, la 18.8 anterior a la 18.8.6, y la 18.9 anterior a la 18.9.2 que podría haber permitido a un usuario autenticado realizar solicitudes internas no intencionadas a través de entornos proxy bajo ciertas condiciones debido a una validación de entrada incorrecta en la funcionalidad de importación."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"8.11","lessThan":"18.7.6","versionType":"semver","status":"affected"},{"version":"18.8","lessThan":"18.8.6","versionType":"semver","status":"affected"},{"version":"18.9","lessThan":"18.9.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N","baseScore":5.0,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-12T14:23:34.060887Z","id":"CVE-2026-3848","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-93"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.11.0","versionEndExcluding":"18.7.6","matchCriteriaId":"452C4C38-FBAA-43F8-A149-E241432E1BBB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.11.0","versionEndExcluding":"18.7.6","matchCriteriaId":"A1C1FDF8-D6DB-4A3E-9BA2-7C70D68B401A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.6","matchCriteriaId":"B703CB01-7F6D-4D6E-AE88-CF2F8012CA27"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.6","matchCriteriaId":"2B1F834B-A628-4894-A531-1A2A60DD58D7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.2","matchCriteriaId":"44EAE9A6-5ED9-42F6-9BBD-0E2F8072F0D9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.2","matchCriteriaId":"12A2DEC0-C471-4C98-960C-405209403AB9"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/03/11/patch-release-gitlab-18-9-2-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/577298","source":"cve@gitlab.com","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2025-12555","sourceIdentifier":"cve@gitlab.com","published":"2026-03-11T17:16:50.063","lastModified":"2026-06-17T08:32:34.833","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.1 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that, under certain conditions, could have allowed an authenticated user to access previous pipeline job information on projects with repository and CI/CD disabled due to improper authorization checks."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab CE/EE que afecta a todas las versiones desde la 15.1 anterior a la 18.7.6, la 18.8 anterior a la 18.8.6 y la 18.9 anterior a la 18.9.2 que, bajo ciertas condiciones, podría haber permitido a un usuario autenticado acceder a información de trabajos de pipeline anteriores en proyectos con el repositorio y CI/CD deshabilitados debido a comprobaciones de autorización incorrectas."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.1","lessThan":"18.7.6","versionType":"semver","status":"affected"},{"version":"18.8","lessThan":"18.8.6","versionType":"semver","status":"affected"},{"version":"18.9","lessThan":"18.9.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-12T15:43:00.821254Z","id":"CVE-2025-12555","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.1.0","versionEndExcluding":"18.7.6","matchCriteriaId":"90D98056-76B5-4507-B54E-1EA9C03A883B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.1.0","versionEndExcluding":"18.7.6","matchCriteriaId":"E345CFD1-20A4-42B7-9545-6D6240D46810"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.6","matchCriteriaId":"B703CB01-7F6D-4D6E-AE88-CF2F8012CA27"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.6","matchCriteriaId":"2B1F834B-A628-4894-A531-1A2A60DD58D7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.2","matchCriteriaId":"44EAE9A6-5ED9-42F6-9BBD-0E2F8072F0D9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.2","matchCriteriaId":"12A2DEC0-C471-4C98-960C-405209403AB9"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/03/11/patch-release-gitlab-18-9-2-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/579126","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3354642","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-1182","sourceIdentifier":"cve@gitlab.com","published":"2026-03-12T02:15:58.433","lastModified":"2026-06-17T10:15:17.090","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.14 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to gain unauthorized access to confidential issue title created in public projects under certain circumstances."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab CE/EE que afecta a todas las versiones desde la 8.14 anteriores a la 18.7.6, la 18.8 anteriores a la 18.8.6, y la 18.9 anteriores a la 18.9.2 que podría haber permitido a un usuario autenticado obtener acceso no autorizado al título de un problema confidencial creado en proyectos públicos bajo ciertas circunstancias."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"8.14","lessThan":"18.7.6","versionType":"semver","status":"affected"},{"version":"18.8","lessThan":"18.8.6","versionType":"semver","status":"affected"},{"version":"18.9","lessThan":"18.9.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-12T13:25:00.727480Z","id":"CVE-2026-1182","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-212"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.14.0","versionEndExcluding":"18.7.6","matchCriteriaId":"770437A8-2C1C-4D95-A6A9-25C2F337B0D7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.14.0","versionEndExcluding":"18.7.6","matchCriteriaId":"19BFB4A2-0CAE-47F6-9081-9E3400ED218C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.6","matchCriteriaId":"B703CB01-7F6D-4D6E-AE88-CF2F8012CA27"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.6","matchCriteriaId":"2B1F834B-A628-4894-A531-1A2A60DD58D7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.2","matchCriteriaId":"44EAE9A6-5ED9-42F6-9BBD-0E2F8072F0D9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.2","matchCriteriaId":"12A2DEC0-C471-4C98-960C-405209403AB9"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/586613","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3515716","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-4363","sourceIdentifier":"cve@gitlab.com","published":"2026-03-25T15:16:50.550","lastModified":"2026-06-17T10:56:28.667","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 18.1 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that under certain conditions could have allowed an authenticated user to gain unauthorized access to resources due to improper caching of authorization decisions."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab EE que afecta a todas las versiones desde la 18.1 anterior a la 18.8.7, la 18.9 anterior a la 18.9.3, y la 18.10 anterior a la 18.10.1 que bajo ciertas condiciones podría haber permitido a un usuario autenticado obtener acceso no autorizado a recursos debido a un almacenamiento en caché incorrecto de las decisiones de autorización."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.1","lessThan":"18.8.7","versionType":"semver","status":"affected"},{"version":"18.9","lessThan":"18.9.3","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N","baseScore":3.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-25T19:57:30.302180Z","id":"CVE-2026-4363","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.1.0","versionEndExcluding":"18.8.7","matchCriteriaId":"6007A8A2-439E-41E7-8DF8-36BE0F25983F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.3","matchCriteriaId":"C3240349-67A3-43E2-BAD9-EFAA3E0A5D31"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.10.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"2B8DF779-B99E-4096-B734-78AB1849D136"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/03/25/patch-release-gitlab-18-10-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/578561","source":"cve@gitlab.com","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2025-13078","sourceIdentifier":"cve@gitlab.com","published":"2026-03-25T17:16:26.963","lastModified":"2026-06-17T08:33:28.040","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.10 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to cause a denial of service due to excessive resource consumption when processing certain webhook configuration inputs."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab CE/EE que afecta a todas las versiones desde la 16.10 anterior a la 18.8.7, la 18.9 anterior a la 18.9.3 y la 18.10 anterior a la 18.10.1 que podría haber permitido a un usuario autenticado causar una denegación de servicio debido al consumo excesivo de recursos al procesar ciertas entradas de configuración de webhook."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.10","lessThan":"18.8.7","versionType":"semver","status":"affected"},{"version":"18.9","lessThan":"18.9.3","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-25T17:02:49.827497Z","id":"CVE-2025-13078","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1284"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.10.0","versionEndExcluding":"18.8.7","matchCriteriaId":"5EB3BAD7-BFFC-4370-87EE-D454100D4A25"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.10.0","versionEndExcluding":"18.8.7","matchCriteriaId":"36DF36AD-8660-4B56-8EF0-9C467117F89D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.3","matchCriteriaId":"96F7E7EC-4C2E-4A48-8134-9262B251C89C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.3","matchCriteriaId":"C3240349-67A3-43E2-BAD9-EFAA3E0A5D31"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.10.0:*:*:*:community:*:*:*","matchCriteriaId":"D5B6ECC9-6AEA-4DD0-B12B-A3A7A9FE91DA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.10.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"2B8DF779-B99E-4096-B734-78AB1849D136"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/03/25/patch-release-gitlab-18-10-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/580488","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3413704","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-13436","sourceIdentifier":"cve@gitlab.com","published":"2026-03-25T17:16:27.163","lastModified":"2026-06-17T08:34:08.617","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to cause a denial of service due to excessive resource consumption when handling certain CI-related inputs."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab CE/EE que afecta a todas las versiones desde la 13.7 antes de la 18.8.7, la 18.9 antes de la 18.9.3, y la 18.10 antes de la 18.10.1 que podría haber permitido a un usuario autenticado causar una denegación de servicio debido al consumo excesivo de recursos al manejar ciertas entradas relacionadas con CI."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"13.7","lessThan":"18.8.7","versionType":"semver","status":"affected"},{"version":"18.9","lessThan":"18.9.3","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-25T17:03:46.990746Z","id":"CVE-2025-13436","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"18.8.7","matchCriteriaId":"946B195B-BD75-4727-B507-E8C9B53F3B15"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"18.8.7","matchCriteriaId":"99CF3B34-E11C-47C7-8F9D-188BF5CB5BB6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.3","matchCriteriaId":"96F7E7EC-4C2E-4A48-8134-9262B251C89C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.3","matchCriteriaId":"C3240349-67A3-43E2-BAD9-EFAA3E0A5D31"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.10.0:*:*:*:community:*:*:*","matchCriteriaId":"D5B6ECC9-6AEA-4DD0-B12B-A3A7A9FE91DA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.10.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"2B8DF779-B99E-4096-B734-78AB1849D136"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/03/25/patch-release-gitlab-18-10-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/581372","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3418149","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-14595","sourceIdentifier":"cve@gitlab.com","published":"2026-03-25T17:16:27.363","lastModified":"2026-06-17T08:36:14.403","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that under certain conditions could have allowed an authenticated user with Planner role to view security category metadata and attributes in group security configuration due to improper access control"},{"lang":"es","value":"GitLab ha remediado un problema en GitLab EE que afecta a todas las versiones desde la 18.6 anterior a la 18.8.7, la 18.9 anterior a la 18.9.3 y la 18.10 anterior a la 18.10.1 que bajo ciertas condiciones podría haber permitido a un usuario autenticado con rol de Planificador ver metadatos y atributos de categoría de seguridad en la configuración de seguridad del grupo debido a un control de acceso inadecuado."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.6","lessThan":"18.8.7","versionType":"semver","status":"affected"},{"version":"18.9","lessThan":"18.9.3","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-27T14:58:30.286645Z","id":"CVE-2025-14595","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.6.0","versionEndExcluding":"18.8.7","matchCriteriaId":"DEB82ED4-D7EE-476D-B925-3B1244A34599"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.6.0","versionEndExcluding":"18.8.7","matchCriteriaId":"E97386DE-180F-4FD1-AC93-F3263F55C540"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.3","matchCriteriaId":"96F7E7EC-4C2E-4A48-8134-9262B251C89C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.3","matchCriteriaId":"C3240349-67A3-43E2-BAD9-EFAA3E0A5D31"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.10.0:*:*:*:community:*:*:*","matchCriteriaId":"D5B6ECC9-6AEA-4DD0-B12B-A3A7A9FE91DA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.10.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"2B8DF779-B99E-4096-B734-78AB1849D136"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/03/25/patch-release-gitlab-18-10-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/583971","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3457779","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-1724","sourceIdentifier":"cve@gitlab.com","published":"2026-03-25T17:16:29.943","lastModified":"2026-06-17T10:16:24.103","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 18.5 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an unauthenticated user to access API tokens of self-hosted AI models due to improper access control."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab EE que afectaba a todas las versiones desde la 18.5 anterior a la 18.8.7, la 18.9 anterior a la 18.9.3 y la 18.10 anterior a la 18.10.1 que podría haber permitido a un usuario no autenticado acceder a los tokens de la API de modelos de IA autoalojados debido a un control de acceso inadecuado."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.5","lessThan":"18.8.7","versionType":"semver","status":"affected"},{"version":"18.9","lessThan":"18.9.3","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N","baseScore":6.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":4.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-27T14:59:08.175770Z","id":"CVE-2026-1724","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-306"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.5.0","versionEndExcluding":"18.8.7","matchCriteriaId":"91B89AFE-E378-447B-99AB-627A8BE12907"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.3","matchCriteriaId":"C3240349-67A3-43E2-BAD9-EFAA3E0A5D31"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.10.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"2B8DF779-B99E-4096-B734-78AB1849D136"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/03/25/patch-release-gitlab-18-10-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/588334","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3531412","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-2726","sourceIdentifier":"cve@gitlab.com","published":"2026-03-25T17:16:57.640","lastModified":"2026-06-17T10:31:36.740","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to perform unauthorized actions on merge requests in other projects due to improper access control during cross-repository operations."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab CE/EE que afecta a todas las versiones desde la 11.10 anterior a la 18.8.7, la 18.9 anterior a la 18.9.3, y la 18.10 anterior a la 18.10.1 que podría haber permitido a un usuario autenticado realizar acciones no autorizadas en solicitudes de fusión en otros proyectos debido a un control de acceso inadecuado durante operaciones entre repositorios."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"11.10","lessThan":"18.8.7","versionType":"semver","status":"affected"},{"version":"18.9","lessThan":"18.9.3","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-25T17:14:29.737181Z","id":"CVE-2026-2726","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.10.0","versionEndExcluding":"18.8.7","matchCriteriaId":"9BE6F7AF-744F-47CA-B1F1-878BDF61FCD1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.10.0","versionEndExcluding":"18.8.7","matchCriteriaId":"74034C2D-481F-469C-8DD2-DAF9F254A47D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.3","matchCriteriaId":"96F7E7EC-4C2E-4A48-8134-9262B251C89C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.3","matchCriteriaId":"C3240349-67A3-43E2-BAD9-EFAA3E0A5D31"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.10.0:*:*:*:community:*:*:*","matchCriteriaId":"D5B6ECC9-6AEA-4DD0-B12B-A3A7A9FE91DA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.10.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"2B8DF779-B99E-4096-B734-78AB1849D136"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/03/25/patch-release-gitlab-18-10-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/590717","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3543886","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-2745","sourceIdentifier":"cve@gitlab.com","published":"2026-03-25T17:16:57.803","lastModified":"2026-06-17T10:31:38.687","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 7.11 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an unauthenticated user to bypass WebAuthn two-factor authentication and gain unauthorized access to user accounts due to inconsistent input validation in the authentication process."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab CE/EE que afecta a todas las versiones desde la 7.11 anterior a la 18.8.7, la 18.9 anterior a la 18.9.3, y la 18.10 anterior a la 18.10.1 que podría haber permitido a un usuario no autenticado eludir la autenticación de dos factores de WebAuthn y obtener acceso no autorizado a cuentas de usuario debido a una validación de entrada inconsistente en el proceso de autenticación."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"7.11","lessThan":"18.8.7","versionType":"semver","status":"affected"},{"version":"18.9","lessThan":"18.9.3","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","baseScore":6.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-25T00:00:00+00:00","id":"CVE-2026-2745","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-288"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"7.11.0","versionEndExcluding":"18.8.7","matchCriteriaId":"BC1BE350-F69B-4723-9253-3AD72B05258E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"7.11.0","versionEndExcluding":"18.8.7","matchCriteriaId":"61B4B116-5BAD-4AA0-BC4F-E6306107497F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.3","matchCriteriaId":"96F7E7EC-4C2E-4A48-8134-9262B251C89C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.3","matchCriteriaId":"C3240349-67A3-43E2-BAD9-EFAA3E0A5D31"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.10.0:*:*:*:community:*:*:*","matchCriteriaId":"D5B6ECC9-6AEA-4DD0-B12B-A3A7A9FE91DA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.10.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"2B8DF779-B99E-4096-B734-78AB1849D136"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/03/25/patch-release-gitlab-18-10-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/590810","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3557844","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-2973","sourceIdentifier":"cve@gitlab.com","published":"2026-03-25T17:16:58.183","lastModified":"2026-06-17T10:32:08.977","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.7 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to execute arbitrary JavaScript in a user's browser due to improper sanitization of entity-encoded content in Mermaid diagrams."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab CE/EE que afecta a todas las versiones desde la 17.7 y anteriores a la 18.8.7, la 18.9 y anteriores a la 18.9.3, y la 18.10 y anteriores a la 18.10.1 que podría haber permitido a un usuario autenticado ejecutar JavaScript arbitrario en el navegador de un usuario debido a una sanitización incorrecta del contenido codificado por entidades en los diagramas de Mermaid."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.7","lessThan":"18.8.7","versionType":"semver","status":"affected"},{"version":"18.9","lessThan":"18.9.3","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-26T17:24:23.575803Z","id":"CVE-2026-2973","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.7.0","versionEndExcluding":"18.8.7","matchCriteriaId":"70E34BB8-A1A5-4A52-BC2D-D146F05CF974"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.7.0","versionEndExcluding":"18.8.7","matchCriteriaId":"A8AE2657-B060-4415-95A1-BC32BA1DC06B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.3","matchCriteriaId":"96F7E7EC-4C2E-4A48-8134-9262B251C89C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.3","matchCriteriaId":"C3240349-67A3-43E2-BAD9-EFAA3E0A5D31"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.10.0:*:*:*:community:*:*:*","matchCriteriaId":"D5B6ECC9-6AEA-4DD0-B12B-A3A7A9FE91DA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.10.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"2B8DF779-B99E-4096-B734-78AB1849D136"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/03/25/patch-release-gitlab-18-10-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/591049","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3566802","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-2995","sourceIdentifier":"cve@gitlab.com","published":"2026-03-25T17:16:58.347","lastModified":"2026-06-17T10:32:27.750","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 15.4 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to add email addresses to targeted user accounts due to improper sanitization of HTML content."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab EE que afecta a todas las versiones desde la 15.4 anteriores a la 18.8.7, la 18.9 anteriores a la 18.9.3, y la 18.10 anteriores a la 18.10.1 que podría haber permitido a un usuario autenticado añadir direcciones de correo electrónico a cuentas de usuario objetivo debido a una sanitización inadecuada del contenido HTML."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.4","lessThan":"18.8.7","versionType":"semver","status":"affected"},{"version":"18.9","lessThan":"18.9.3","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":7.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.3,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-26T03:55:35.901615Z","id":"CVE-2026-2995","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-80"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.4.0","versionEndExcluding":"18.8.7","matchCriteriaId":"022646FF-38A8-4EB1-A783-2C1E7DD3505A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.3","matchCriteriaId":"C3240349-67A3-43E2-BAD9-EFAA3E0A5D31"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.10.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"2B8DF779-B99E-4096-B734-78AB1849D136"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/03/25/patch-release-gitlab-18-10-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/591065","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3564600","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-3857","sourceIdentifier":"cve@gitlab.com","published":"2026-03-25T17:17:09.387","lastModified":"2026-06-17T10:44:20.953","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an unauthenticated user to execute arbitrary GraphQL mutations on behalf of authenticated users due to insufficient CSRF protection."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab CE/EE que afecta a todas las versiones desde la 17.10 anterior a la 18.8.7, la 18.9 anterior a la 18.9.3 y la 18.10 anterior a la 18.10.1 que podría haber permitido a un usuario no autenticado ejecutar mutaciones GraphQL arbitrarias en nombre de usuarios autenticados debido a una protección CSRF insuficiente."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.10","lessThan":"18.8.7","versionType":"semver","status":"affected"},{"version":"18.9","lessThan":"18.9.3","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-26T03:55:34.505033Z","id":"CVE-2026-3857","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-352"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.10.0","versionEndExcluding":"18.8.7","matchCriteriaId":"A562894A-828C-4621-85AD-6721BD73EEBE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.10.0","versionEndExcluding":"18.8.7","matchCriteriaId":"F87F2721-57D2-47B3-8B6C-D7C27720E50D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.3","matchCriteriaId":"96F7E7EC-4C2E-4A48-8134-9262B251C89C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.3","matchCriteriaId":"C3240349-67A3-43E2-BAD9-EFAA3E0A5D31"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.10.0:*:*:*:community:*:*:*","matchCriteriaId":"D5B6ECC9-6AEA-4DD0-B12B-A3A7A9FE91DA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.10.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"2B8DF779-B99E-4096-B734-78AB1849D136"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/03/25/patch-release-gitlab-18-10-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/592828","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3584382","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-3988","sourceIdentifier":"cve@gitlab.com","published":"2026-03-25T17:17:09.553","lastModified":"2026-06-17T10:44:34.603","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an unauthenticated user to cause a denial of service by making the GitLab instance unresponsive due to improper input validation in GraphQL request processing."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab CE/EE que afectaba a todas las versiones desde la 18.5 antes de la 18.8.7, la 18.9 antes de la 18.9.3 y la 18.10 antes de la 18.10.1 que podría haber permitido a un usuario no autenticado causar una denegación de servicio al hacer que la instancia de GitLab no respondiera debido a una validación de entrada incorrecta en el procesamiento de solicitudes GraphQL."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.5","lessThan":"18.8.7","versionType":"semver","status":"affected"},{"version":"18.9","lessThan":"18.9.3","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-25T17:21:45.431064Z","id":"CVE-2026-3988","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-407"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.5.0","versionEndExcluding":"18.8.7","matchCriteriaId":"991041A7-46AA-49CE-9AA0-D2BF561C4713"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.5.0","versionEndExcluding":"18.8.7","matchCriteriaId":"91B89AFE-E378-447B-99AB-627A8BE12907"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.3","matchCriteriaId":"96F7E7EC-4C2E-4A48-8134-9262B251C89C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.3","matchCriteriaId":"C3240349-67A3-43E2-BAD9-EFAA3E0A5D31"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.10.0:*:*:*:community:*:*:*","matchCriteriaId":"D5B6ECC9-6AEA-4DD0-B12B-A3A7A9FE91DA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.10.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"2B8DF779-B99E-4096-B734-78AB1849D136"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/03/25/patch-release-gitlab-18-10-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/593140","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3597342","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-2370","sourceIdentifier":"cve@gitlab.com","published":"2026-03-30T00:16:01.800","lastModified":"2026-07-15T02:19:30.360","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.3 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 affecting Jira Connect installations that could have allowed an authenticated user with minimal workspace permissions to obtain installation credentials and impersonate the GitLab app due to improper authorization checks."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab CE/EE que afecta a todas las versiones desde la 14.3 anteriores a la 18.8.7, la 18.9 anteriores a la 18.9.3 y la 18.10 anteriores a la 18.10.1, y que afecta a las instalaciones de Jira Connect, que podría haber permitido a un usuario autenticado con permisos mínimos de espacio de trabajo obtener credenciales de instalación e suplantar la aplicación de GitLab debido a comprobaciones de autorización incorrectas."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"14.3","lessThan":"18.8.7","versionType":"semver","status":"affected"},{"version":"18.9","lessThan":"18.9.3","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.1","versionType":"semver","status":"affected"}]}]},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","affectedData":[{"vendor":"Red Hat","product":"OpenShift Pipelines","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-pipelines/pipelines-console-plugin-rhel9","cpes":["cpe:/a:redhat:openshift_pipelines:1"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift4/ose-console","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift4/ose-console-rhel9","cpes":["cpe:/a:redhat:openshift:4"]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-30T15:01:52.806448Z","id":"CVE-2026-2370","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-233"}]},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","description":[{"lang":"en","value":"CWE-233"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.3.0","versionEndExcluding":"18.8.7","matchCriteriaId":"22F9C9B9-964C-421E-8CB5-B2FBE5E5A84F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.3.0","versionEndExcluding":"18.8.7","matchCriteriaId":"F419394A-3E12-4548-BD49-FF5027B9CFF7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.3","matchCriteriaId":"96F7E7EC-4C2E-4A48-8134-9262B251C89C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.3","matchCriteriaId":"C3240349-67A3-43E2-BAD9-EFAA3E0A5D31"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.10.0:*:*:*:community:*:*:*","matchCriteriaId":"D5B6ECC9-6AEA-4DD0-B12B-A3A7A9FE91DA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.10.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"2B8DF779-B99E-4096-B734-78AB1849D136"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/03/25/patch-release-gitlab-18-10-1-released/","source":"cve@gitlab.com","tags":["Patch","Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/589635","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3522829","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://access.redhat.com/security/cve/CVE-2026-2370","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2452920","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2370.json","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}]}},{"cve":{"id":"CVE-2025-12664","sourceIdentifier":"cve@gitlab.com","published":"2026-04-08T23:16:56.200","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an unauthenticated user to cause denial of service by sending repeated GraphQL queries."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab CE/EE que afecta a todas las versiones desde la 13.0 y anteriores a la 18.8.9, la 18.9 y anteriores a la 18.9.5, y la 18.10 y anteriores a la 18.10.3 que podría haber permitido a un usuario no autenticado causar denegación de servicio mediante el envío de consultas GraphQL repetidas."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"13.0","lessThan":"18.8.9","versionType":"semver","status":"affected"},{"version":"18.9","lessThan":"18.9.5","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-09T13:03:46.881882Z","id":"CVE-2025-12664","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1284"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.0.0","versionEndExcluding":"18.8.9","matchCriteriaId":"48E564F7-CB57-4A79-A921-BA28CF67C623"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.5","matchCriteriaId":"5C4D8A99-6E70-4D55-9ACF-FF2620F070E0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.3","matchCriteriaId":"DBCB346F-0B28-458B-A453-29DA4B0E91FC"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.0.0","versionEndExcluding":"18.8.9","matchCriteriaId":"69D195DE-D52F-4794-84F8-B88A736360A0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.5","matchCriteriaId":"3BA6A89D-D2C1-45B9-A8E8-64256816D880"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.3","matchCriteriaId":"BB2F3665-2451-4A4D-8538-93F540975F0E"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/04/08/patch-release-gitlab-18-10-3-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/579376","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3377091","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-9484","sourceIdentifier":"cve@gitlab.com","published":"2026-04-08T23:16:57.343","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 16.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that under certain circumstances could have allowed an authenticated user to have access to other users' email addresses via certain GraphQL queries."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab EE que afectaba a todas las versiones desde la 16.6 y anteriores a la 18.8.9, la 18.9 y anteriores a la 18.9.5, y la 18.10 y anteriores a la 18.10.3 que bajo ciertas circunstancias podría haber permitido a un usuario autenticado tener acceso a las direcciones de correo electrónico de otros usuarios a través de ciertas consultas GraphQL."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.6","lessThan":"18.8.9","versionType":"semver","status":"affected"},{"version":"18.9","lessThan":"18.9.5","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-09T13:03:07.698784Z","id":"CVE-2025-9484","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.6.0","versionEndExcluding":"18.8.9","matchCriteriaId":"935920C5-6C73-43AE-8CA5-80DBA520C1D9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.5","matchCriteriaId":"3BA6A89D-D2C1-45B9-A8E8-64256816D880"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.3","matchCriteriaId":"BB2F3665-2451-4A4D-8538-93F540975F0E"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/04/08/patch-release-gitlab-18-10-3-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/565363","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3303810","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-1092","sourceIdentifier":"cve@gitlab.com","published":"2026-04-08T23:16:57.510","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.10 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an unauthenticated user to cause denial of service due to improper input validation of JSON payloads."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab CE/EE que afectaba a todas las versiones desde la 12.10 antes de la 18.8.9, la 18.9 antes de la 18.9.5, y la 18.10 antes de la 18.10.3 que podría haber permitido a un usuario no autenticado causar denegación de servicio debido a una validación de entrada incorrecta de las cargas útiles JSON."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"12.10","lessThan":"18.8.9","versionType":"semver","status":"affected"},{"version":"18.9","lessThan":"18.9.5","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-09T15:09:43.259973Z","id":"CVE-2026-1092","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1284"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.10.0","versionEndExcluding":"18.8.9","matchCriteriaId":"4E41EACE-A6CA-490D-9592-4964BFBF6B76"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.5","matchCriteriaId":"3BA6A89D-D2C1-45B9-A8E8-64256816D880"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.3","matchCriteriaId":"BB2F3665-2451-4A4D-8538-93F540975F0E"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.10.0","versionEndExcluding":"18.8.9","matchCriteriaId":"41952659-B58E-4EB8-976C-AA43350A39F6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.5","matchCriteriaId":"5C4D8A99-6E70-4D55-9ACF-FF2620F070E0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.3","matchCriteriaId":"DBCB346F-0B28-458B-A453-29DA4B0E91FC"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/04/08/patch-release-gitlab-18-10-3-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/586479","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3487030","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-1101","sourceIdentifier":"cve@gitlab.com","published":"2026-04-08T23:16:57.667","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user to cause denial of service to the GitLab instance due to improper input validation in GraphQL queries."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab EE que afectaba a todas las versiones desde la 18.2 anterior a la 18.8.9, la 18.9 anterior a la 18.9.5 y la 18.10 anterior a la 18.10.3 que podría haber permitido a un usuario autenticado causar una denegación de servicio a la instancia de GitLab debido a una validación de entrada incorrecta en las consultas GraphQL."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.2","lessThan":"18.8.9","versionType":"semver","status":"affected"},{"version":"18.9","lessThan":"18.9.5","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-09T15:40:51.074249Z","id":"CVE-2026-1101","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1284"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.2","versionEndExcluding":"18.8.9","matchCriteriaId":"DE6B64C1-04D6-4E07-A730-72DD62AB9443"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.5","matchCriteriaId":"3BA6A89D-D2C1-45B9-A8E8-64256816D880"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.3","matchCriteriaId":"BB2F3665-2451-4A4D-8538-93F540975F0E"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/04/08/patch-release-gitlab-18-10-3-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/586488","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3460228","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-1516","sourceIdentifier":"cve@gitlab.com","published":"2026-04-08T23:16:57.920","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 18.0.0 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that in Code Quality reports could have allowed an authenticated user to leak IP addresses of users viewing the report via specially crafted content."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab EE que afectaba a todas las versiones desde la 18.0.0 anteriores a la 18.8.9, la 18.9 anteriores a la 18.9.5, y la 18.10 anteriores a la 18.10.3 que en los informes de Calidad de Código podría haber permitido a un usuario autenticado filtrar direcciones IP de usuarios que visualizaban el informe a través de contenido especialmente diseñado."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.0.0","lessThan":"18.8.9","versionType":"semver","status":"affected"},{"version":"18.9","lessThan":"18.9.5","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N","baseScore":5.7,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-09T15:42:16.466494Z","id":"CVE-2026-1516","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-94"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.0.0","versionEndExcluding":"18.8.9","matchCriteriaId":"E44C8A18-7C71-4626-85E4-9753A7039A03"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.5","matchCriteriaId":"3BA6A89D-D2C1-45B9-A8E8-64256816D880"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.3","matchCriteriaId":"BB2F3665-2451-4A4D-8538-93F540975F0E"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/04/08/patch-release-gitlab-18-10-3-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/587893","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3514461","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-1752","sourceIdentifier":"cve@gitlab.com","published":"2026-04-08T23:16:58.077","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 11.3 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user with developer-role permissions to modify protected environment settings due to improper authorization checks in the API."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab EE que afecta a todas las versiones desde la 11.3 anterior a la 18.8.9, la 18.9 anterior a la 18.9.5 y la 18.10 anterior a la 18.10.3 que podría haber permitido a un usuario autenticado con permisos de rol de desarrollador modificar la configuración de entornos protegidos debido a comprobaciones de autorización incorrectas en la API."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"11.3","lessThan":"18.8.9","versionType":"semver","status":"affected"},{"version":"18.9","lessThan":"18.9.5","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-09T14:58:34.582561Z","id":"CVE-2026-1752","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"18.8.9","matchCriteriaId":"680D11CA-8B72-40D6-B510-852E4E7C5DE9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.5","matchCriteriaId":"3BA6A89D-D2C1-45B9-A8E8-64256816D880"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.3","matchCriteriaId":"BB2F3665-2451-4A4D-8538-93F540975F0E"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/04/08/patch-release-gitlab-18-10-3-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/588413","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3533545","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-2104","sourceIdentifier":"cve@gitlab.com","published":"2026-04-08T23:16:58.393","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user to access confidential issues assigned to other users via CSV export due to insufficient authorization checks."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab CE/EE que afecta a todas las versiones desde la 18.2 anterior a la 18.8.9, la 18.9 anterior a la 18.9.5 y la 18.10 anterior a la 18.10.3 que podría haber permitido a un usuario autenticado acceder a problemas confidenciales asignados a otros usuarios a través de la exportación CSV debido a comprobaciones de autorización insuficientes."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.2","lessThan":"18.8.9","versionType":"semver","status":"affected"},{"version":"18.9","lessThan":"18.9.5","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-09T15:43:15.918452Z","id":"CVE-2026-2104","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-639"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"18.8.9","matchCriteriaId":"CFAD5EB0-9700-4C16-AEF0-27599F84541F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.5","matchCriteriaId":"3BA6A89D-D2C1-45B9-A8E8-64256816D880"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.3","matchCriteriaId":"BB2F3665-2451-4A4D-8538-93F540975F0E"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"18.8.9","matchCriteriaId":"6E8B1FB2-AA24-4447-8403-F082B4DCA62A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.5","matchCriteriaId":"5C4D8A99-6E70-4D55-9ACF-FF2620F070E0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.3","matchCriteriaId":"DBCB346F-0B28-458B-A453-29DA4B0E91FC"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/04/08/patch-release-gitlab-18-10-3-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/589021","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3541476","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-2619","sourceIdentifier":"cve@gitlab.com","published":"2026-04-08T23:16:58.557","lastModified":"2026-07-20T20:10:00.110","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that under certain circumstances could have allowed an authenticated user with auditor privileges to modify vulnerability flag data in private projects due to incorrect authorization."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab EE que afecta a todas las versiones desde la 18.6 anterior a la 18.8.9, la 18.9 anterior a la 18.9.5, y la 18.10 anterior a la 18.10.3 que bajo ciertas circunstancias podría haber permitido a un usuario autenticado con privilegios de auditor modificar datos de indicadores de vulnerabilidad en proyectos privados debido a una autorización incorrecta."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.6","lessThan":"18.8.9","versionType":"semver","status":"affected"},{"version":"18.9","lessThan":"18.9.5","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-09T13:04:19.434883Z","id":"CVE-2026-2619","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.6.0","versionEndExcluding":"18.8.9","matchCriteriaId":"13D9228E-DCC9-4811-B395-8B36ED4F84BE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.5","matchCriteriaId":"3BA6A89D-D2C1-45B9-A8E8-64256816D880"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.3","matchCriteriaId":"BB2F3665-2451-4A4D-8538-93F540975F0E"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/04/08/patch-release-gitlab-18-10-3-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/590430","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3554982","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-4332","sourceIdentifier":"cve@gitlab.com","published":"2026-04-08T23:16:59.683","lastModified":"2026-07-24T20:10:00.147","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that, in customizable analytics dashboards, could have allowed an authenticated user to execute arbitrary JavaScript in the context of other users' browsers due to improper input sanitization."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab EE que afecta a todas las versiones desde la 18.2 anterior a la 18.8.9, la 18.9 anterior a la 18.9.5, y la 18.10 anterior a la 18.10.3 que, en los paneles de análisis personalizables, podría haber permitido a un usuario autenticado ejecutar JavaScript arbitrario en el contexto de los navegadores de otros usuarios debido a una sanitización de entrada incorrecta."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.2","lessThan":"18.8.9","versionType":"semver","status":"affected"},{"version":"18.9","lessThan":"18.9.5","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-09T13:04:56.534709Z","id":"CVE-2026-4332","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"18.8.9","matchCriteriaId":"CFAD5EB0-9700-4C16-AEF0-27599F84541F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.5","matchCriteriaId":"3BA6A89D-D2C1-45B9-A8E8-64256816D880"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.3","matchCriteriaId":"BB2F3665-2451-4A4D-8538-93F540975F0E"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/04/08/patch-release-gitlab-18-10-3-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/593853","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3600345","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-4398","sourceIdentifier":"cve@gitlab.com","published":"2026-04-08T23:16:59.907","lastModified":"2026-08-28T16:18:13.620","vulnStatus":"Awaiting Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user could have assigned compliance frameworks from namespaces they were not authorized to access to their own project, due to missing namespace validation on self-managed instances."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.3","lessThan":"19.1.7","versionType":"semver","status":"affected"},{"version":"19.2","lessThan":"19.2.5","versionType":"semver","status":"affected"},{"version":"19.3","lessThan":"19.3.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-28T13:58:41.461501Z","id":"CVE-2026-4398","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-639"}]}],"references":[{"url":"https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-1-released/","source":"cve@gitlab.com"},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/600360","source":"cve@gitlab.com"},{"url":"https://hackerone.com/reports/3549150","source":"cve@gitlab.com"}]}},{"cve":{"id":"CVE-2026-4916","sourceIdentifier":"cve@gitlab.com","published":"2026-04-08T23:17:00.053","lastModified":"2026-07-24T20:10:00.147","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user with custom role permissions to demote or remove higher-privileged group members due to improper authorization checks on member management operations."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab CE/EE que afecta a todas las versiones 18.2 anteriores a la 18.8.9, 18.9 anteriores a la 18.9.5 y 18.10 anteriores a la 18.10.3 que podría haber permitido a un usuario autenticado con permisos de rol personalizados degradar o eliminar miembros del grupo con mayores privilegios debido a comprobaciones de autorización incorrectas en operaciones de gestión de miembros."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.2","lessThan":"18.8.9","versionType":"semver","status":"affected"},{"version":"18.9","lessThan":"18.9.5","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N","baseScore":2.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-09T13:05:47.114773Z","id":"CVE-2026-4916","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"18.8.9","matchCriteriaId":"CFAD5EB0-9700-4C16-AEF0-27599F84541F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.5","matchCriteriaId":"3BA6A89D-D2C1-45B9-A8E8-64256816D880"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.3","matchCriteriaId":"BB2F3665-2451-4A4D-8538-93F540975F0E"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"18.8.9","matchCriteriaId":"6E8B1FB2-AA24-4447-8403-F082B4DCA62A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.5","matchCriteriaId":"5C4D8A99-6E70-4D55-9ACF-FF2620F070E0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.3","matchCriteriaId":"DBCB346F-0B28-458B-A453-29DA4B0E91FC"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/04/08/patch-release-gitlab-18-10-3-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/565414","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3301240","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-5173","sourceIdentifier":"cve@gitlab.com","published":"2026-04-08T23:17:00.220","lastModified":"2026-07-24T20:10:00.147","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.9.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user to invoke unintended server-side methods through websocket connections due to improper access control."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab CE/EE que afecta a todas las versiones desde la 16.9.6 hasta las previas a la 18.8.9, la 18.9 hasta las previas a la 18.9.5, y la 18.10 hasta las previas a la 18.10.3 que podría haber permitido a un usuario autenticado invocar métodos de lado del servidor no intencionados a través de conexiones websocket debido a un control de acceso inadecuado."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.9.6","lessThan":"18.8.9","versionType":"semver","status":"affected"},{"version":"18.9","lessThan":"18.9.5","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N","baseScore":8.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":4.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-09T13:16:45.655060Z","id":"CVE-2026-5173","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-749"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.9.6","versionEndExcluding":"18.8.9","matchCriteriaId":"4C2970CC-B6D7-43CB-9E8C-D7F50DD13BD6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.5","matchCriteriaId":"3BA6A89D-D2C1-45B9-A8E8-64256816D880"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.3","matchCriteriaId":"BB2F3665-2451-4A4D-8538-93F540975F0E"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.9.6","versionEndExcluding":"18.8.9","matchCriteriaId":"50442516-A352-4018-AC06-22242834A510"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.5","matchCriteriaId":"5C4D8A99-6E70-4D55-9ACF-FF2620F070E0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.3","matchCriteriaId":"DBCB346F-0B28-458B-A453-29DA4B0E91FC"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/04/08/patch-release-gitlab-18-10-3-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/588959","source":"cve@gitlab.com","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2025-0186","sourceIdentifier":"cve@gitlab.com","published":"2026-04-22T17:16:32.950","lastModified":"2026-06-17T08:26:02.277","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that could have allowed an authenticated user to cause denial of service under certain conditions by exhausting server resources by making crafted requests to a discussions endpoint."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"10.6","lessThan":"18.9.6","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.4","versionType":"semver","status":"affected"},{"version":"18.11","lessThan":"18.11.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-22T17:24:41.549479Z","id":"CVE-2025-0186","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.6.0","versionEndExcluding":"18.9.6","matchCriteriaId":"56DFBE31-2EAF-4E41-A5DF-D4073223C285"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.6.0","versionEndExcluding":"18.9.6","matchCriteriaId":"94DA81FB-D270-48E8-AF76-A9000CE943FA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.4","matchCriteriaId":"98D16D9B-6A45-45F3-934B-3ED95C8371BF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.4","matchCriteriaId":"58B8096F-9D7B-403D-B685-E9D4FA24F3E5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.11.0:*:*:*:community:*:*:*","matchCriteriaId":"A6100523-821F-4F41-872D-AC5A60EECC19"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.11.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"C78F9577-CDD5-497B-A92F-3C578AC6709E"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/04/22/patch-release-gitlab-18-11-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/511312","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2915694","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-3922","sourceIdentifier":"cve@gitlab.com","published":"2026-04-22T17:16:33.123","lastModified":"2026-06-17T09:20:56.033","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.4 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that could have allowed an authenticated user to cause denial of service by overwhelming system resources under certain conditions due to insufficient resource allocation limits in the GraphQL API."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"12.4","lessThan":"18.9.6","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.4","versionType":"semver","status":"affected"},{"version":"18.11","lessThan":"18.11.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-22T17:27:36.090684Z","id":"CVE-2025-3922","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.4.0","versionEndExcluding":"18.9.6","matchCriteriaId":"A8C006EB-2168-4565-BA7D-0D14969C3E77"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.4.0","versionEndExcluding":"18.9.6","matchCriteriaId":"41D67F06-D700-4323-8893-9AD616F8E965"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.4","matchCriteriaId":"98D16D9B-6A45-45F3-934B-3ED95C8371BF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.4","matchCriteriaId":"58B8096F-9D7B-403D-B685-E9D4FA24F3E5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.11.0:*:*:*:community:*:*:*","matchCriteriaId":"A6100523-821F-4F41-872D-AC5A60EECC19"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.11.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"C78F9577-CDD5-497B-A92F-3C578AC6709E"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/04/22/patch-release-gitlab-18-11-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/537422","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3098035","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-6016","sourceIdentifier":"cve@gitlab.com","published":"2026-04-22T17:16:33.410","lastModified":"2026-06-17T10:00:59.673","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.2 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that could have allowed an authenticated user to cause denial of service due to insufficient resource allocation limits when retrieving notes under certain conditions."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"9.2","lessThan":"18.9.6","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.4","versionType":"semver","status":"affected"},{"version":"18.11","lessThan":"18.11.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-22T17:30:23.809273Z","id":"CVE-2025-6016","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"9.2.0","versionEndExcluding":"18.9.6","matchCriteriaId":"BEBC9124-7EA1-4AE4-95C7-04CE72F90780"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"9.2.0","versionEndExcluding":"18.9.6","matchCriteriaId":"F475B5A5-C6EE-4F9C-843B-F356B7546C90"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.4","matchCriteriaId":"98D16D9B-6A45-45F3-934B-3ED95C8371BF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.4","matchCriteriaId":"58B8096F-9D7B-403D-B685-E9D4FA24F3E5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.11.0:*:*:*:community:*:*:*","matchCriteriaId":"A6100523-821F-4F41-872D-AC5A60EECC19"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.11.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"C78F9577-CDD5-497B-A92F-3C578AC6709E"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/04/22/patch-release-gitlab-18-11-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/548940","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3160363","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-9957","sourceIdentifier":"cve@gitlab.com","published":"2026-04-22T17:16:33.557","lastModified":"2026-06-17T10:10:09.230","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.2 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that under certain conditions could have allowed an authenticated user with project owner permissions to bypass group fork prevention settings due to improper authorization checks."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"11.2","lessThan":"18.9.6","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.4","versionType":"semver","status":"affected"},{"version":"18.11","lessThan":"18.11.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N","baseScore":2.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-22T17:33:26.222226Z","id":"CVE-2025-9957","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.2.0","versionEndExcluding":"18.9.6","matchCriteriaId":"9B5F84F8-7A9E-4B0F-81DD-71535EB1516C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.2.0","versionEndExcluding":"18.9.6","matchCriteriaId":"2E02C3EE-D0C8-4AC3-8095-7F25A2DB5F1D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.4","matchCriteriaId":"98D16D9B-6A45-45F3-934B-3ED95C8371BF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.4","matchCriteriaId":"58B8096F-9D7B-403D-B685-E9D4FA24F3E5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.11.0:*:*:*:community:*:*:*","matchCriteriaId":"A6100523-821F-4F41-872D-AC5A60EECC19"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.11.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"C78F9577-CDD5-497B-A92F-3C578AC6709E"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/04/22/patch-release-gitlab-18-11-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/567781","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3275222","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-1660","sourceIdentifier":"cve@gitlab.com","published":"2026-04-22T17:16:33.697","lastModified":"2026-06-17T10:16:16.243","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.3 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that under certain conditions could have allowed an authenticated user to cause denial of service when importing issues due to improper input validation."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"12.3","lessThan":"18.9.6","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.4","versionType":"semver","status":"affected"},{"version":"18.11","lessThan":"18.11.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-22T17:38:02.392370Z","id":"CVE-2026-1660","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.3.0","versionEndExcluding":"18.9.6","matchCriteriaId":"645F1F94-5DB2-4F63-A978-29F67486FD8C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.3.0","versionEndExcluding":"18.9.6","matchCriteriaId":"4ED51050-8CA2-4875-AA85-5E2AD7E8C884"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.4","matchCriteriaId":"98D16D9B-6A45-45F3-934B-3ED95C8371BF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.4","matchCriteriaId":"58B8096F-9D7B-403D-B685-E9D4FA24F3E5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.11.0:*:*:*:community:*:*:*","matchCriteriaId":"A6100523-821F-4F41-872D-AC5A60EECC19"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.11.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"C78F9577-CDD5-497B-A92F-3C578AC6709E"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/04/22/patch-release-gitlab-18-11-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/588200","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3518743","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-3254","sourceIdentifier":"cve@gitlab.com","published":"2026-04-22T17:16:43.433","lastModified":"2026-06-17T10:43:16.920","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.11 before 18.11.1 that under certain conditions could have allowed an authenticated user to load unauthorized content into another user's browser due to improper input validation in the Mermaid sandbox."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.11","lessThan":"18.11.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N","baseScore":3.5,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-22T17:39:38.576809Z","id":"CVE-2026-3254","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1021"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.11.0:*:*:*:community:*:*:*","matchCriteriaId":"A6100523-821F-4F41-872D-AC5A60EECC19"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.11.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"C78F9577-CDD5-497B-A92F-3C578AC6709E"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/591587","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3572752","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-4922","sourceIdentifier":"cve@gitlab.com","published":"2026-04-22T17:16:44.277","lastModified":"2026-06-17T10:57:27.637","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.0 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that could have allowed an unauthenticated user to execute GraphQL mutations on behalf of authenticated users due to insufficient CSRF protection."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.0","lessThan":"18.9.6","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.4","versionType":"semver","status":"affected"},{"version":"18.11","lessThan":"18.11.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-23T00:00:00+00:00","id":"CVE-2026-4922","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-352"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"18.9.6","matchCriteriaId":"F68571FC-0B09-47F5-9C9B-05EC01C062BC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"18.9.6","matchCriteriaId":"5C6C1021-1F58-4C4D-9349-9AB16C923AB0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.4","matchCriteriaId":"98D16D9B-6A45-45F3-934B-3ED95C8371BF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.4","matchCriteriaId":"58B8096F-9D7B-403D-B685-E9D4FA24F3E5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.11.0:*:*:*:community:*:*:*","matchCriteriaId":"A6100523-821F-4F41-872D-AC5A60EECC19"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.11.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"C78F9577-CDD5-497B-A92F-3C578AC6709E"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/04/22/patch-release-gitlab-18-11-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/594937","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3627285","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-5262","sourceIdentifier":"cve@gitlab.com","published":"2026-04-22T17:16:44.437","lastModified":"2026-06-17T10:58:42.310","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.1.0 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that under certain conditions could have allowed an unauthenticated user to access tokens in the Storybook development environment due to improper input validation."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.1.0","lessThan":"18.9.6","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.4","versionType":"semver","status":"affected"},{"version":"18.11","lessThan":"18.11.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N","baseScore":8.0,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-22T18:08:25.203207Z","id":"CVE-2026-5262","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.1.0","versionEndExcluding":"18.9.6","matchCriteriaId":"F3F88F81-2243-4313-A2BE-831156C31094"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.1.0","versionEndExcluding":"18.9.6","matchCriteriaId":"724502CD-C6FC-4080-8D82-5465B8FD6AB8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.4","matchCriteriaId":"98D16D9B-6A45-45F3-934B-3ED95C8371BF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.4","matchCriteriaId":"58B8096F-9D7B-403D-B685-E9D4FA24F3E5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.11.0:*:*:*:community:*:*:*","matchCriteriaId":"A6100523-821F-4F41-872D-AC5A60EECC19"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.11.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"C78F9577-CDD5-497B-A92F-3C578AC6709E"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/04/22/patch-release-gitlab-18-11-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/595332","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3574642","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-5377","sourceIdentifier":"cve@gitlab.com","published":"2026-04-22T17:16:44.613","lastModified":"2026-06-17T10:58:55.843","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.11 before 18.11.1 that could have allowed an authenticated user to access titles of confidential or private issues in public projects due to improper access control in the issue description rendering process."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.11","lessThan":"18.11.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-22T17:52:07.159068Z","id":"CVE-2026-5377","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.11.0:*:*:*:community:*:*:*","matchCriteriaId":"A6100523-821F-4F41-872D-AC5A60EECC19"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.11.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"C78F9577-CDD5-497B-A92F-3C578AC6709E"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/04/22/patch-release-gitlab-18-11-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/595553","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3640688","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-5816","sourceIdentifier":"cve@gitlab.com","published":"2026-04-22T17:16:44.763","lastModified":"2026-06-17T10:59:41.650","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.10.4 and 18.11 before 18.11.1 that could have allowed an unauthenticated user to execute arbitrary JavaScript in a user's browser session due to improper path validation under certain conditions."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.10","lessThan":"18.10.4","versionType":"semver","status":"affected"},{"version":"18.11","lessThan":"18.11.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N","baseScore":8.0,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-22T00:00:00+00:00","id":"CVE-2026-5816","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-41"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.4","matchCriteriaId":"98D16D9B-6A45-45F3-934B-3ED95C8371BF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.4","matchCriteriaId":"58B8096F-9D7B-403D-B685-E9D4FA24F3E5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.11.0:*:*:*:community:*:*:*","matchCriteriaId":"A6100523-821F-4F41-872D-AC5A60EECC19"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.11.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"C78F9577-CDD5-497B-A92F-3C578AC6709E"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/04/22/patch-release-gitlab-18-11-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/592816","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3572231","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-6515","sourceIdentifier":"cve@gitlab.com","published":"2026-04-22T17:16:44.923","lastModified":"2026-06-17T11:00:54.937","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that could have allowed a user to use invalidated or incorrectly scoped credentials to access Virtual Registries under certain conditions."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.2","lessThan":"18.9.6","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.4","versionType":"semver","status":"affected"},{"version":"18.11","lessThan":"18.11.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-22T17:50:48.419094Z","id":"CVE-2026-6515","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-613"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"18.9.6","matchCriteriaId":"290D3AC1-6A70-4070-98D0-A78A47B2AF59"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"18.9.6","matchCriteriaId":"11CFC80F-6935-49C1-B3C6-E6F80BE6A710"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.4","matchCriteriaId":"98D16D9B-6A45-45F3-934B-3ED95C8371BF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.4","matchCriteriaId":"58B8096F-9D7B-403D-B685-E9D4FA24F3E5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.11.0:*:*:*:community:*:*:*","matchCriteriaId":"A6100523-821F-4F41-872D-AC5A60EECC19"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.11.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"C78F9577-CDD5-497B-A92F-3C578AC6709E"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/04/22/patch-release-gitlab-18-11-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/595993","source":"cve@gitlab.com","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2025-12669","sourceIdentifier":"cve@gitlab.com","published":"2026-05-14T06:16:19.370","lastModified":"2026-06-17T08:32:46.530","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to inject HTML and JavaScript into email notifications sent to other users due to improper input sanitization."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.11","lessThan":"18.9.7","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.6","versionType":"semver","status":"affected"},{"version":"18.11","lessThan":"18.11.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-14T17:46:54.867865Z","id":"CVE-2025-12669","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-94"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.11.0","versionEndExcluding":"18.9.7","matchCriteriaId":"623B188B-8EC5-436E-80C6-1B5CB8D41BEB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.11.0","versionEndExcluding":"18.9.7","matchCriteriaId":"91908ABD-B01C-4F31-985A-9C746595C5AD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.6","matchCriteriaId":"98488AF5-9D73-47EC-B7CB-41766FBC3774"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.6","matchCriteriaId":"E79D4F10-88B3-4AA7-BC5E-3FC8FA698969"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.3","matchCriteriaId":"4215ACCD-67B6-4394-AD76-1CE39077FCD2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.3","matchCriteriaId":"DA0D6580-3530-4D76-81CE-D852BCE0D411"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/05/13/patch-release-gitlab-18-11-3-released/","source":"cve@gitlab.com","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/579385","source":"cve@gitlab.com","tags":["Not Applicable"]},{"url":"https://hackerone.com/reports/3368096","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-13874","sourceIdentifier":"cve@gitlab.com","published":"2026-05-14T06:16:20.617","lastModified":"2026-06-17T08:34:54.390","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.1 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with Guest permissions to view issues in projects they were not authorized to access."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.1","lessThan":"18.9.7","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.6","versionType":"semver","status":"affected"},{"version":"18.11","lessThan":"18.11.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-14T17:44:55.100220Z","id":"CVE-2025-13874","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-639"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.1.0","versionEndExcluding":"18.9.7","matchCriteriaId":"174B08BE-32EF-415A-95FB-F94BCBAF81A2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.1.0","versionEndExcluding":"18.9.7","matchCriteriaId":"096989C0-1550-4EBA-8A46-9F5EA69705EB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.6","matchCriteriaId":"98488AF5-9D73-47EC-B7CB-41766FBC3774"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.6","matchCriteriaId":"E79D4F10-88B3-4AA7-BC5E-3FC8FA698969"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.3","matchCriteriaId":"4215ACCD-67B6-4394-AD76-1CE39077FCD2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.3","matchCriteriaId":"DA0D6580-3530-4D76-81CE-D852BCE0D411"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/05/13/patch-release-gitlab-18-11-3-released/","source":"cve@gitlab.com","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/582634","source":"cve@gitlab.com","tags":["Not Applicable"]},{"url":"https://hackerone.com/reports/3445398","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-14869","sourceIdentifier":"cve@gitlab.com","published":"2026-05-14T06:16:20.757","lastModified":"2026-06-17T08:36:41.117","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to cause denial of service by sending specially crafted payloads on certain API endpoints."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.5","lessThan":"18.9.7","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.6","versionType":"semver","status":"affected"},{"version":"18.11","lessThan":"18.11.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-14T17:43:39.358756Z","id":"CVE-2025-14869","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1284"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.5.0","versionEndExcluding":"18.9.7","matchCriteriaId":"BD6C8F39-DD9B-4435-93CC-8CDADB54235D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.5.0","versionEndExcluding":"18.9.7","matchCriteriaId":"DC3C80A7-2DB1-41D2-B6A4-47F8DD0353BA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.6","matchCriteriaId":"98488AF5-9D73-47EC-B7CB-41766FBC3774"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.6","matchCriteriaId":"E79D4F10-88B3-4AA7-BC5E-3FC8FA698969"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.3","matchCriteriaId":"4215ACCD-67B6-4394-AD76-1CE39077FCD2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.3","matchCriteriaId":"DA0D6580-3530-4D76-81CE-D852BCE0D411"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/05/13/patch-release-gitlab-18-11-3-released/","source":"cve@gitlab.com","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/584489","source":"cve@gitlab.com","tags":["Not Applicable"]},{"url":"https://hackerone.com/reports/3447146","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-14870","sourceIdentifier":"cve@gitlab.com","published":"2026-05-14T06:16:20.887","lastModified":"2026-06-17T08:36:41.230","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to cause denial of service by sending specially crafted JSON payloads due to insufficient input validation."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.5","lessThan":"18.9.7","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.6","versionType":"semver","status":"affected"},{"version":"18.11","lessThan":"18.11.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-14T13:02:46.629087Z","id":"CVE-2025-14870","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.5.0","versionEndExcluding":"18.9.7","matchCriteriaId":"BD6C8F39-DD9B-4435-93CC-8CDADB54235D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.5.0","versionEndExcluding":"18.9.7","matchCriteriaId":"DC3C80A7-2DB1-41D2-B6A4-47F8DD0353BA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.6","matchCriteriaId":"98488AF5-9D73-47EC-B7CB-41766FBC3774"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.6","matchCriteriaId":"E79D4F10-88B3-4AA7-BC5E-3FC8FA698969"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.3","matchCriteriaId":"4215ACCD-67B6-4394-AD76-1CE39077FCD2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.3","matchCriteriaId":"DA0D6580-3530-4D76-81CE-D852BCE0D411"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/05/13/patch-release-gitlab-18-11-3-released/","source":"cve@gitlab.com","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/584490","source":"cve@gitlab.com","tags":["Not Applicable"]},{"url":"https://hackerone.com/reports/3446641","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-1184","sourceIdentifier":"cve@gitlab.com","published":"2026-05-14T06:16:21.190","lastModified":"2026-06-17T10:15:17.320","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 11.9 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to cause denial of service by uploading a specially crafted file due to improper validation."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"11.9","lessThan":"18.9.7","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.6","versionType":"semver","status":"affected"},{"version":"18.11","lessThan":"18.11.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-14T13:04:11.878362Z","id":"CVE-2026-1184","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-502"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.9.0","versionEndExcluding":"18.9.7","matchCriteriaId":"CAAAC1B2-E387-4D70-9A1B-0B462D6F82FE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.6","matchCriteriaId":"E79D4F10-88B3-4AA7-BC5E-3FC8FA698969"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.3","matchCriteriaId":"DA0D6580-3530-4D76-81CE-D852BCE0D411"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/05/13/patch-release-gitlab-18-11-3-released/","source":"cve@gitlab.com","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/586634","source":"cve@gitlab.com","tags":["Not Applicable"]},{"url":"https://hackerone.com/reports/3515842","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-1322","sourceIdentifier":"cve@gitlab.com","published":"2026-05-14T06:16:21.340","lastModified":"2026-06-17T10:15:35.780","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.0 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with a read_api scoped OAuth application to create issues and add comments to issues in private projects due to improper authorization."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.0","lessThan":"18.9.7","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.6","versionType":"semver","status":"affected"},{"version":"18.11","lessThan":"18.11.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","baseScore":6.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-14T13:04:55.963966Z","id":"CVE-2026-1322","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-840"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"18.9.7","matchCriteriaId":"CDFFF54A-E7A5-4ED5-B59B-3425F5CFC6C2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"18.9.7","matchCriteriaId":"D96A7B2B-58F0-4C6E-A9E8-756BCA6F2122"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.6","matchCriteriaId":"98488AF5-9D73-47EC-B7CB-41766FBC3774"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.6","matchCriteriaId":"E79D4F10-88B3-4AA7-BC5E-3FC8FA698969"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.3","matchCriteriaId":"4215ACCD-67B6-4394-AD76-1CE39077FCD2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.3","matchCriteriaId":"DA0D6580-3530-4D76-81CE-D852BCE0D411"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/05/13/patch-release-gitlab-18-11-3-released/","source":"cve@gitlab.com","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/587270","source":"cve@gitlab.com","tags":["Not Applicable"]},{"url":"https://hackerone.com/reports/3508895","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-1338","sourceIdentifier":"cve@gitlab.com","published":"2026-05-14T06:16:21.520","lastModified":"2026-06-17T10:15:37.760","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with developer-role permissions to delete protected container registry tags due to improper authorization checks."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.10","lessThan":"18.9.7","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.6","versionType":"semver","status":"affected"},{"version":"18.11","lessThan":"18.11.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-14T13:05:50.413837Z","id":"CVE-2026-1338","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-639"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.10.0","versionEndExcluding":"18.9.7","matchCriteriaId":"E8665854-3B66-4454-808F-16AF7DB61BEA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.10.0","versionEndExcluding":"18.9.7","matchCriteriaId":"A58B1300-ECC0-4683-B910-38A3807D4DC6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.6","matchCriteriaId":"98488AF5-9D73-47EC-B7CB-41766FBC3774"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.6","matchCriteriaId":"E79D4F10-88B3-4AA7-BC5E-3FC8FA698969"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.3","matchCriteriaId":"4215ACCD-67B6-4394-AD76-1CE39077FCD2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.3","matchCriteriaId":"DA0D6580-3530-4D76-81CE-D852BCE0D411"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/05/13/patch-release-gitlab-18-11-3-released/","source":"cve@gitlab.com","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/587326","source":"cve@gitlab.com","tags":["Not Applicable"]},{"url":"https://hackerone.com/reports/3480620","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-1659","sourceIdentifier":"cve@gitlab.com","published":"2026-05-14T06:16:21.667","lastModified":"2026-06-17T10:16:16.130","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.0 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to cause denial of service by sending specially crafted requests due to insufficient input validation."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"9.0","lessThan":"18.9.7","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.6","versionType":"semver","status":"affected"},{"version":"18.11","lessThan":"18.11.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-14T13:00:40.324405Z","id":"CVE-2026-1659","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"9.0.0","versionEndExcluding":"18.9.7","matchCriteriaId":"6144D1E8-D044-49FF-A6C2-BE90AAE5A626"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"9.0.0","versionEndExcluding":"18.9.7","matchCriteriaId":"A6010726-6D38-4A29-AEA9-AF7655ED7909"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.6","matchCriteriaId":"98488AF5-9D73-47EC-B7CB-41766FBC3774"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.6","matchCriteriaId":"E79D4F10-88B3-4AA7-BC5E-3FC8FA698969"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.3","matchCriteriaId":"4215ACCD-67B6-4394-AD76-1CE39077FCD2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.3","matchCriteriaId":"DA0D6580-3530-4D76-81CE-D852BCE0D411"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/05/13/patch-release-gitlab-18-11-3-released/","source":"cve@gitlab.com","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/588201","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3519824","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-2900","sourceIdentifier":"cve@gitlab.com","published":"2026-05-14T06:16:21.803","lastModified":"2026-06-17T10:31:59.957","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 16.10 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that when instance-level approval rule editing prevention was enabled, could have allowed an authenticated user with Maintainer permissions to modify or delete project approval rules due to missing authorization checks."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.10","lessThan":"18.9.7","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.6","versionType":"semver","status":"affected"},{"version":"18.11","lessThan":"18.11.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N","baseScore":2.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-14T13:07:09.373948Z","id":"CVE-2026-2900","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.10.0","versionEndExcluding":"18.9.7","matchCriteriaId":"B1720F8D-9C3B-4F65-B279-AF1E0D325564"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.6","matchCriteriaId":"E79D4F10-88B3-4AA7-BC5E-3FC8FA698969"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.3","matchCriteriaId":"DA0D6580-3530-4D76-81CE-D852BCE0D411"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/05/13/patch-release-gitlab-18-11-3-released/","source":"cve@gitlab.com","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/590983","source":"cve@gitlab.com","tags":["Not Applicable"]},{"url":"https://hackerone.com/reports/3561092","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-3073","sourceIdentifier":"cve@gitlab.com","published":"2026-05-14T06:16:22.240","lastModified":"2026-06-17T10:43:00.500","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.6 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with developer-role permissions to bypass PyPI package protection rules and upload restricted packages due to improper authorization checks."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.6","lessThan":"18.9.7","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.6","versionType":"semver","status":"affected"},{"version":"18.11","lessThan":"18.11.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-14T13:07:39.355839Z","id":"CVE-2026-3073","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-639"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.6.0","versionEndExcluding":"18.9.7","matchCriteriaId":"E5E8F5E0-F198-4C02-9A3E-B01945A20F56"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.6.0","versionEndExcluding":"18.9.7","matchCriteriaId":"85899319-D6F1-4682-B040-125676C5C4D6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.6","matchCriteriaId":"98488AF5-9D73-47EC-B7CB-41766FBC3774"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.6","matchCriteriaId":"E79D4F10-88B3-4AA7-BC5E-3FC8FA698969"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.3","matchCriteriaId":"4215ACCD-67B6-4394-AD76-1CE39077FCD2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.3","matchCriteriaId":"DA0D6580-3530-4D76-81CE-D852BCE0D411"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/05/13/patch-release-gitlab-18-11-3-released/","source":"cve@gitlab.com","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/591227","source":"cve@gitlab.com","tags":["Not Applicable"]},{"url":"https://hackerone.com/reports/3532563","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-3074","sourceIdentifier":"cve@gitlab.com","published":"2026-05-14T06:16:22.400","lastModified":"2026-06-17T10:43:00.603","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to download private debugging symbols from inaccessible projects due to improper access control."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.7","lessThan":"18.9.7","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.6","versionType":"semver","status":"affected"},{"version":"18.11","lessThan":"18.11.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-14T13:08:20.301724Z","id":"CVE-2026-3074","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-639"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.7.0","versionEndExcluding":"18.9.7","matchCriteriaId":"D99B90C3-8740-4D02-B746-874787FF5A60"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.7.0","versionEndExcluding":"18.9.7","matchCriteriaId":"3AA4EA51-881B-46C6-858E-389906ECF739"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.6","matchCriteriaId":"98488AF5-9D73-47EC-B7CB-41766FBC3774"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.6","matchCriteriaId":"E79D4F10-88B3-4AA7-BC5E-3FC8FA698969"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.3","matchCriteriaId":"4215ACCD-67B6-4394-AD76-1CE39077FCD2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.3","matchCriteriaId":"DA0D6580-3530-4D76-81CE-D852BCE0D411"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/05/13/patch-release-gitlab-18-11-3-released/","source":"cve@gitlab.com","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/591229","source":"cve@gitlab.com","tags":["Not Applicable"]},{"url":"https://hackerone.com/reports/3556163","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-3160","sourceIdentifier":"cve@gitlab.com","published":"2026-05-14T06:16:22.657","lastModified":"2026-06-17T10:43:08.270","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to view Jira issues outside the configured project scope due to an integration filter functioning only as a display control rather than enforcing access boundaries as specified."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"13.7","lessThan":"18.9.7","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.6","versionType":"semver","status":"affected"},{"version":"18.11","lessThan":"18.11.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N","baseScore":5.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-14T13:09:16.159396Z","id":"CVE-2026-3160","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-441"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"18.9.7","matchCriteriaId":"FC85DC69-6F6D-4809-A8A3-715292D3ED6C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"18.9.7","matchCriteriaId":"88432D14-F3DD-4549-A414-EE745969CEDF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.6","matchCriteriaId":"98488AF5-9D73-47EC-B7CB-41766FBC3774"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.6","matchCriteriaId":"E79D4F10-88B3-4AA7-BC5E-3FC8FA698969"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.3","matchCriteriaId":"4215ACCD-67B6-4394-AD76-1CE39077FCD2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.3","matchCriteriaId":"DA0D6580-3530-4D76-81CE-D852BCE0D411"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/05/13/patch-release-gitlab-18-11-3-released/","source":"cve@gitlab.com","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/591354","source":"cve@gitlab.com","tags":["Not Applicable"]},{"url":"https://hackerone.com/reports/3566042","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-3607","sourceIdentifier":"cve@gitlab.com","published":"2026-05-14T06:16:22.790","lastModified":"2026-06-17T10:43:51.630","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with developer-role permissions to bypass package protection rules due to improper access control."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.3","lessThan":"18.9.7","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.6","versionType":"semver","status":"affected"},{"version":"18.11","lessThan":"18.11.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-14T13:06:35.358821Z","id":"CVE-2026-3607","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1280"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.3.0","versionEndExcluding":"18.9.7","matchCriteriaId":"6AC53BC1-87B7-4697-AC30-C7FCAEC42BCB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.3.0","versionEndExcluding":"18.9.7","matchCriteriaId":"D63792CD-C4CF-4AB0-92D7-621CF39B8088"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.6","matchCriteriaId":"98488AF5-9D73-47EC-B7CB-41766FBC3774"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.6","matchCriteriaId":"E79D4F10-88B3-4AA7-BC5E-3FC8FA698969"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.3","matchCriteriaId":"4215ACCD-67B6-4394-AD76-1CE39077FCD2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.3","matchCriteriaId":"DA0D6580-3530-4D76-81CE-D852BCE0D411"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/05/13/patch-release-gitlab-18-11-3-released/","source":"cve@gitlab.com","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/592466","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3586233","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-4524","sourceIdentifier":"cve@gitlab.com","published":"2026-05-14T06:16:23.677","lastModified":"2026-06-17T10:56:44.830","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.9.1 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to access confidential issue content in public projects without proper authorization due to improper authorization checks."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.9.1","lessThan":"18.9.7","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.6","versionType":"semver","status":"affected"},{"version":"18.11","lessThan":"18.11.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-14T13:23:11.054814Z","id":"CVE-2026-4524","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-288"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.9.1","versionEndExcluding":"18.9.7","matchCriteriaId":"287AA946-6F08-48DB-AA95-03938DEB5066"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.9.1","versionEndExcluding":"18.9.7","matchCriteriaId":"6F489D26-2EAB-4D20-8D65-45FA9EB3F28C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.6","matchCriteriaId":"98488AF5-9D73-47EC-B7CB-41766FBC3774"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.6","matchCriteriaId":"E79D4F10-88B3-4AA7-BC5E-3FC8FA698969"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.3","matchCriteriaId":"4215ACCD-67B6-4394-AD76-1CE39077FCD2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.3","matchCriteriaId":"DA0D6580-3530-4D76-81CE-D852BCE0D411"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/05/13/patch-release-gitlab-18-11-3-released/","source":"cve@gitlab.com","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/594295","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3597717","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-4527","sourceIdentifier":"cve@gitlab.com","published":"2026-05-14T06:16:23.810","lastModified":"2026-06-17T10:56:45.050","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to create unauthorized Jira subscriptions for a targeted user's namespace via a specially crafted link due to missing CSRF protection."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"11.10","lessThan":"18.9.7","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.6","versionType":"semver","status":"affected"},{"version":"18.11","lessThan":"18.11.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-14T13:22:26.022452Z","id":"CVE-2026-4527","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-352"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.10.0","versionEndExcluding":"18.9.7","matchCriteriaId":"6BF14399-2C83-416B-A608-6A8E50E03254"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.10.0","versionEndExcluding":"18.9.7","matchCriteriaId":"89AA9E0E-F6CD-4FAB-8782-F2FF39365F4B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.6","matchCriteriaId":"98488AF5-9D73-47EC-B7CB-41766FBC3774"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.6","matchCriteriaId":"E79D4F10-88B3-4AA7-BC5E-3FC8FA698969"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.3","matchCriteriaId":"4215ACCD-67B6-4394-AD76-1CE39077FCD2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.3","matchCriteriaId":"DA0D6580-3530-4D76-81CE-D852BCE0D411"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/05/13/patch-release-gitlab-18-11-3-released/","source":"cve@gitlab.com","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/594339","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3590487","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-6063","sourceIdentifier":"cve@gitlab.com","published":"2026-05-14T06:16:24.307","lastModified":"2026-06-17T11:00:15.360","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 11.10 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that under certain conditions could have allowed an authenticated user with developer-role permissions to remove code owner approval rules from merge requests due to improper access control."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"11.10","lessThan":"18.9.7","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.6","versionType":"semver","status":"affected"},{"version":"18.11","lessThan":"18.11.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-14T13:21:41.702425Z","id":"CVE-2026-6063","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-639"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.10.0","versionEndExcluding":"18.9.7","matchCriteriaId":"89AA9E0E-F6CD-4FAB-8782-F2FF39365F4B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.6","matchCriteriaId":"E79D4F10-88B3-4AA7-BC5E-3FC8FA698969"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.3","matchCriteriaId":"DA0D6580-3530-4D76-81CE-D852BCE0D411"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/05/13/patch-release-gitlab-18-11-3-released/","source":"cve@gitlab.com","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/596332","source":"cve@gitlab.com","tags":["Not Applicable"]},{"url":"https://hackerone.com/reports/3649087","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-6073","sourceIdentifier":"cve@gitlab.com","published":"2026-05-14T06:16:24.503","lastModified":"2026-06-17T11:00:16.147","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to execute arbitrary JavaScript in other users' browsers due to improper input sanitization."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.7","lessThan":"18.9.7","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.6","versionType":"semver","status":"affected"},{"version":"18.11","lessThan":"18.11.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-14T00:00:00+00:00","id":"CVE-2026-6073","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.7.0","versionEndExcluding":"18.9.7","matchCriteriaId":"CFA9DF4E-835C-4F18-B4C4-2F2B64F6546D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.6","matchCriteriaId":"E79D4F10-88B3-4AA7-BC5E-3FC8FA698969"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.3","matchCriteriaId":"DA0D6580-3530-4D76-81CE-D852BCE0D411"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/05/13/patch-release-gitlab-18-11-3-released/","source":"cve@gitlab.com","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/596340","source":"cve@gitlab.com","tags":["Not Applicable"]},{"url":"https://hackerone.com/reports/3655677","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-6335","sourceIdentifier":"cve@gitlab.com","published":"2026-05-14T06:16:24.780","lastModified":"2026-06-17T11:00:40.883","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.11 before 18.11.3 that under certain conditions could have allowed an authenticated user to execute arbitrary code in another user's browser session due to improper sanitization."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.11","lessThan":"18.11.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-15T03:55:48.991964Z","id":"CVE-2026-6335","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.3","matchCriteriaId":"4215ACCD-67B6-4394-AD76-1CE39077FCD2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.3","matchCriteriaId":"DA0D6580-3530-4D76-81CE-D852BCE0D411"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/05/13/patch-release-gitlab-18-11-3-released/","source":"cve@gitlab.com","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/596760","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3673647","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-6883","sourceIdentifier":"cve@gitlab.com","published":"2026-05-14T06:16:25.117","lastModified":"2026-06-17T11:01:28.283","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 15.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to bypass merge request approval requirements due to improper cleanup of orphaned policy records."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.7","lessThan":"18.9.7","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.6","versionType":"semver","status":"affected"},{"version":"18.11","lessThan":"18.11.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N","baseScore":2.6,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-14T13:14:33.496450Z","id":"CVE-2026-6883","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.7.0","versionEndExcluding":"18.9.7","matchCriteriaId":"D86F30EE-DF79-4AA9-BE69-FCEB740BE201"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.6","matchCriteriaId":"E79D4F10-88B3-4AA7-BC5E-3FC8FA698969"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.3","matchCriteriaId":"DA0D6580-3530-4D76-81CE-D852BCE0D411"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/05/13/patch-release-gitlab-18-11-3-released/","source":"cve@gitlab.com","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/596350","source":"cve@gitlab.com","tags":["Not Applicable"]}]}},{"cve":{"id":"CVE-2026-7377","sourceIdentifier":"cve@gitlab.com","published":"2026-05-14T06:16:25.267","lastModified":"2026-06-17T11:02:18.860","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that, in customizable analytics dashboards, could have allowed an authenticated user to execute arbitrary JavaScript in the context of other users' browsers due to improper input sanitization."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.7","lessThan":"18.9.7","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.6","versionType":"semver","status":"affected"},{"version":"18.11","lessThan":"18.11.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-14T00:00:00+00:00","id":"CVE-2026-7377","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.7.0","versionEndExcluding":"18.9.7","matchCriteriaId":"CFA9DF4E-835C-4F18-B4C4-2F2B64F6546D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.6","matchCriteriaId":"E79D4F10-88B3-4AA7-BC5E-3FC8FA698969"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.3","matchCriteriaId":"DA0D6580-3530-4D76-81CE-D852BCE0D411"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/05/13/patch-release-gitlab-18-11-3-released/","source":"cve@gitlab.com","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/598497","source":"cve@gitlab.com","tags":["Not Applicable"]},{"url":"https://hackerone.com/reports/3659044","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-7471","sourceIdentifier":"cve@gitlab.com","published":"2026-05-14T06:16:25.477","lastModified":"2026-06-17T11:02:28.857","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with control of a virtual registry upstream to make requests to internal hosts due to improper validation."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.8","lessThan":"18.9.7","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.6","versionType":"semver","status":"affected"},{"version":"18.11","lessThan":"18.11.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N","baseScore":3.5,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-14T13:17:45.869808Z","id":"CVE-2026-7471","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.9.7","matchCriteriaId":"3B168A5B-5B96-48AA-882D-77529BCA8006"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.6","matchCriteriaId":"E79D4F10-88B3-4AA7-BC5E-3FC8FA698969"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.3","matchCriteriaId":"DA0D6580-3530-4D76-81CE-D852BCE0D411"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/05/13/patch-release-gitlab-18-11-3-released/","source":"cve@gitlab.com","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/594196","source":"cve@gitlab.com","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2026-7481","sourceIdentifier":"cve@gitlab.com","published":"2026-05-14T06:16:25.660","lastModified":"2026-06-17T11:02:29.923","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 16.4 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with developer-role permissions to execute arbitrary JavaScript in other users' browsers due to improper input sanitization."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.4","lessThan":"18.9.7","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.6","versionType":"semver","status":"affected"},{"version":"18.11","lessThan":"18.11.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-14T00:00:00+00:00","id":"CVE-2026-7481","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.4.0","versionEndExcluding":"18.9.7","matchCriteriaId":"ACF146E3-AD48-4493-89F1-2F26D172A4C6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.6","matchCriteriaId":"E79D4F10-88B3-4AA7-BC5E-3FC8FA698969"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.3","matchCriteriaId":"DA0D6580-3530-4D76-81CE-D852BCE0D411"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/05/13/patch-release-gitlab-18-11-3-released/","source":"cve@gitlab.com","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/598646","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3697379","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-8144","sourceIdentifier":"cve@gitlab.com","published":"2026-05-14T06:16:25.840","lastModified":"2026-06-17T11:03:33.817","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.1 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with project membership to enumerate private group members due to missing authorization checks."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.1","lessThan":"18.9.7","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.6","versionType":"semver","status":"affected"},{"version":"18.11","lessThan":"18.11.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-14T13:49:03.396252Z","id":"CVE-2026-8144","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.1.0","versionEndExcluding":"18.9.7","matchCriteriaId":"174B08BE-32EF-415A-95FB-F94BCBAF81A2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.1.0","versionEndExcluding":"18.9.7","matchCriteriaId":"096989C0-1550-4EBA-8A46-9F5EA69705EB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.6","matchCriteriaId":"98488AF5-9D73-47EC-B7CB-41766FBC3774"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.6","matchCriteriaId":"E79D4F10-88B3-4AA7-BC5E-3FC8FA698969"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.3","matchCriteriaId":"4215ACCD-67B6-4394-AD76-1CE39077FCD2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.3","matchCriteriaId":"DA0D6580-3530-4D76-81CE-D852BCE0D411"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/05/13/patch-release-gitlab-18-11-3-released/","source":"cve@gitlab.com","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/591964","source":"cve@gitlab.com","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2026-8280","sourceIdentifier":"cve@gitlab.com","published":"2026-05-14T06:16:26.207","lastModified":"2026-06-17T11:03:46.930","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to cause denial of service through excessive memory consumption due to improper input validation."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"8.3","lessThan":"18.9.7","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.6","versionType":"semver","status":"affected"},{"version":"18.11","lessThan":"18.11.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-14T13:15:22.673654Z","id":"CVE-2026-8280","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.3.0","versionEndExcluding":"18.9.7","matchCriteriaId":"C2C124FA-2189-41CC-A610-75D6A92036A4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.3.0","versionEndExcluding":"18.9.7","matchCriteriaId":"DF09DD57-1F85-434E-8677-8F837F5B4D15"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.6","matchCriteriaId":"98488AF5-9D73-47EC-B7CB-41766FBC3774"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.6","matchCriteriaId":"E79D4F10-88B3-4AA7-BC5E-3FC8FA698969"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.3","matchCriteriaId":"4215ACCD-67B6-4394-AD76-1CE39077FCD2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.3","matchCriteriaId":"DA0D6580-3530-4D76-81CE-D852BCE0D411"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/05/13/patch-release-gitlab-18-11-3-released/","source":"cve@gitlab.com","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/579035","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3329085","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-1402","sourceIdentifier":"cve@gitlab.com","published":"2026-05-27T19:16:15.577","lastModified":"2026-06-17T10:15:42.930","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an authenticated user to cause denial of service due to insufficient validation."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.1","lessThan":"18.10.7","versionType":"semver","status":"affected"},{"version":"18.11","lessThan":"18.11.4","versionType":"semver","status":"affected"},{"version":"19.0","lessThan":"19.0.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-27T18:53:38.611070Z","id":"CVE-2026-1402","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"18.10.7","matchCriteriaId":"758AA61C-C4E8-469F-B72F-DDC41539F98A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"18.10.7","matchCriteriaId":"227AFED2-01D8-4DC7-AAA6-6E9F9DCB12B4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.4","matchCriteriaId":"E97506AF-85D4-4CDE-B129-611438E348E6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.4","matchCriteriaId":"F4085D50-86E4-4FC7-BB90-5181E6E65DEC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:19.0.0:*:*:*:community:*:*:*","matchCriteriaId":"FE7D542C-BB21-4CF0-A3E5-FAD6E9FB2851"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:19.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"57A0D68B-909C-416E-8EAE-A14886F4ABA9"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/05/27/patch-release-gitlab-19-0-1-released/","source":"cve@gitlab.com","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/587569","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3517283","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-2601","sourceIdentifier":"cve@gitlab.com","published":"2026-05-27T19:16:16.000","lastModified":"2026-06-17T10:31:22.893","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 11.5 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to access sensitive deployment data on projects due to improper authorization checks."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"11.5","lessThan":"18.10.7","versionType":"semver","status":"affected"},{"version":"18.11","lessThan":"18.11.4","versionType":"semver","status":"affected"},{"version":"19.0","lessThan":"19.0.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-27T19:00:57.399478Z","id":"CVE-2026-2601","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"18.10.7","matchCriteriaId":"C612CA55-EFC0-4716-AC7C-68FBDF6654B1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.4","matchCriteriaId":"F4085D50-86E4-4FC7-BB90-5181E6E65DEC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:19.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"57A0D68B-909C-416E-8EAE-A14886F4ABA9"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/05/27/patch-release-gitlab-19-0-1-released/","source":"cve@gitlab.com","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/590389","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3556381","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-4868","sourceIdentifier":"cve@gitlab.com","published":"2026-05-27T19:16:24.317","lastModified":"2026-06-17T10:57:21.940","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that, under certain conditions, could have allowed an authenticated user to cause specific Duo AI workflows to run under another user's identity due to improper user identity resolution when triggering Duo AI workflow runners."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.8","lessThan":"18.10.7","versionType":"semver","status":"affected"},{"version":"18.11","lessThan":"18.11.4","versionType":"semver","status":"affected"},{"version":"19.0","lessThan":"19.0.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N","baseScore":8.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.8,"impactScore":5.8}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-27T00:00:00+00:00","id":"CVE-2026-4868","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-639"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.10.7","matchCriteriaId":"E1F4CEEB-95BD-4BFE-9316-403106E919EC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.4","matchCriteriaId":"F4085D50-86E4-4FC7-BB90-5181E6E65DEC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:19.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"57A0D68B-909C-416E-8EAE-A14886F4ABA9"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/05/27/patch-release-gitlab-19-0-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/594809","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3619872","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-5296","sourceIdentifier":"cve@gitlab.com","published":"2026-05-27T19:16:24.450","lastModified":"2026-06-17T10:58:46.523","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that when foundational flows were enabled at the group level, could have allowed an authenticated user with developer-role permissions to bypass flow restrictions under certain conditions."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.7","lessThan":"18.10.7","versionType":"semver","status":"affected"},{"version":"18.11","lessThan":"18.11.4","versionType":"semver","status":"affected"},{"version":"19.0","lessThan":"19.0.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-27T18:58:53.696216Z","id":"CVE-2026-5296","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.7.0","versionEndExcluding":"18.10.7","matchCriteriaId":"630B547B-DD30-47B8-968D-8F3D6849E215"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.4","matchCriteriaId":"F4085D50-86E4-4FC7-BB90-5181E6E65DEC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:19.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"57A0D68B-909C-416E-8EAE-A14886F4ABA9"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/05/27/patch-release-gitlab-19-0-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/595423","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3626303","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-6713","sourceIdentifier":"cve@gitlab.com","published":"2026-05-27T19:16:24.640","lastModified":"2026-06-17T11:01:12.777","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an unauthorized user to enumerate private projects due to incorrect authorization checks."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.2","lessThan":"18.10.7","versionType":"semver","status":"affected"},{"version":"18.11","lessThan":"18.11.4","versionType":"semver","status":"affected"},{"version":"19.0","lessThan":"19.0.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-27T19:22:11.455424Z","id":"CVE-2026-6713","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"18.10.7","matchCriteriaId":"75B3D00F-CEEF-473F-B9F9-A26AEBE504C8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"18.10.7","matchCriteriaId":"63CE197F-E713-44E3-9EBE-958D8FF3665C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.4","matchCriteriaId":"E97506AF-85D4-4CDE-B129-611438E348E6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.4","matchCriteriaId":"F4085D50-86E4-4FC7-BB90-5181E6E65DEC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:19.0.0:*:*:*:community:*:*:*","matchCriteriaId":"FE7D542C-BB21-4CF0-A3E5-FAD6E9FB2851"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:19.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"57A0D68B-909C-416E-8EAE-A14886F4ABA9"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/05/27/patch-release-gitlab-19-0-1-released/","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/597490","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3644605","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-8716","sourceIdentifier":"cve@gitlab.com","published":"2026-05-27T19:16:25.097","lastModified":"2026-06-17T11:04:19.480","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.7 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an authenticated user to access CI data from a different ref type than intended."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"12.7","lessThan":"18.10.7","versionType":"semver","status":"affected"},{"version":"18.11","lessThan":"18.11.4","versionType":"semver","status":"affected"},{"version":"19.0","lessThan":"19.0.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-27T19:34:31.889199Z","id":"CVE-2026-8716","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-706"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.7.0","versionEndExcluding":"18.10.7","matchCriteriaId":"D1F6BC04-28A6-4655-AC66-077023277DDD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.7.0","versionEndExcluding":"18.10.7","matchCriteriaId":"39DEE09D-A962-4A5A-A9F1-6A13516A0981"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.4","matchCriteriaId":"E97506AF-85D4-4CDE-B129-611438E348E6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.4","matchCriteriaId":"F4085D50-86E4-4FC7-BB90-5181E6E65DEC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:19.0.0:*:*:*:community:*:*:*","matchCriteriaId":"FE7D542C-BB21-4CF0-A3E5-FAD6E9FB2851"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:19.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"57A0D68B-909C-416E-8EAE-A14886F4ABA9"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/05/27/patch-release-gitlab-19-0-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/570059","source":"cve@gitlab.com","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2026-9807","sourceIdentifier":"cve@gitlab.com","published":"2026-05-28T09:16:49.760","lastModified":"2026-06-17T11:05:39.980","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.9 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed a blocked Project Access Token to continue accessing private resources due to incorrect authorization enforcement."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.9","lessThan":"18.10.7","versionType":"semver","status":"affected"},{"version":"18.11","lessThan":"18.11.4","versionType":"semver","status":"affected"},{"version":"19.0","lessThan":"19.0.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-28T12:10:59.788148Z","id":"CVE-2026-9807","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.10.7","matchCriteriaId":"B05AAA42-FE02-4189-8C9A-1458ACF3C24C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.10.7","matchCriteriaId":"DF7E0D07-DCBD-4D49-AA05-5E99FC5A74FF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.4","matchCriteriaId":"E97506AF-85D4-4CDE-B129-611438E348E6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.4","matchCriteriaId":"F4085D50-86E4-4FC7-BB90-5181E6E65DEC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:19.0.0:*:*:*:community:*:*:*","matchCriteriaId":"FE7D542C-BB21-4CF0-A3E5-FAD6E9FB2851"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:19.0.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"57A0D68B-909C-416E-8EAE-A14886F4ABA9"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/05/27/patch-release-gitlab-19-0-1-released/","source":"cve@gitlab.com","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/590694","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3554993","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-10087","sourceIdentifier":"cve@gitlab.com","published":"2026-06-11T12:16:30.820","lastModified":"2026-06-17T10:11:52.123","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 17.1 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute arbitrary client-side code on behalf of a targeted user due to improper input sanitization in the Analytics Dashboard."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.1","lessThan":"18.10.8","versionType":"semver","status":"affected"},{"version":"18.11","lessThan":"18.11.5","versionType":"semver","status":"affected"},{"version":"19.0","lessThan":"19.0.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":5.8}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-06-11T12:39:39.206911Z","id":"CVE-2026-10087","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"18.10.8","matchCriteriaId":"E59BA2EA-59E3-4130-A78D-079800F62945"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.1.0","versionEndExcluding":"18.10.8","matchCriteriaId":"B94584B7-AE5B-40C4-9E7A-3EC65BBF032A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.5","matchCriteriaId":"D3442E29-F164-40E0-B972-F0EEE8ED4FD1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.5","matchCriteriaId":"7FB0D7FE-9A4F-45D8-B564-31DF9F2F4066"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"19.0.0","versionEndExcluding":"19.0.2","matchCriteriaId":"A6FAB200-DFB3-42FC-A901-8E5C0A3CA706"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.0.0","versionEndExcluding":"19.0.2","matchCriteriaId":"1A666CA8-8D31-4765-87ED-D0F56E9DAFF0"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/06/10/patch-release-gitlab-19-0-2-released/","source":"cve@gitlab.com","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/601633","source":"cve@gitlab.com","tags":["Issue Tracking"]},{"url":"https://hackerone.com/reports/3759090","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-10733","sourceIdentifier":"cve@gitlab.com","published":"2026-06-11T12:16:30.950","lastModified":"2026-06-17T10:12:31.443","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.0 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that could have allowed an authenticated user to cause denial of service on the CI/CD Catalog page due to improper sanitization."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.0","lessThan":"18.10.8","versionType":"semver","status":"affected"},{"version":"18.11","lessThan":"18.11.5","versionType":"semver","status":"affected"},{"version":"19.0","lessThan":"19.0.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-06-11T12:40:15.077741Z","id":"CVE-2026-10733","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1021"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"18.10.8","matchCriteriaId":"40FFBE12-13A6-4346-B9D1-5B010B10F716"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"18.10.8","matchCriteriaId":"E10C34CC-B60F-49B4-96E6-CF7B897AC559"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.5","matchCriteriaId":"D3442E29-F164-40E0-B972-F0EEE8ED4FD1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.5","matchCriteriaId":"7FB0D7FE-9A4F-45D8-B564-31DF9F2F4066"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"19.0.0","versionEndExcluding":"19.0.2","matchCriteriaId":"A6FAB200-DFB3-42FC-A901-8E5C0A3CA706"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.0.0","versionEndExcluding":"19.0.2","matchCriteriaId":"1A666CA8-8D31-4765-87ED-D0F56E9DAFF0"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/06/10/patch-release-gitlab-19-0-2-released/","source":"cve@gitlab.com","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/600446","source":"cve@gitlab.com","tags":["Issue Tracking"]}]}},{"cve":{"id":"CVE-2026-1500","sourceIdentifier":"cve@gitlab.com","published":"2026-06-11T12:16:31.073","lastModified":"2026-06-17T10:15:57.163","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user to cause denial of service due to uncontrolled resource consumption when processing a specially crafted file upload."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.10","lessThan":"18.10.8","versionType":"semver","status":"affected"},{"version":"18.11","lessThan":"18.11.5","versionType":"semver","status":"affected"},{"version":"19.0","lessThan":"19.0.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-06-11T12:18:11.879672Z","id":"CVE-2026-1500","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.10.0","versionEndExcluding":"18.10.8","matchCriteriaId":"B4CA633C-92DA-40EA-8B12-AEB9B652C2FC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.10.0","versionEndExcluding":"18.10.8","matchCriteriaId":"3B7744D8-0832-44CE-8D78-4BA3270F9CCC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.5","matchCriteriaId":"D3442E29-F164-40E0-B972-F0EEE8ED4FD1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.5","matchCriteriaId":"7FB0D7FE-9A4F-45D8-B564-31DF9F2F4066"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"19.0.0","versionEndExcluding":"19.0.2","matchCriteriaId":"A6FAB200-DFB3-42FC-A901-8E5C0A3CA706"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.0.0","versionEndExcluding":"19.0.2","matchCriteriaId":"1A666CA8-8D31-4765-87ED-D0F56E9DAFF0"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/06/10/patch-release-gitlab-19-0-2-released/","source":"cve@gitlab.com","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/587825","source":"cve@gitlab.com","tags":["Issue Tracking"]},{"url":"https://hackerone.com/reports/3517331","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-3553","sourceIdentifier":"cve@gitlab.com","published":"2026-06-11T12:16:31.380","lastModified":"2026-06-17T10:43:46.550","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.0 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user to access confidential issue details due to incorrect authorization checks."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"12.0","lessThan":"18.10.8","versionType":"semver","status":"affected"},{"version":"18.11","lessThan":"18.11.5","versionType":"semver","status":"affected"},{"version":"19.0","lessThan":"19.0.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":3.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-06-11T12:28:17.019689Z","id":"CVE-2026-3553","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.0.0","versionEndExcluding":"18.10.8","matchCriteriaId":"3CA1BFF8-7AE4-4A29-91C0-CCE6C8E1516E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.0.0","versionEndExcluding":"18.10.8","matchCriteriaId":"8A4D048C-3248-4479-9721-25C46341E0C8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.5","matchCriteriaId":"D3442E29-F164-40E0-B972-F0EEE8ED4FD1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.5","matchCriteriaId":"7FB0D7FE-9A4F-45D8-B564-31DF9F2F4066"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"19.0.0","versionEndExcluding":"19.0.2","matchCriteriaId":"A6FAB200-DFB3-42FC-A901-8E5C0A3CA706"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.0.0","versionEndExcluding":"19.0.2","matchCriteriaId":"1A666CA8-8D31-4765-87ED-D0F56E9DAFF0"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/06/10/patch-release-gitlab-19-0-2-released/","source":"cve@gitlab.com","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/592295","source":"cve@gitlab.com","tags":["Issue Tracking"]},{"url":"https://hackerone.com/reports/3578216","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-6269","sourceIdentifier":"cve@gitlab.com","published":"2026-06-11T12:16:32.090","lastModified":"2026-06-17T11:00:34.320","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to modify hidden merge requests due to incorrect authorization enforcements."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.10","lessThan":"18.10.8","versionType":"semver","status":"affected"},{"version":"18.11","lessThan":"18.11.5","versionType":"semver","status":"affected"},{"version":"19.0","lessThan":"19.0.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-06-11T12:29:55.738457Z","id":"CVE-2026-6269","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.10.0","versionEndExcluding":"18.10.8","matchCriteriaId":"7ED03740-F39B-4A51-999D-BBDE0ADE03D6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.10.0","versionEndExcluding":"18.10.8","matchCriteriaId":"6434B14E-3F05-47B6-894E-6E249209E563"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.5","matchCriteriaId":"D3442E29-F164-40E0-B972-F0EEE8ED4FD1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.5","matchCriteriaId":"7FB0D7FE-9A4F-45D8-B564-31DF9F2F4066"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"19.0.0","versionEndExcluding":"19.0.2","matchCriteriaId":"A6FAB200-DFB3-42FC-A901-8E5C0A3CA706"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.0.0","versionEndExcluding":"19.0.2","matchCriteriaId":"1A666CA8-8D31-4765-87ED-D0F56E9DAFF0"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/06/10/patch-release-gitlab-19-0-2-released/","source":"cve@gitlab.com","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/596625","source":"cve@gitlab.com","tags":["Issue Tracking"]},{"url":"https://hackerone.com/reports/3661880","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-6277","sourceIdentifier":"cve@gitlab.com","published":"2026-06-11T12:16:32.217","lastModified":"2026-06-17T11:00:35.253","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 13.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user with Security Manager-role permissions to manage project security configuration even when the relevant feature was in a disabled state, due to incorrect authorization enforcement."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"13.9","lessThan":"18.10.8","versionType":"semver","status":"affected"},{"version":"18.11","lessThan":"18.11.5","versionType":"semver","status":"affected"},{"version":"19.0","lessThan":"19.0.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-06-11T12:30:20.404806Z","id":"CVE-2026-6277","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.9.0","versionEndExcluding":"18.10.8","matchCriteriaId":"8BBAF113-0E87-4BDF-BFE3-B6F63D3219F2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.9.0","versionEndExcluding":"18.10.8","matchCriteriaId":"92F60900-EEFE-4C2D-88E9-3F07152F2E62"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.5","matchCriteriaId":"D3442E29-F164-40E0-B972-F0EEE8ED4FD1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.5","matchCriteriaId":"7FB0D7FE-9A4F-45D8-B564-31DF9F2F4066"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"19.0.0","versionEndExcluding":"19.0.2","matchCriteriaId":"A6FAB200-DFB3-42FC-A901-8E5C0A3CA706"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.0.0","versionEndExcluding":"19.0.2","matchCriteriaId":"1A666CA8-8D31-4765-87ED-D0F56E9DAFF0"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/06/10/patch-release-gitlab-19-0-2-released/","source":"cve@gitlab.com","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/596656","source":"cve@gitlab.com","tags":["Issue Tracking"]},{"url":"https://hackerone.com/reports/3662615","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-6976","sourceIdentifier":"cve@gitlab.com","published":"2026-06-11T12:16:32.467","lastModified":"2026-06-17T11:01:34.463","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to hide changes from merge request diff views due to improper input handling of file names."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.9","lessThan":"18.10.8","versionType":"semver","status":"affected"},{"version":"18.11","lessThan":"18.11.5","versionType":"semver","status":"affected"},{"version":"19.0","lessThan":"19.0.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N","baseScore":3.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-06-11T12:33:12.743514Z","id":"CVE-2026-6976","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-639"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.9.0","versionEndExcluding":"18.10.8","matchCriteriaId":"1D0971DD-D736-4736-938C-0623B5A4B498"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.9.0","versionEndExcluding":"18.10.8","matchCriteriaId":"B12AF75C-B1B4-4FF4-A133-3E7D134DE8D5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.5","matchCriteriaId":"D3442E29-F164-40E0-B972-F0EEE8ED4FD1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.5","matchCriteriaId":"7FB0D7FE-9A4F-45D8-B564-31DF9F2F4066"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"19.0.0","versionEndExcluding":"19.0.2","matchCriteriaId":"A6FAB200-DFB3-42FC-A901-8E5C0A3CA706"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.0.0","versionEndExcluding":"19.0.2","matchCriteriaId":"1A666CA8-8D31-4765-87ED-D0F56E9DAFF0"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/06/10/patch-release-gitlab-19-0-2-released/","source":"cve@gitlab.com","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/598165","source":"cve@gitlab.com","tags":["Issue Tracking"]},{"url":"https://hackerone.com/reports/3638136","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-7250","sourceIdentifier":"cve@gitlab.com","published":"2026-06-11T12:16:32.587","lastModified":"2026-06-17T11:02:05.020","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an unauthenticated user to cause denial of service due to improper input validation in the API request parsing middleware."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"12.10","lessThan":"18.10.8","versionType":"semver","status":"affected"},{"version":"18.11","lessThan":"18.11.5","versionType":"semver","status":"affected"},{"version":"19.0","lessThan":"19.0.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-06-11T12:26:59.036767Z","id":"CVE-2026-7250","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.10.0","versionEndExcluding":"18.10.8","matchCriteriaId":"6C7F56B7-ACD2-4360-A034-4AC2587A018D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.10.0","versionEndExcluding":"18.10.8","matchCriteriaId":"6E86DAB7-AE93-464D-A51D-F830D469363B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.5","matchCriteriaId":"D3442E29-F164-40E0-B972-F0EEE8ED4FD1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.5","matchCriteriaId":"7FB0D7FE-9A4F-45D8-B564-31DF9F2F4066"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"19.0.0","versionEndExcluding":"19.0.2","matchCriteriaId":"A6FAB200-DFB3-42FC-A901-8E5C0A3CA706"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.0.0","versionEndExcluding":"19.0.2","matchCriteriaId":"1A666CA8-8D31-4765-87ED-D0F56E9DAFF0"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/06/10/patch-release-gitlab-19-0-2-released/","source":"cve@gitlab.com","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/598311","source":"cve@gitlab.com","tags":["Issue Tracking"]},{"url":"https://hackerone.com/reports/3671995","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-8589","sourceIdentifier":"cve@gitlab.com","published":"2026-06-11T12:16:32.860","lastModified":"2026-06-17T11:04:11.890","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 13.1.4 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user to add unauthorized email addresses to a targeted user's account due to improper sanitization of user-supplied input in certain group setting fields."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"13.1.4","lessThan":"18.10.8","versionType":"semver","status":"affected"},{"version":"18.11","lessThan":"18.11.5","versionType":"semver","status":"affected"},{"version":"19.0","lessThan":"19.0.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:N","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.0,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":5.8}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-06-11T12:27:53.213287Z","id":"CVE-2026-8589","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.1.4","versionEndExcluding":"18.10.8","matchCriteriaId":"6BD9809B-9486-4D2B-A0D0-8E567AF86754"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.1.4","versionEndExcluding":"18.10.8","matchCriteriaId":"BA1FE381-79F3-49A7-89DC-3EC71D9A2FA2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.5","matchCriteriaId":"D3442E29-F164-40E0-B972-F0EEE8ED4FD1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.5","matchCriteriaId":"7FB0D7FE-9A4F-45D8-B564-31DF9F2F4066"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"19.0.0","versionEndExcluding":"19.0.2","matchCriteriaId":"A6FAB200-DFB3-42FC-A901-8E5C0A3CA706"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.0.0","versionEndExcluding":"19.0.2","matchCriteriaId":"1A666CA8-8D31-4765-87ED-D0F56E9DAFF0"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/06/10/patch-release-gitlab-19-0-2-released/","source":"cve@gitlab.com","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/600099","source":"cve@gitlab.com","tags":["Issue Tracking"]},{"url":"https://hackerone.com/reports/3722842","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-9204","sourceIdentifier":"cve@gitlab.com","published":"2026-06-11T12:16:32.983","lastModified":"2026-06-17T11:04:55.337","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user to read arbitrary files from the Gitaly server and access internal network resources during repository import, due to insufficient validation of secondary URLs."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitaly:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.10","lessThan":"18.10.8","versionType":"semver","status":"affected"},{"version":"18.11","lessThan":"18.11.5","versionType":"semver","status":"affected"},{"version":"19.0","lessThan":"19.0.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-06-11T12:31:05.710988Z","id":"CVE-2026-9204","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.8","matchCriteriaId":"13823E75-AE85-46CA-81B2-B41187DA5E8B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.8","matchCriteriaId":"9E8223D9-103A-4158-8F8B-F3978AA288F5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.5","matchCriteriaId":"D3442E29-F164-40E0-B972-F0EEE8ED4FD1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.5","matchCriteriaId":"7FB0D7FE-9A4F-45D8-B564-31DF9F2F4066"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"19.0.0","versionEndExcluding":"19.0.2","matchCriteriaId":"A6FAB200-DFB3-42FC-A901-8E5C0A3CA706"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.0.0","versionEndExcluding":"19.0.2","matchCriteriaId":"1A666CA8-8D31-4765-87ED-D0F56E9DAFF0"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/06/10/patch-release-gitlab-19-0-2-released/","source":"cve@gitlab.com","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/592677","source":"cve@gitlab.com","tags":["Issue Tracking"]}]}},{"cve":{"id":"CVE-2026-9694","sourceIdentifier":"cve@gitlab.com","published":"2026-06-11T12:16:33.110","lastModified":"2026-06-17T11:05:35.113","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions, could have allowed an unauthenticated user to impersonate the GitLab Support Bot and inject arbitrary content via a specially crafted Service Desk email reply due to improper neutralization in email template processing."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.9","lessThan":"18.10.8","versionType":"semver","status":"affected"},{"version":"18.11","lessThan":"18.11.5","versionType":"semver","status":"affected"},{"version":"19.0","lessThan":"19.0.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N","baseScore":2.6,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-06-11T12:38:47.898774Z","id":"CVE-2026-9694","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-153"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.9.0","versionEndExcluding":"18.10.8","matchCriteriaId":"1D0971DD-D736-4736-938C-0623B5A4B498"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.9.0","versionEndExcluding":"18.10.8","matchCriteriaId":"B12AF75C-B1B4-4FF4-A133-3E7D134DE8D5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.5","matchCriteriaId":"D3442E29-F164-40E0-B972-F0EEE8ED4FD1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.11.0","versionEndExcluding":"18.11.5","matchCriteriaId":"7FB0D7FE-9A4F-45D8-B564-31DF9F2F4066"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"19.0.0","versionEndExcluding":"19.0.2","matchCriteriaId":"A6FAB200-DFB3-42FC-A901-8E5C0A3CA706"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.0.0","versionEndExcluding":"19.0.2","matchCriteriaId":"1A666CA8-8D31-4765-87ED-D0F56E9DAFF0"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/06/10/patch-release-gitlab-19-0-2-released/","source":"cve@gitlab.com","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/601330","source":"cve@gitlab.com","tags":["Issue Tracking"]},{"url":"https://hackerone.com/reports/3685720","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-0934","sourceIdentifier":"cve@gitlab.com","published":"2026-06-25T05:16:50.410","lastModified":"2026-06-26T18:36:49.923","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 17.9 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with custom role permissions to view, create, or delete protected environment configurations despite CI/CD visibility being disabled for the project."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.9","lessThan":"18.11.6","versionType":"semver","status":"affected"},{"version":"19.0","lessThan":"19.0.3","versionType":"semver","status":"affected"},{"version":"19.1","lessThan":"19.1.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N","baseScore":3.8,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-06-25T12:50:11.428883Z","id":"CVE-2026-0934","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.9.0","versionEndExcluding":"18.11.6","matchCriteriaId":"11AB2104-DEBE-44B9-9041-38CF73916A2A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.0.0","versionEndExcluding":"19.0.3","matchCriteriaId":"D398AA66-56F3-4ED2-AD85-E2C094EE577E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:19.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"49957E0D-C888-4AB1-9C15-8CD6E55454B1"}]}]}],"references":[{"url":"https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-1-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/585961","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3508760","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-10086","sourceIdentifier":"cve@gitlab.com","published":"2026-06-25T05:16:50.530","lastModified":"2026-06-26T18:36:05.783","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 16.4 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute arbitrary client-side code in the context of another user's session, due to improper sanitization of user-supplied input."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.4","lessThan":"18.11.6","versionType":"semver","status":"affected"},{"version":"19.0","lessThan":"19.0.3","versionType":"semver","status":"affected"},{"version":"19.1","lessThan":"19.1.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-06-25T00:00:00+00:00","id":"CVE-2026-10086","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.4.0","versionEndExcluding":"18.11.6","matchCriteriaId":"B6442921-C30A-4345-B0C2-14896044D93E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.0.0","versionEndExcluding":"19.0.3","matchCriteriaId":"D398AA66-56F3-4ED2-AD85-E2C094EE577E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:19.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"49957E0D-C888-4AB1-9C15-8CD6E55454B1"}]}]}],"references":[{"url":"https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-1-1-released/","source":"cve@gitlab.com","tags":["Patch","Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/601634","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3734800","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-10712","sourceIdentifier":"cve@gitlab.com","published":"2026-06-25T05:16:50.640","lastModified":"2026-06-26T18:30:40.870","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an unauthenticated user to execute arbitrary JavaScript in a user's browser session due to improper path validation under certain conditions."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.10","lessThan":"18.11.6","versionType":"semver","status":"affected"},{"version":"19.0","lessThan":"19.0.3","versionType":"semver","status":"affected"},{"version":"19.1","lessThan":"19.1.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N","baseScore":8.0,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-06-25T00:00:00+00:00","id":"CVE-2026-10712","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.11.6","matchCriteriaId":"C8FCB681-4849-40F5-A989-6DBDEA66FB30"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"19.0.0","versionEndExcluding":"19.0.3","matchCriteriaId":"9AF0E03E-D1A7-4C9E-B0BC-9EE4A5BE7CCC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:19.1.0:*:*:*:*:*:*:*","matchCriteriaId":"49004C41-7512-49AA-A70B-AEE1A6C0718A"}]}]}],"references":[{"url":"https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-1-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/601857","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3688717","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-11379","sourceIdentifier":"cve@gitlab.com","published":"2026-06-25T05:16:50.767","lastModified":"2026-06-26T18:34:26.150","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 13.11 prior to 18.11.6, 19.0 prior to 19.0.3, and 19.1 prior to 19.1.1 in which incorrect authorization in DAST site profile management could allow a user with Developer role to exfiltrate DAST site profile secrets under certain conditions."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"13.11","lessThan":"18.11.6","versionType":"semver","status":"affected"},{"version":"19.0","lessThan":"19.0.3","versionType":"semver","status":"affected"},{"version":"19.1","lessThan":"19.1.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-06-25T13:10:02.747596Z","id":"CVE-2026-11379","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.11.0","versionEndExcluding":"18.11.6","matchCriteriaId":"2248E1A1-D78E-4BD8-A5D3-29F93FE2A2D8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.0.0","versionEndExcluding":"19.0.3","matchCriteriaId":"D398AA66-56F3-4ED2-AD85-E2C094EE577E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:19.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"49957E0D-C888-4AB1-9C15-8CD6E55454B1"}]}]}],"references":[{"url":"https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-1-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/517659","source":"cve@gitlab.com","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2026-12053","sourceIdentifier":"cve@gitlab.com","published":"2026-06-25T05:16:50.890","lastModified":"2026-06-26T18:33:13.820","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.1 that under certain conditions could have allowed a user to access sensitive information that had already been committed to a project, due to insufficient output filtering in Duo Workflows."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"19.1","lessThan":"19.1.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N","baseScore":8.6,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":4.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-06-25T13:17:13.971317Z","id":"CVE-2026-12053","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-532"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:19.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"49957E0D-C888-4AB1-9C15-8CD6E55454B1"}]}]}],"references":[{"url":"https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-1-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/602194","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3757762","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-12635","sourceIdentifier":"cve@gitlab.com","published":"2026-06-25T05:16:51.170","lastModified":"2026-06-26T18:29:37.460","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with maintainer-role permissions to make requests to internal network resources through mirror synchronization due to improper URL validation."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"8.3","lessThan":"18.11.6","versionType":"semver","status":"affected"},{"version":"19.0","lessThan":"19.0.3","versionType":"semver","status":"affected"},{"version":"19.1","lessThan":"19.1.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:N","baseScore":0.0,"baseSeverity":"NONE","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":0.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":3.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-06-25T13:23:32.053651Z","id":"CVE-2026-12635","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-350"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"8.3.0","versionEndExcluding":"18.11.6","matchCriteriaId":"7B473040-DFF5-4D47-ACBD-7E281202D370"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"19.0.0","versionEndExcluding":"19.0.3","matchCriteriaId":"9AF0E03E-D1A7-4C9E-B0BC-9EE4A5BE7CCC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:19.1.0:*:*:*:*:*:*:*","matchCriteriaId":"49004C41-7512-49AA-A70B-AEE1A6C0718A"}]}]}],"references":[{"url":"https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-1-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/594321","source":"cve@gitlab.com","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2026-1606","sourceIdentifier":"cve@gitlab.com","published":"2026-06-25T05:16:52.920","lastModified":"2026-06-26T18:40:32.407","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.8 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user to conceal content within a Snippet due to improper input validation."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"14.8","lessThan":"18.11.6","versionType":"semver","status":"affected"},{"version":"19.0","lessThan":"19.0.3","versionType":"semver","status":"affected"},{"version":"19.1","lessThan":"19.1.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-06-25T12:51:03.290608Z","id":"CVE-2026-1606","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-94"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"14.8.0","versionEndExcluding":"18.11.6","matchCriteriaId":"C4856818-AB16-4928-8938-824CB00A7BE5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"19.0.0","versionEndExcluding":"19.0.3","matchCriteriaId":"9AF0E03E-D1A7-4C9E-B0BC-9EE4A5BE7CCC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:19.1.0:*:*:*:*:*:*:*","matchCriteriaId":"49004C41-7512-49AA-A70B-AEE1A6C0718A"}]}]}],"references":[{"url":"https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-1-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/588128","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3527473","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-2238","sourceIdentifier":"cve@gitlab.com","published":"2026-06-25T05:16:53.323","lastModified":"2026-06-26T18:40:02.447","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.5 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an unauthenticated user to view confidential issue references on public projects due to improper authorization checks."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.5","lessThan":"18.11.6","versionType":"semver","status":"affected"},{"version":"19.0","lessThan":"19.0.3","versionType":"semver","status":"affected"},{"version":"19.1","lessThan":"19.1.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-06-25T12:55:19.991027Z","id":"CVE-2026-2238","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"17.5.0","versionEndExcluding":"18.11.6","matchCriteriaId":"A6C7CC57-7148-48F4-B67D-9E9AF67C4138"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"19.0.0","versionEndExcluding":"19.0.3","matchCriteriaId":"9AF0E03E-D1A7-4C9E-B0BC-9EE4A5BE7CCC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:19.1.0:*:*:*:*:*:*:*","matchCriteriaId":"49004C41-7512-49AA-A70B-AEE1A6C0718A"}]}]}],"references":[{"url":"https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-1-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/589186","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3543011","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-3176","sourceIdentifier":"cve@gitlab.com","published":"2026-06-25T05:16:53.440","lastModified":"2026-06-26T18:26:22.103","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with limited permissions to access project information due to insufficient authorization checks."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.6","lessThan":"18.11.6","versionType":"semver","status":"affected"},{"version":"19.0","lessThan":"19.0.3","versionType":"semver","status":"affected"},{"version":"19.1","lessThan":"19.1.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":3.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-06-25T12:58:32.824711Z","id":"CVE-2026-3176","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.6.0","versionEndExcluding":"18.11.6","matchCriteriaId":"17A1B3DA-A793-4A56-8A13-563B391730D0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.0.0","versionEndExcluding":"19.0.3","matchCriteriaId":"D398AA66-56F3-4ED2-AD85-E2C094EE577E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:19.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"49957E0D-C888-4AB1-9C15-8CD6E55454B1"}]}]}],"references":[{"url":"https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-1-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/591373","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3568164","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-5309","sourceIdentifier":"cve@gitlab.com","published":"2026-06-25T05:16:55.390","lastModified":"2026-06-26T18:05:00.820","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user to read or modify another group's virtual registry cleanup policy settings without authorization."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.6","lessThan":"18.11.6","versionType":"semver","status":"affected"},{"version":"19.0","lessThan":"19.0.3","versionType":"semver","status":"affected"},{"version":"19.1","lessThan":"19.1.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-06-25T13:01:32.835888Z","id":"CVE-2026-5309","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-639"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.6.0","versionEndExcluding":"18.11.6","matchCriteriaId":"17A1B3DA-A793-4A56-8A13-563B391730D0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.0.0","versionEndExcluding":"19.0.3","matchCriteriaId":"D398AA66-56F3-4ED2-AD85-E2C094EE577E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:19.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"49957E0D-C888-4AB1-9C15-8CD6E55454B1"}]}]}],"references":[{"url":"https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-1-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/595468","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3628793","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-5796","sourceIdentifier":"cve@gitlab.com","published":"2026-06-25T05:16:55.510","lastModified":"2026-06-26T18:39:25.990","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with Reporter-level group permissions to view package metadata from projects with the Package Registry disabled due to incorrect authorization checks in the group packages feature."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"13.6","lessThan":"18.11.6","versionType":"semver","status":"affected"},{"version":"19.0","lessThan":"19.0.3","versionType":"semver","status":"affected"},{"version":"19.1","lessThan":"19.1.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-06-25T13:02:59.427397Z","id":"CVE-2026-5796","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"13.6.0","versionEndExcluding":"18.11.6","matchCriteriaId":"A72D2ADC-8533-47EE-8CED-7135169B6EA6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"19.0.0","versionEndExcluding":"19.0.3","matchCriteriaId":"9AF0E03E-D1A7-4C9E-B0BC-9EE4A5BE7CCC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:19.1.0:*:*:*:*:*:*:*","matchCriteriaId":"49004C41-7512-49AA-A70B-AEE1A6C0718A"}]}]}],"references":[{"url":"https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-1-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/596035","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3646902","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-5952","sourceIdentifier":"cve@gitlab.com","published":"2026-06-25T05:16:55.620","lastModified":"2026-06-26T18:38:49.427","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.11 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to bypass package protection rules and overwrite protected Maven package metadata due to incorrect authorization checks."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.11","lessThan":"18.11.6","versionType":"semver","status":"affected"},{"version":"19.0","lessThan":"19.0.3","versionType":"semver","status":"affected"},{"version":"19.1","lessThan":"19.1.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-06-25T13:06:34.162967Z","id":"CVE-2026-5952","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"17.11.0","versionEndExcluding":"18.11.6","matchCriteriaId":"74624962-150A-450A-9F64-F6A1CAF1A223"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"19.0.0","versionEndExcluding":"19.0.3","matchCriteriaId":"9AF0E03E-D1A7-4C9E-B0BC-9EE4A5BE7CCC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:19.1.0:*:*:*:*:*:*:*","matchCriteriaId":"49004C41-7512-49AA-A70B-AEE1A6C0718A"}]}]}],"references":[{"url":"https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-1-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/596134","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3632428","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-8330","sourceIdentifier":"cve@gitlab.com","published":"2026-06-25T05:16:55.733","lastModified":"2026-06-26T18:24:38.023","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.3 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed sensitive information to be written to application logs due to insufficient filtering in a CI/CD API endpoint."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"9.3","lessThan":"18.11.6","versionType":"semver","status":"affected"},{"version":"19.0","lessThan":"19.0.3","versionType":"semver","status":"affected"},{"version":"19.1","lessThan":"19.1.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","baseScore":4.4,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":0.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-06-25T13:09:13.818558Z","id":"CVE-2026-8330","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-532"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"9.3.0","versionEndExcluding":"18.11.6","matchCriteriaId":"DFE0E06D-DEBC-48A1-B2B5-05D2A44160C5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"19.0.0","versionEndExcluding":"19.0.3","matchCriteriaId":"9AF0E03E-D1A7-4C9E-B0BC-9EE4A5BE7CCC"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:19.1.0:*:*:*:*:*:*:*","matchCriteriaId":"49004C41-7512-49AA-A70B-AEE1A6C0718A"}]}]}],"references":[{"url":"https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-1-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/599621","source":"cve@gitlab.com","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2025-12506","sourceIdentifier":"cve@gitlab.com","published":"2026-07-08T21:16:44.493","lastModified":"2026-07-09T20:17:33.973","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.5 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user to create a repository where the content displayed in the web interface differed from the content available for download, due to improper handling of Git reference name resolution."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.5","lessThan":"18.11.7","versionType":"semver","status":"affected"},{"version":"19.0","lessThan":"19.0.4","versionType":"semver","status":"affected"},{"version":"19.1","lessThan":"19.1.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N","baseScore":3.5,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-09T13:53:19.849180Z","id":"CVE-2025-12506","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-706"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.5.0","versionEndExcluding":"18.11.7","matchCriteriaId":"F80A630E-B6B3-4F61-AB1E-1E7A162A2748"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.5.0","versionEndExcluding":"18.11.7","matchCriteriaId":"F05C9C1B-B9B8-4C37-9058-E94A474ACFAF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"19.0.0","versionEndExcluding":"19.0.4","matchCriteriaId":"EFCDDDB3-8242-420F-AAA0-65985B9B525D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.0.0","versionEndExcluding":"19.0.4","matchCriteriaId":"77F37C9F-5A51-4AD0-A919-F74CA49F8048"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"19.1.0","versionEndExcluding":"19.1.2","matchCriteriaId":"C12717E0-C005-4D05-8B76-6D974C5CED08"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.1.0","versionEndExcluding":"19.1.2","matchCriteriaId":"71AC7E45-C1B7-4EFE-8C29-E1D7ADD3D9F4"}]}]}],"references":[{"url":"https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-1-2-released/","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/578988","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3351460","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-11827","sourceIdentifier":"cve@gitlab.com","published":"2026-07-08T21:16:46.397","lastModified":"2026-07-09T20:15:29.420","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 9.5 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with maintainer-role permissions to obtain another user's stored credentials due to improper authorization controls."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"9.5","lessThan":"18.11.7","versionType":"semver","status":"affected"},{"version":"19.0","lessThan":"19.0.4","versionType":"semver","status":"affected"},{"version":"19.1","lessThan":"19.1.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-09T14:14:56.093248Z","id":"CVE-2026-11827","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-522"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"9.5.0","versionEndExcluding":"18.11.7","matchCriteriaId":"66FFC736-5D40-413C-BEA8-94FCADEC35C6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.0.0","versionEndExcluding":"19.0.4","matchCriteriaId":"77F37C9F-5A51-4AD0-A919-F74CA49F8048"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.1.0","versionEndExcluding":"19.1.2","matchCriteriaId":"71AC7E45-C1B7-4EFE-8C29-E1D7ADD3D9F4"}]}]}],"references":[{"url":"https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-1-2-released/","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/602478","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3720483","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-13320","sourceIdentifier":"cve@gitlab.com","published":"2026-07-08T21:16:46.630","lastModified":"2026-07-09T20:35:14.233","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.7 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user to execute arbitrary scripts in another user's browser session due to improper sanitization of user-supplied input."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.7","lessThan":"18.11.7","versionType":"semver","status":"affected"},{"version":"19.0","lessThan":"19.0.4","versionType":"semver","status":"affected"},{"version":"19.1","lessThan":"19.1.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:N","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.0,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-09T13:41:38.644164Z","id":"CVE-2026-13320","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.7.0","versionEndExcluding":"18.11.7","matchCriteriaId":"755A1ECC-3D10-4301-AF23-98AC37B872C9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.7.0","versionEndExcluding":"18.11.7","matchCriteriaId":"F91F3636-63EF-452A-B8F1-FA4E6FF9D109"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"19.0.0","versionEndExcluding":"19.0.4","matchCriteriaId":"EFCDDDB3-8242-420F-AAA0-65985B9B525D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.0.0","versionEndExcluding":"19.0.4","matchCriteriaId":"77F37C9F-5A51-4AD0-A919-F74CA49F8048"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"19.1.0","versionEndExcluding":"19.1.2","matchCriteriaId":"C12717E0-C005-4D05-8B76-6D974C5CED08"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.1.0","versionEndExcluding":"19.1.2","matchCriteriaId":"71AC7E45-C1B7-4EFE-8C29-E1D7ADD3D9F4"}]}]}],"references":[{"url":"https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-1-2-released/","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/604063","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3816917","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-6352","sourceIdentifier":"cve@gitlab.com","published":"2026-07-08T21:16:54.960","lastModified":"2026-07-09T20:36:00.707","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with auditor-level access to modify compliance violation records due to improper authorization on certain GraphQL operations."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.2","lessThan":"18.11.7","versionType":"semver","status":"affected"},{"version":"19.0","lessThan":"19.0.4","versionType":"semver","status":"affected"},{"version":"19.1","lessThan":"19.1.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N","baseScore":2.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-09T14:13:12.188493Z","id":"CVE-2026-6352","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"18.11.7","matchCriteriaId":"1B2372E0-84F3-4C53-AD65-D9E60AE7A564"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.0.0","versionEndExcluding":"19.0.4","matchCriteriaId":"77F37C9F-5A51-4AD0-A919-F74CA49F8048"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.1.0","versionEndExcluding":"19.1.2","matchCriteriaId":"71AC7E45-C1B7-4EFE-8C29-E1D7ADD3D9F4"}]}]}],"references":[{"url":"https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-1-2-released/","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/596789","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3631344","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-6896","sourceIdentifier":"cve@gitlab.com","published":"2026-07-08T21:16:55.097","lastModified":"2026-07-09T20:38:26.077","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 13.11 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute arbitrary scripts in another user's browser session due to improper sanitization of user-supplied input."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"13.11","lessThan":"18.11.7","versionType":"semver","status":"affected"},{"version":"19.0","lessThan":"19.0.4","versionType":"semver","status":"affected"},{"version":"19.1","lessThan":"19.1.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-09T14:13:44.236024Z","id":"CVE-2026-6896","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.11.0","versionEndExcluding":"18.11.7","matchCriteriaId":"32643EA5-8C1A-418A-A6B5-EDCADEC8C79E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.0.0","versionEndExcluding":"19.0.4","matchCriteriaId":"77F37C9F-5A51-4AD0-A919-F74CA49F8048"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.1.0","versionEndExcluding":"19.1.2","matchCriteriaId":"71AC7E45-C1B7-4EFE-8C29-E1D7ADD3D9F4"}]}]}],"references":[{"url":"https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-1-2-released/","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/597887","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3682085","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-7492","sourceIdentifier":"cve@gitlab.com","published":"2026-07-08T21:16:55.213","lastModified":"2026-07-09T20:37:12.463","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.1 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an unauthenticated user to determine the existence of a private project due to improper authorization controls on cross-project reference pages."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"9.1","lessThan":"18.11.7","versionType":"semver","status":"affected"},{"version":"19.0","lessThan":"19.0.4","versionType":"semver","status":"affected"},{"version":"19.1","lessThan":"19.1.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-09T14:14:09.362350Z","id":"CVE-2026-7492","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"9.1.0","versionEndExcluding":"18.11.7","matchCriteriaId":"A662B6DB-BEB1-4E15-B7C0-4B661D363525"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"9.1.0","versionEndExcluding":"18.11.7","matchCriteriaId":"0C9C6A25-5370-4E15-98E3-CC630B6B3C18"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"19.0.0","versionEndExcluding":"19.0.4","matchCriteriaId":"EFCDDDB3-8242-420F-AAA0-65985B9B525D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.0.0","versionEndExcluding":"19.0.4","matchCriteriaId":"77F37C9F-5A51-4AD0-A919-F74CA49F8048"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"19.1.0","versionEndExcluding":"19.1.2","matchCriteriaId":"C12717E0-C005-4D05-8B76-6D974C5CED08"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.1.0","versionEndExcluding":"19.1.2","matchCriteriaId":"71AC7E45-C1B7-4EFE-8C29-E1D7ADD3D9F4"}]}]}],"references":[{"url":"https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-1-2-released/","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/597947","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3704739","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-8472","sourceIdentifier":"cve@gitlab.com","published":"2026-07-08T21:16:55.327","lastModified":"2026-07-10T13:02:22.957","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with minimal access permissions to read work item metadata from private projects due to missing authorization checks."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.9","lessThan":"18.11.7","versionType":"semver","status":"affected"},{"version":"19.0","lessThan":"19.0.4","versionType":"semver","status":"affected"},{"version":"19.1","lessThan":"19.1.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-09T14:14:37.744166Z","id":"CVE-2026-8472","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.11.7","matchCriteriaId":"D2243C03-3CA0-476A-AB5A-7E8B2C95B209"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.0.0","versionEndExcluding":"19.0.4","matchCriteriaId":"77F37C9F-5A51-4AD0-A919-F74CA49F8048"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.1.0","versionEndExcluding":"19.1.2","matchCriteriaId":"71AC7E45-C1B7-4EFE-8C29-E1D7ADD3D9F4"}]}]}],"references":[{"url":"https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-1-2-released/","source":"cve@gitlab.com","tags":["Vendor Advisory","Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/599987","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3615282","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-14562","sourceIdentifier":"cve@gitlab.com","published":"2026-07-29T20:17:00.067","lastModified":"2026-08-03T13:44:10.667","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to commit changes to a project after being removed as a member, due to improper authorization checks on merge request collaboration settings."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"10.6","lessThan":"19.0.5","versionType":"semver","status":"affected"},{"version":"19.1","lessThan":"19.1.3","versionType":"semver","status":"affected"},{"version":"19.2","lessThan":"19.2.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":3.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-29T19:33:37.371507Z","id":"CVE-2025-14562","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.6.0","versionEndExcluding":"19.0.5","matchCriteriaId":"37FBD6D5-5332-47FA-937B-AF2FD6CD23EB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.6.0","versionEndExcluding":"19.0.5","matchCriteriaId":"C3A123A9-46BD-4A10-BC8F-4A4ED8F0C558"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"19.1.0","versionEndExcluding":"19.1.3","matchCriteriaId":"A63CCF5E-7A62-47E0-8949-269E2487CC82"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.1.0","versionEndExcluding":"19.1.3","matchCriteriaId":"02C7C8D4-9DFC-42F5-9E73-C2E81B2A7C3C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:19.2.0:*:*:*:community:*:*:*","matchCriteriaId":"CB23328F-6D4D-4FBE-8AF1-11AE68F7F824"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:19.2.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"2BA0ECDA-CCC7-41A9-8FFD-3557AE49F9B2"}]}]}],"references":[{"url":"https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/583889","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3460445","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-12436","sourceIdentifier":"cve@gitlab.com","published":"2026-07-29T20:17:00.417","lastModified":"2026-08-03T13:42:46.800","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to modify CI/CD configuration belonging to another user due to improper validation of user-supplied attributes when processing pipeline schedule inputs."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.0","lessThan":"19.0.5","versionType":"semver","status":"affected"},{"version":"19.1","lessThan":"19.1.3","versionType":"semver","status":"affected"},{"version":"19.2","lessThan":"19.2.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L","baseScore":8.4,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":1.8,"impactScore":6.0}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-30T03:55:42.557469Z","id":"CVE-2026-12436","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-915"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.0.0","versionEndExcluding":"19.0.5","matchCriteriaId":"0647A01C-2AF0-46B2-B951-E0E21DD88514"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.0.0","versionEndExcluding":"19.0.5","matchCriteriaId":"98F5731F-B97D-4C93-AFF2-AD487A2E97C6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"19.1.0","versionEndExcluding":"19.1.3","matchCriteriaId":"A63CCF5E-7A62-47E0-8949-269E2487CC82"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.1.0","versionEndExcluding":"19.1.3","matchCriteriaId":"02C7C8D4-9DFC-42F5-9E73-C2E81B2A7C3C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:19.2.0:*:*:*:community:*:*:*","matchCriteriaId":"CB23328F-6D4D-4FBE-8AF1-11AE68F7F824"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:19.2.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"2BA0ECDA-CCC7-41A9-8FFD-3557AE49F9B2"}]}]}],"references":[{"url":"https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/603223","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3800511","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-13113","sourceIdentifier":"cve@gitlab.com","published":"2026-07-29T20:17:00.550","lastModified":"2026-08-03T13:29:14.830","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 17.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to merge code into a protected branch without the required approvals due to a race condition in approval rule processing."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.0","lessThan":"19.0.5","versionType":"semver","status":"affected"},{"version":"19.1","lessThan":"19.1.3","versionType":"semver","status":"affected"},{"version":"19.2","lessThan":"19.2.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-29T19:42:19.157690Z","id":"CVE-2026-13113","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Primary","description":[{"lang":"en","value":"CWE-367"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"19.0.5","matchCriteriaId":"EE1CB1F1-E8BB-45B5-987E-64A979683416"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.1.0","versionEndExcluding":"19.1.3","matchCriteriaId":"02C7C8D4-9DFC-42F5-9E73-C2E81B2A7C3C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:19.2.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"2BA0ECDA-CCC7-41A9-8FFD-3557AE49F9B2"}]}]}],"references":[{"url":"https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/597838","source":"cve@gitlab.com","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2026-14341","sourceIdentifier":"cve@gitlab.com","published":"2026-07-29T20:17:01.063","lastModified":"2026-08-03T13:28:24.863","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with Maintainer role to modify protected branch configuration due to improper authorization in a projects API endpoint."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"12.8","lessThan":"19.0.5","versionType":"semver","status":"affected"},{"version":"19.1","lessThan":"19.1.3","versionType":"semver","status":"affected"},{"version":"19.2","lessThan":"19.2.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-29T19:43:48.858149Z","id":"CVE-2026-14341","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.8.0","versionEndExcluding":"19.0.5","matchCriteriaId":"8E172A09-A7EA-4560-A9B2-E9A3DFC67DF6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.8.0","versionEndExcluding":"19.0.5","matchCriteriaId":"13699532-480B-4539-ADE8-4586D273B6D1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"19.1.0","versionEndExcluding":"19.1.3","matchCriteriaId":"A63CCF5E-7A62-47E0-8949-269E2487CC82"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.1.0","versionEndExcluding":"19.1.3","matchCriteriaId":"02C7C8D4-9DFC-42F5-9E73-C2E81B2A7C3C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:19.2.0:*:*:*:community:*:*:*","matchCriteriaId":"CB23328F-6D4D-4FBE-8AF1-11AE68F7F824"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:19.2.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"2BA0ECDA-CCC7-41A9-8FFD-3557AE49F9B2"}]}]}],"references":[{"url":"https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/604665","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3807593","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-14351","sourceIdentifier":"cve@gitlab.com","published":"2026-07-29T20:17:01.197","lastModified":"2026-08-03T13:27:26.207","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an unauthenticated user to view the title of a confidential issue through a publicly accessible merge request due to improper authorization checks."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"8.8","lessThan":"19.0.5","versionType":"semver","status":"affected"},{"version":"19.1","lessThan":"19.1.3","versionType":"semver","status":"affected"},{"version":"19.2","lessThan":"19.2.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-29T19:33:44.703173Z","id":"CVE-2026-14351","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Primary","description":[{"lang":"en","value":"CWE-1230"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.8.0","versionEndExcluding":"19.0.5","matchCriteriaId":"02791505-2EDD-4B46-AB29-80F8F45B7150"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.8.0","versionEndExcluding":"19.0.5","matchCriteriaId":"9E557078-357B-4E20-932E-D05965C7B2B3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"19.1.0","versionEndExcluding":"19.1.3","matchCriteriaId":"A63CCF5E-7A62-47E0-8949-269E2487CC82"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.1.0","versionEndExcluding":"19.1.3","matchCriteriaId":"02C7C8D4-9DFC-42F5-9E73-C2E81B2A7C3C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:19.2.0:*:*:*:community:*:*:*","matchCriteriaId":"CB23328F-6D4D-4FBE-8AF1-11AE68F7F824"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:19.2.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"2BA0ECDA-CCC7-41A9-8FFD-3557AE49F9B2"}]}]}],"references":[{"url":"https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/604691","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3708242","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-15077","sourceIdentifier":"cve@gitlab.com","published":"2026-07-29T20:17:01.690","lastModified":"2026-08-03T13:26:04.457","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.3 and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to access information from unauthorized projects due to improper neutralization of untrusted content processed by the AI-assisted code review functionality."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"19.1","lessThan":"19.1.3","versionType":"semver","status":"affected"},{"version":"19.2","lessThan":"19.2.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-29T19:33:13.987893Z","id":"CVE-2026-15077","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-74"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.1.0","versionEndExcluding":"19.1.3","matchCriteriaId":"02C7C8D4-9DFC-42F5-9E73-C2E81B2A7C3C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:19.2.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"2BA0ECDA-CCC7-41A9-8FFD-3557AE49F9B2"}]}]}],"references":[{"url":"https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/601482","source":"cve@gitlab.com","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2026-15831","sourceIdentifier":"cve@gitlab.com","published":"2026-07-29T20:17:01.983","lastModified":"2026-08-03T12:59:58.090","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.3 and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to bypass administrator-configured tool governance policies due to improper authorization enforcement during token generation."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"19.1","lessThan":"19.1.3","versionType":"semver","status":"affected"},{"version":"19.2","lessThan":"19.2.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-29T19:32:41.478838Z","id":"CVE-2026-15831","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Primary","description":[{"lang":"en","value":"CWE-1270"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.1.0","versionEndExcluding":"19.1.3","matchCriteriaId":"02C7C8D4-9DFC-42F5-9E73-C2E81B2A7C3C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:19.2.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"2BA0ECDA-CCC7-41A9-8FFD-3557AE49F9B2"}]}]}],"references":[{"url":"https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/605484","source":"cve@gitlab.com","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2026-15975","sourceIdentifier":"cve@gitlab.com","published":"2026-07-29T20:17:02.117","lastModified":"2026-08-03T14:28:00.947","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an unauthenticated user to cause a denial of service due to insufficient resource throttling when processing merge request discussions."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"11.8","lessThan":"19.0.5","versionType":"semver","status":"affected"},{"version":"19.1","lessThan":"19.1.3","versionType":"semver","status":"affected"},{"version":"19.2","lessThan":"19.2.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-29T19:32:13.534654Z","id":"CVE-2026-15975","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Primary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"19.0.5","matchCriteriaId":"0DB4A8D4-3CEE-4628-A07D-AFF0F964A7D3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.8.0","versionEndExcluding":"19.0.5","matchCriteriaId":"4BF88976-ED37-4769-A3D5-4B2ADE272030"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"19.1.0","versionEndExcluding":"19.1.3","matchCriteriaId":"A63CCF5E-7A62-47E0-8949-269E2487CC82"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.1.0","versionEndExcluding":"19.1.3","matchCriteriaId":"02C7C8D4-9DFC-42F5-9E73-C2E81B2A7C3C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:19.2.0:*:*:*:community:*:*:*","matchCriteriaId":"CB23328F-6D4D-4FBE-8AF1-11AE68F7F824"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:19.2.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"2BA0ECDA-CCC7-41A9-8FFD-3557AE49F9B2"}]}]}],"references":[{"url":"https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/601420","source":"cve@gitlab.com","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2026-16553","sourceIdentifier":"cve@gitlab.com","published":"2026-07-29T20:17:02.460","lastModified":"2026-08-03T14:14:35.333","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed some sensitive information to be disclosed to an unintended host due to improper handling of upstream requests in virtual registries."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.8","lessThan":"19.0.5","versionType":"semver","status":"affected"},{"version":"19.1","lessThan":"19.1.3","versionType":"semver","status":"affected"},{"version":"19.2","lessThan":"19.2.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-29T19:31:32.638083Z","id":"CVE-2026-16553","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Primary","description":[{"lang":"en","value":"CWE-522"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"19.0.5","matchCriteriaId":"ACDDDB77-8594-4D29-B890-8BB788E6497F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.1.0","versionEndExcluding":"19.1.3","matchCriteriaId":"02C7C8D4-9DFC-42F5-9E73-C2E81B2A7C3C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:19.2.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"2BA0ECDA-CCC7-41A9-8FFD-3557AE49F9B2"}]}]}],"references":[{"url":"https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/603269","source":"cve@gitlab.com","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2026-3093","sourceIdentifier":"cve@gitlab.com","published":"2026-07-29T20:17:03.137","lastModified":"2026-08-03T14:04:02.133","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an attacker to execute arbitrary JavaScript in another user's browser via a crafted URL, due to improper sanitization of user-controlled input."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"14.0","lessThan":"19.0.5","versionType":"semver","status":"affected"},{"version":"19.1","lessThan":"19.1.3","versionType":"semver","status":"affected"},{"version":"19.2","lessThan":"19.2.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":4.7,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-29T19:34:51.686360Z","id":"CVE-2026-3093","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"19.0.5","matchCriteriaId":"4172398D-1AC7-4165-9341-F8C0961943ED"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"19.0.5","matchCriteriaId":"CD0AE2AB-F14E-40D0-B09C-5A3F08E32629"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"19.1.0","versionEndExcluding":"19.1.3","matchCriteriaId":"A63CCF5E-7A62-47E0-8949-269E2487CC82"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.1.0","versionEndExcluding":"19.1.3","matchCriteriaId":"02C7C8D4-9DFC-42F5-9E73-C2E81B2A7C3C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:19.2.0:*:*:*:community:*:*:*","matchCriteriaId":"CB23328F-6D4D-4FBE-8AF1-11AE68F7F824"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:19.2.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"2BA0ECDA-CCC7-41A9-8FFD-3557AE49F9B2"}]}]}],"references":[{"url":"https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/591274","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3539833","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-4672","sourceIdentifier":"cve@gitlab.com","published":"2026-07-29T20:17:03.963","lastModified":"2026-08-03T14:03:16.267","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with guest-role permissions to access test report contents they were not authorized to view due to improper access control enforcement."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.4","lessThan":"19.0.5","versionType":"semver","status":"affected"},{"version":"19.1","lessThan":"19.1.3","versionType":"semver","status":"affected"},{"version":"19.2","lessThan":"19.2.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-29T19:35:42.457995Z","id":"CVE-2026-4672","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.4.0","versionEndExcluding":"19.0.5","matchCriteriaId":"D8DD6476-EBB8-4D49-B0E8-F117D259F922"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.4.0","versionEndExcluding":"19.0.5","matchCriteriaId":"12BEEBC3-B865-494E-A7DD-91BB3ADF56F5"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"19.1.0","versionEndExcluding":"19.1.3","matchCriteriaId":"A63CCF5E-7A62-47E0-8949-269E2487CC82"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.1.0","versionEndExcluding":"19.1.3","matchCriteriaId":"02C7C8D4-9DFC-42F5-9E73-C2E81B2A7C3C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:19.2.0:*:*:*:community:*:*:*","matchCriteriaId":"CB23328F-6D4D-4FBE-8AF1-11AE68F7F824"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:19.2.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"2BA0ECDA-CCC7-41A9-8FFD-3557AE49F9B2"}]}]}],"references":[{"url":"https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/594528","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3617676","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-6267","sourceIdentifier":"cve@gitlab.com","published":"2026-07-29T20:17:13.123","lastModified":"2026-08-03T14:02:29.670","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with Developer role to access unauthorized information due to insufficient access controls on internal request handling."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"10.1.0","lessThan":"19.0.5","versionType":"semver","status":"affected"},{"version":"19.1","lessThan":"19.1.3","versionType":"semver","status":"affected"},{"version":"19.2","lessThan":"19.2.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":8.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":6.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-30T03:55:43.298969Z","id":"CVE-2026-6267","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-201"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"10.1.0","versionEndExcluding":"19.0.5","matchCriteriaId":"BE556341-8629-49A6-AC09-E30F29423BC4"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.1.0","versionEndExcluding":"19.0.5","matchCriteriaId":"01315736-306A-42F3-B9DD-1DE8C7A04DDD"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"19.1.0","versionEndExcluding":"19.1.3","matchCriteriaId":"A63CCF5E-7A62-47E0-8949-269E2487CC82"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.1.0","versionEndExcluding":"19.1.3","matchCriteriaId":"02C7C8D4-9DFC-42F5-9E73-C2E81B2A7C3C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:19.2.0:*:*:*:community:*:*:*","matchCriteriaId":"CB23328F-6D4D-4FBE-8AF1-11AE68F7F824"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:19.2.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"2BA0ECDA-CCC7-41A9-8FFD-3557AE49F9B2"}]}]}],"references":[{"url":"https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/596606","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3658324","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-6336","sourceIdentifier":"cve@gitlab.com","published":"2026-07-29T20:17:13.270","lastModified":"2026-08-03T13:58:30.287","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.6 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an unauthorized user to view project import source information due to a missing authorization check."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.6","lessThan":"19.0.5","versionType":"semver","status":"affected"},{"version":"19.1","lessThan":"19.1.3","versionType":"semver","status":"affected"},{"version":"19.2","lessThan":"19.2.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-29T19:40:43.985304Z","id":"CVE-2026-6336","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.6.0","versionEndExcluding":"19.0.5","matchCriteriaId":"1ED8EE05-8AF6-4309-B1E1-48F471B17352"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.6.0","versionEndExcluding":"19.0.5","matchCriteriaId":"5D03CD05-EDBD-49A3-87B1-6DD0369D24BF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"19.1.0","versionEndExcluding":"19.1.3","matchCriteriaId":"A63CCF5E-7A62-47E0-8949-269E2487CC82"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.1.0","versionEndExcluding":"19.1.3","matchCriteriaId":"02C7C8D4-9DFC-42F5-9E73-C2E81B2A7C3C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:19.2.0:*:*:*:community:*:*:*","matchCriteriaId":"CB23328F-6D4D-4FBE-8AF1-11AE68F7F824"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:19.2.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"2BA0ECDA-CCC7-41A9-8FFD-3557AE49F9B2"}]}]}],"references":[{"url":"https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/596762","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3661988","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-15423","sourceIdentifier":"cve@gitlab.com","published":"2026-08-12T18:17:23.820","lastModified":"2026-08-19T16:44:22.503","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute CI/CD pipelines on a protected branch without the required push permissions due to improper authorization in pipeline reference validation."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"19.0","lessThan":"19.0.6","versionType":"semver","status":"affected"},{"version":"19.1","lessThan":"19.1.4","versionType":"semver","status":"affected"},{"version":"19.2","lessThan":"19.2.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N","baseScore":8.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":4.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-13T14:56:59.857936Z","id":"CVE-2026-15423","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"19.0.0","versionEndExcluding":"19.0.6","matchCriteriaId":"284D8181-9E7E-4BFF-AC76-FDD5E094171A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.0.0","versionEndExcluding":"19.0.6","matchCriteriaId":"77597D9E-04E3-464B-B365-67BA3A49305E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"19.1.0","versionEndExcluding":"19.1.4","matchCriteriaId":"DAF19EF5-7EAB-4009-98CA-650FCCC71427"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.1.0","versionEndExcluding":"19.1.4","matchCriteriaId":"661A9F6B-ABD9-4472-AB05-1EF209A05C8F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"19.2.0","versionEndExcluding":"19.2.2","matchCriteriaId":"F8ECD226-79B1-4CAB-B862-9AD79EC7FE7E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.2.0","versionEndExcluding":"19.2.2","matchCriteriaId":"0E3FB1C2-D0B6-4462-9B66-9B93FF9330E3"}]}]}],"references":[{"url":"https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-2-released/","source":"cve@gitlab.com","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/605705","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3832069","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-16627","sourceIdentifier":"cve@gitlab.com","published":"2026-08-12T18:17:24.160","lastModified":"2026-08-19T15:59:51.830","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to escalate privileges due to improper sanitization of HTML content rendered in a CI job modal."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"19.2","lessThan":"19.2.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":7.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.3,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H","baseScore":9.0,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.3,"impactScore":6.0}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-12T00:00:00+00:00","id":"CVE-2026-16627","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"19.2.0","versionEndExcluding":"19.2.2","matchCriteriaId":"F8ECD226-79B1-4CAB-B862-9AD79EC7FE7E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.2.0","versionEndExcluding":"19.2.2","matchCriteriaId":"0E3FB1C2-D0B6-4462-9B66-9B93FF9330E3"}]}]}],"references":[{"url":"https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-2-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/606678","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3880796","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-18244","sourceIdentifier":"cve@gitlab.com","published":"2026-08-12T18:17:28.127","lastModified":"2026-08-19T15:58:58.680","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 17.7 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to view restricted configuration settings due to improper authorization checks on a group settings page."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.7","lessThan":"19.0.6","versionType":"semver","status":"affected"},{"version":"19.1","lessThan":"19.1.4","versionType":"semver","status":"affected"},{"version":"19.2","lessThan":"19.2.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-13T15:03:10.997646Z","id":"CVE-2026-18244","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.7.0","versionEndExcluding":"19.0.6","matchCriteriaId":"A71A77B0-1D74-4AB4-B265-42F32BB9E805"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.1.0","versionEndExcluding":"19.1.4","matchCriteriaId":"661A9F6B-ABD9-4472-AB05-1EF209A05C8F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.2.0","versionEndExcluding":"19.2.2","matchCriteriaId":"0E3FB1C2-D0B6-4462-9B66-9B93FF9330E3"}]}]}],"references":[{"url":"https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-2-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/597953","source":"cve@gitlab.com","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2026-7427","sourceIdentifier":"cve@gitlab.com","published":"2026-08-12T18:18:16.157","lastModified":"2026-08-19T15:57:57.313","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an unauthenticated user to cause a denial of service due to improper input validation."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.5","lessThan":"19.0.6","versionType":"semver","status":"affected"},{"version":"19.1","lessThan":"19.1.4","versionType":"semver","status":"affected"},{"version":"19.2","lessThan":"19.2.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-13T14:54:53.967895Z","id":"CVE-2026-7427","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.5.0","versionEndExcluding":"19.0.6","matchCriteriaId":"B04C96FA-1AB0-48A1-A037-7824705A8337"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.5.0","versionEndExcluding":"19.0.6","matchCriteriaId":"56529520-513E-458A-BDA8-2213DAA61219"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"19.1.0","versionEndExcluding":"19.1.4","matchCriteriaId":"DAF19EF5-7EAB-4009-98CA-650FCCC71427"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.1.0","versionEndExcluding":"19.1.4","matchCriteriaId":"661A9F6B-ABD9-4472-AB05-1EF209A05C8F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"19.2.0","versionEndExcluding":"19.2.2","matchCriteriaId":"F8ECD226-79B1-4CAB-B862-9AD79EC7FE7E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.2.0","versionEndExcluding":"19.2.2","matchCriteriaId":"0E3FB1C2-D0B6-4462-9B66-9B93FF9330E3"}]}]}],"references":[{"url":"https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-2-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/598561","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3638799","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-8667","sourceIdentifier":"cve@gitlab.com","published":"2026-08-12T18:18:16.283","lastModified":"2026-08-19T15:57:10.533","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.6 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2  that under certain conditions could have allowed an authenticated user with developer role to modify certain package registry metadata without the required maintainer-level permissions due to improper authorization checks."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.6","lessThan":"19.0.6","versionType":"semver","status":"affected"},{"version":"19.1","lessThan":"19.1.4","versionType":"semver","status":"affected"},{"version":"19.2","lessThan":"19.2.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-13T14:55:40.605379Z","id":"CVE-2026-8667","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.6.0","versionEndExcluding":"19.0.6","matchCriteriaId":"4904B286-58BF-409B-A34B-0FB88F85D9B0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.6.0","versionEndExcluding":"19.0.6","matchCriteriaId":"AC5D4290-1776-4CA7-9FC7-FD451D1365D1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"19.1.0","versionEndExcluding":"19.1.4","matchCriteriaId":"DAF19EF5-7EAB-4009-98CA-650FCCC71427"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.1.0","versionEndExcluding":"19.1.4","matchCriteriaId":"661A9F6B-ABD9-4472-AB05-1EF209A05C8F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"19.2.0","versionEndExcluding":"19.2.2","matchCriteriaId":"F8ECD226-79B1-4CAB-B862-9AD79EC7FE7E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.2.0","versionEndExcluding":"19.2.2","matchCriteriaId":"0E3FB1C2-D0B6-4462-9B66-9B93FF9330E3"}]}]}],"references":[{"url":"https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-2-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/600228","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3598070","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-9486","sourceIdentifier":"cve@gitlab.com","published":"2026-08-12T20:17:33.120","lastModified":"2026-08-19T16:32:23.603","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 15.6 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed a user with a pending membership to receive permissions granted by a custom role, due to incorrect privilege assignment that did not account for membership state."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.6","lessThan":"19.0.6","versionType":"semver","status":"affected"},{"version":"19.1","lessThan":"19.1.4","versionType":"semver","status":"affected"},{"version":"19.2","lessThan":"19.2.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N","baseScore":3.3,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":0.7,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-13T12:29:57.474985Z","id":"CVE-2025-9486","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-266"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.6.0","versionEndExcluding":"19.0.6","matchCriteriaId":"9CF8D7D2-FCC5-46B7-A231-1AB0693150B3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.1.0","versionEndExcluding":"19.1.4","matchCriteriaId":"661A9F6B-ABD9-4472-AB05-1EF209A05C8F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.2.0","versionEndExcluding":"19.2.2","matchCriteriaId":"0E3FB1C2-D0B6-4462-9B66-9B93FF9330E3"}]}]}],"references":[{"url":"https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-2-released/","source":"cve@gitlab.com","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/565412","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3262844","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-15216","sourceIdentifier":"cve@gitlab.com","published":"2026-08-12T20:17:36.513","lastModified":"2026-08-19T16:44:13.203","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed cross-site scripting due to improper neutralization of user-controlled data rendered in pagination controls by an analytics dashboard component."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.2","lessThan":"19.0.6","versionType":"semver","status":"affected"},{"version":"19.1","lessThan":"19.1.4","versionType":"semver","status":"affected"},{"version":"19.2","lessThan":"19.2.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":5.8}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-13T14:40:45.865820Z","id":"CVE-2026-15216","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"19.0.6","matchCriteriaId":"9C18FC81-B9BF-4522-A3B5-5EAD0C6C6F1C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"19.0.6","matchCriteriaId":"2DA34813-2D18-4C2F-AB37-EA58F9439386"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"19.1.0","versionEndExcluding":"19.1.4","matchCriteriaId":"DAF19EF5-7EAB-4009-98CA-650FCCC71427"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.1.0","versionEndExcluding":"19.1.4","matchCriteriaId":"661A9F6B-ABD9-4472-AB05-1EF209A05C8F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"19.2.0","versionEndExcluding":"19.2.2","matchCriteriaId":"F8ECD226-79B1-4CAB-B862-9AD79EC7FE7E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.2.0","versionEndExcluding":"19.2.2","matchCriteriaId":"0E3FB1C2-D0B6-4462-9B66-9B93FF9330E3"}]}]}],"references":[{"url":"https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-2-released/","source":"cve@gitlab.com","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/605448","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3830061","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-15217","sourceIdentifier":"cve@gitlab.com","published":"2026-08-12T20:17:36.667","lastModified":"2026-08-19T16:44:03.530","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed cross-site scripting due to improper neutralization of user-controlled values rendered in table cell content by an analytics dashboard component."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.2","lessThan":"19.0.6","versionType":"semver","status":"affected"},{"version":"19.1","lessThan":"19.1.4","versionType":"semver","status":"affected"},{"version":"19.2","lessThan":"19.2.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":5.8}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-13T14:39:04.917689Z","id":"CVE-2026-15217","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"19.0.6","matchCriteriaId":"9C18FC81-B9BF-4522-A3B5-5EAD0C6C6F1C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"19.0.6","matchCriteriaId":"2DA34813-2D18-4C2F-AB37-EA58F9439386"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"19.1.0","versionEndExcluding":"19.1.4","matchCriteriaId":"DAF19EF5-7EAB-4009-98CA-650FCCC71427"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.1.0","versionEndExcluding":"19.1.4","matchCriteriaId":"661A9F6B-ABD9-4472-AB05-1EF209A05C8F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"19.2.0","versionEndExcluding":"19.2.2","matchCriteriaId":"F8ECD226-79B1-4CAB-B862-9AD79EC7FE7E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.2.0","versionEndExcluding":"19.2.2","matchCriteriaId":"0E3FB1C2-D0B6-4462-9B66-9B93FF9330E3"}]}]}],"references":[{"url":"https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-2-released/","source":"cve@gitlab.com","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/605449","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3830478","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-16494","sourceIdentifier":"cve@gitlab.com","published":"2026-08-12T20:17:37.640","lastModified":"2026-08-19T16:32:34.817","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to modify project settings restricted to higher-privileged roles, due to missing authorization checks on a project update endpoint."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"19.1","lessThan":"19.1.4","versionType":"semver","status":"affected"},{"version":"19.2","lessThan":"19.2.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":4.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-13T14:41:27.907692Z","id":"CVE-2026-16494","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.1.0","versionEndExcluding":"19.1.4","matchCriteriaId":"661A9F6B-ABD9-4472-AB05-1EF209A05C8F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.2.0","versionEndExcluding":"19.2.2","matchCriteriaId":"0E3FB1C2-D0B6-4462-9B66-9B93FF9330E3"}]}]}],"references":[{"url":"https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-2-released/","source":"cve@gitlab.com","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/606580","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3775445","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-18433","sourceIdentifier":"cve@gitlab.com","published":"2026-08-12T20:17:41.723","lastModified":"2026-08-19T16:32:42.263","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to read policy configuration belonging to a namespace they were not authorized to access, due to incorrect authorization checks in a GraphQL query."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"19.1","lessThan":"19.1.4","versionType":"semver","status":"affected"},{"version":"19.2","lessThan":"19.2.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-13T14:42:18.635245Z","id":"CVE-2026-18433","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.1.0","versionEndExcluding":"19.1.4","matchCriteriaId":"661A9F6B-ABD9-4472-AB05-1EF209A05C8F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.2.0","versionEndExcluding":"19.2.2","matchCriteriaId":"0E3FB1C2-D0B6-4462-9B66-9B93FF9330E3"}]}]}],"references":[{"url":"https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-2-released/","source":"cve@gitlab.com","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/607556","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3776182","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-19228","sourceIdentifier":"cve@gitlab.com","published":"2026-08-12T20:17:42.213","lastModified":"2026-08-19T16:32:49.340","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to cause AI usage to be attributed to another namespace, due to improper authorization of identity information supplied in requests."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"19.1","lessThan":"19.1.4","versionType":"semver","status":"affected"},{"version":"19.2","lessThan":"19.2.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L","baseScore":8.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":3.1,"impactScore":4.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-13T14:42:56.055059Z","id":"CVE-2026-19228","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-639"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.1.0","versionEndExcluding":"19.1.4","matchCriteriaId":"661A9F6B-ABD9-4472-AB05-1EF209A05C8F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.2.0","versionEndExcluding":"19.2.2","matchCriteriaId":"0E3FB1C2-D0B6-4462-9B66-9B93FF9330E3"}]}]}],"references":[{"url":"https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-2-released/","source":"cve@gitlab.com","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/603347","source":"cve@gitlab.com","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2026-4879","sourceIdentifier":"cve@gitlab.com","published":"2026-08-12T20:17:44.850","lastModified":"2026-08-19T16:43:25.717","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 16.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to view external status check configuration restricted to higher-privileged roles due to missing authorization on a merge request API endpoint."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.0","lessThan":"19.0.6","versionType":"semver","status":"affected"},{"version":"19.1","lessThan":"19.1.4","versionType":"semver","status":"affected"},{"version":"19.2","lessThan":"19.2.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-13T12:19:33.226549Z","id":"CVE-2026-4879","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.0.0","versionEndExcluding":"19.0.6","matchCriteriaId":"9B9B904B-BFB0-4DB9-9616-E5B5282C8C79"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.1.0","versionEndExcluding":"19.1.4","matchCriteriaId":"661A9F6B-ABD9-4472-AB05-1EF209A05C8F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.2.0","versionEndExcluding":"19.2.2","matchCriteriaId":"0E3FB1C2-D0B6-4462-9B66-9B93FF9330E3"}]}]}],"references":[{"url":"https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-2-released/","source":"cve@gitlab.com","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/594839","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3622861","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-6821","sourceIdentifier":"cve@gitlab.com","published":"2026-08-12T20:17:49.327","lastModified":"2026-08-19T16:43:17.313","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 12.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to bypass IP-based access restrictions and read limited merge request information from a private project due to missing authorization checks in a merge requests API endpoint."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"12.0","lessThan":"19.0.6","versionType":"semver","status":"affected"},{"version":"19.1","lessThan":"19.1.4","versionType":"semver","status":"affected"},{"version":"19.2","lessThan":"19.2.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-13T15:29:15.440285Z","id":"CVE-2026-6821","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.0.0","versionEndExcluding":"19.0.6","matchCriteriaId":"8CCB1DCF-D86B-488A-9F8A-57D972B155F9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.1.0","versionEndExcluding":"19.1.4","matchCriteriaId":"661A9F6B-ABD9-4472-AB05-1EF209A05C8F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.2.0","versionEndExcluding":"19.2.2","matchCriteriaId":"0E3FB1C2-D0B6-4462-9B66-9B93FF9330E3"}]}]}],"references":[{"url":"https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-2-released/","source":"cve@gitlab.com","tags":["Release Notes"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/597702","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3674254","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-19478","sourceIdentifier":"cve@gitlab.com","published":"2026-08-17T20:16:41.777","lastModified":"2026-09-02T12:43:20.490","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.2","lessThan":"18.11.11","versionType":"semver","status":"affected"},{"version":"19.0","lessThan":"19.0.8","versionType":"semver","status":"affected"},{"version":"19.1","lessThan":"19.1.6","versionType":"semver","status":"affected"},{"version":"19.2","lessThan":"19.2.4","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H","baseScore":9.4,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-17T20:43:52.387073Z","id":"CVE-2026-19478","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-94"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"18.11.11","matchCriteriaId":"D528B105-3DE1-471D-9623-F491A9F0D8C8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"18.11.11","matchCriteriaId":"6CD95576-AC3B-4921-A002-72BD47579B77"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"19.0.0","versionEndExcluding":"19.0.8","matchCriteriaId":"C5EDDC0D-4D7B-4B69-A6F4-DA5A3A3C4638"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.0.0","versionEndExcluding":"19.0.8","matchCriteriaId":"A6B9C822-A303-486D-8787-73BA8A82C58B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"19.1.0","versionEndExcluding":"19.1.6","matchCriteriaId":"7BB02223-1F27-4183-840A-0AAC4F6F2A5C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.1.0","versionEndExcluding":"19.1.6","matchCriteriaId":"99D8510B-7BB5-4405-A3E6-D030BD420349"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"19.2.0","versionEndExcluding":"19.2.4","matchCriteriaId":"4D5485F8-E798-4A6B-B1C4-873D0DD58D8C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.2.0","versionEndExcluding":"19.2.4","matchCriteriaId":"F92746EA-6152-4A7C-8509-4A94DF041B94"}]}]}],"references":[{"url":"https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-4-released/","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/611377","source":"cve@gitlab.com","tags":["Not Applicable"]},{"url":"https://hackerone.com/reports/3926431","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-19650","sourceIdentifier":"cve@gitlab.com","published":"2026-08-17T20:16:41.910","lastModified":"2026-09-02T13:07:13.537","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could have allowed an unauthenticated user to execute mutations via GET requests due to improper request validation in GraphQL multiplex query handling."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.2","lessThan":"18.11.11","versionType":"semver","status":"affected"},{"version":"19.0","lessThan":"19.0.8","versionType":"semver","status":"affected"},{"version":"19.1","lessThan":"19.1.6","versionType":"semver","status":"affected"},{"version":"19.2","lessThan":"19.2.4","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":4.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-17T20:44:43.807063Z","id":"CVE-2026-19650","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-352"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"18.11.11","matchCriteriaId":"D528B105-3DE1-471D-9623-F491A9F0D8C8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"18.11.11","matchCriteriaId":"6CD95576-AC3B-4921-A002-72BD47579B77"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"19.0.0","versionEndExcluding":"19.0.8","matchCriteriaId":"C5EDDC0D-4D7B-4B69-A6F4-DA5A3A3C4638"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.0.0","versionEndExcluding":"19.0.8","matchCriteriaId":"A6B9C822-A303-486D-8787-73BA8A82C58B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"19.1.0","versionEndExcluding":"19.1.6","matchCriteriaId":"7BB02223-1F27-4183-840A-0AAC4F6F2A5C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.1.0","versionEndExcluding":"19.1.6","matchCriteriaId":"99D8510B-7BB5-4405-A3E6-D030BD420349"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"19.2.0","versionEndExcluding":"19.2.4","matchCriteriaId":"4D5485F8-E798-4A6B-B1C4-873D0DD58D8C"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.2.0","versionEndExcluding":"19.2.4","matchCriteriaId":"F92746EA-6152-4A7C-8509-4A94DF041B94"}]}]}],"references":[{"url":"https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-4-released/","source":"cve@gitlab.com","tags":["Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/612617","source":"cve@gitlab.com","tags":["Not Applicable"]},{"url":"https://hackerone.com/reports/3903669","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-10053","sourceIdentifier":"cve@gitlab.com","published":"2026-08-23T10:16:27.140","lastModified":"2026-08-31T14:42:52.997","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to achieve remote code execution due to a path traversal vulnerability in the package registry."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.8","lessThan":"19.0.6","versionType":"semver","status":"affected"},{"version":"19.1","lessThan":"19.1.4","versionType":"semver","status":"affected"},{"version":"19.2","lessThan":"19.2.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":8.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":6.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-24T00:00:00+00:00","id":"CVE-2026-10053","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-22"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"19.0.6","matchCriteriaId":"2914D7C6-EB9E-4374-B17E-672EAEF3EBC9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"19.0.6","matchCriteriaId":"5CF72893-6384-452B-B08A-110146147B74"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"19.1.0","versionEndExcluding":"19.1.4","matchCriteriaId":"DAF19EF5-7EAB-4009-98CA-650FCCC71427"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.1.0","versionEndExcluding":"19.1.4","matchCriteriaId":"661A9F6B-ABD9-4472-AB05-1EF209A05C8F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"19.2.0","versionEndExcluding":"19.2.2","matchCriteriaId":"F8ECD226-79B1-4CAB-B862-9AD79EC7FE7E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.2.0","versionEndExcluding":"19.2.2","matchCriteriaId":"0E3FB1C2-D0B6-4462-9B66-9B93FF9330E3"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/601596","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3754194","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2025-10903","sourceIdentifier":"cve@gitlab.com","published":"2026-08-26T14:17:06.597","lastModified":"2026-08-31T15:41:10.070","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 11.10 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user could have caused denial of service, due to an unbounded loop triggered by specially crafted input in the SCIM user provisioning feature."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"11.10","lessThan":"19.1.7","versionType":"semver","status":"affected"},{"version":"19.2","lessThan":"19.2.5","versionType":"semver","status":"affected"},{"version":"19.3","lessThan":"19.3.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-26T15:43:02.084655Z","id":"CVE-2025-10903","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-835"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.1.0","versionEndExcluding":"19.1.7","matchCriteriaId":"D364E33A-A890-4301-A2D9-E54284A70AD6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.2.0","versionEndExcluding":"19.2.5","matchCriteriaId":"80975E60-F9E7-41D6-A1CA-384E3CA3964D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:19.3.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"99734371-8B08-4207-88EB-D23AE5608E9D"}]}]}],"references":[{"url":"https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/571842","source":"cve@gitlab.com","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/3292470","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2026-15387","sourceIdentifier":"cve@gitlab.com","published":"2026-08-26T14:17:07.540","lastModified":"2026-08-31T15:41:20.753","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with developer-role permissions could have influenced the execution environment of Pipeline Execution Policy enforcement jobs, due to improper handling of job dependencies."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"19.1","lessThan":"19.1.7","versionType":"semver","status":"affected"},{"version":"19.2","lessThan":"19.2.5","versionType":"semver","status":"affected"},{"version":"19.3","lessThan":"19.3.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-26T15:40:37.265223Z","id":"CVE-2026-15387","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-349"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.1.0","versionEndExcluding":"19.1.7","matchCriteriaId":"3C6C042D-06D4-46F2-A318-D90564B13BA6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.2.0","versionEndExcluding":"19.2.5","matchCriteriaId":"80975E60-F9E7-41D6-A1CA-384E3CA3964D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:19.3.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"99734371-8B08-4207-88EB-D23AE5608E9D"}]}]}],"references":[{"url":"https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/605632","source":"cve@gitlab.com","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/3754358","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2026-18252","sourceIdentifier":"cve@gitlab.com","published":"2026-08-26T14:17:08.000","lastModified":"2026-08-31T15:42:04.433","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with developer-role permissions could have executed arbitrary commands in a CI context, due to the Claude agent processing configuration from a user-controlled source."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.9","lessThan":"19.1.7","versionType":"semver","status":"affected"},{"version":"19.2","lessThan":"19.2.5","versionType":"semver","status":"affected"},{"version":"19.3","lessThan":"19.3.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-26T00:00:00+00:00","id":"CVE-2026-18252","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-829"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"19.1.7","matchCriteriaId":"52CCB423-5677-48F1-AC4B-33B391881922"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.2.0","versionEndExcluding":"19.2.5","matchCriteriaId":"80975E60-F9E7-41D6-A1CA-384E3CA3964D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:19.3.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"99734371-8B08-4207-88EB-D23AE5608E9D"}]}]}],"references":[{"url":"https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/607342","source":"cve@gitlab.com","tags":["Issue Tracking"]},{"url":"https://hackerone.com/reports/3863650","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2026-3035","sourceIdentifier":"cve@gitlab.com","published":"2026-08-26T14:17:10.680","lastModified":"2026-08-31T15:42:23.067","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 11.3 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with project Maintainer permissions could have accessed the terminal of a protected environment they were not authorized to use due to improper authorization checks."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"11.3","lessThan":"19.1.7","versionType":"semver","status":"affected"},{"version":"19.2","lessThan":"19.2.5","versionType":"semver","status":"affected"},{"version":"19.3","lessThan":"19.3.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-26T15:41:36.331035Z","id":"CVE-2026-3035","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-288"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"19.1.7","matchCriteriaId":"A222BA0F-BC19-47F1-B6F7-A03B154630FE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.2.0","versionEndExcluding":"19.2.5","matchCriteriaId":"80975E60-F9E7-41D6-A1CA-384E3CA3964D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:19.3.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"99734371-8B08-4207-88EB-D23AE5608E9D"}]}]}],"references":[{"url":"https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/591189","source":"cve@gitlab.com","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/3529751","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2026-77801","sourceIdentifier":"cve@gitlab.com","published":"2026-08-26T14:17:15.757","lastModified":"2026-08-31T15:42:30.373","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.8 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, could have allowed an authenticated user to cause a denial of service affecting background job processing, due to missing object count limits."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"12.8","lessThan":"19.1.7","versionType":"semver","status":"affected"},{"version":"19.2","lessThan":"19.2.5","versionType":"semver","status":"affected"},{"version":"19.3","lessThan":"19.3.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-26T15:55:45.489642Z","id":"CVE-2026-77801","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.8.0","versionEndExcluding":"19.1.7","matchCriteriaId":"2A618F68-6664-43F3-8FE7-E295B2806FA9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.8.0","versionEndExcluding":"19.1.7","matchCriteriaId":"92B66601-A77F-4799-92D5-48D3EEC310C9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"19.2.0","versionEndExcluding":"19.2.5","matchCriteriaId":"4AC029F1-AA9C-422B-AD0C-3A01C0CF2EFA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.2.0","versionEndExcluding":"19.2.5","matchCriteriaId":"80975E60-F9E7-41D6-A1CA-384E3CA3964D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:19.3.0:*:*:*:community:*:*:*","matchCriteriaId":"D213E25A-F86A-47DA-ADE9-8CA1A57DCE08"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:19.3.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"99734371-8B08-4207-88EB-D23AE5608E9D"}]}]}],"references":[{"url":"https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/597273","source":"cve@gitlab.com","tags":["Issue Tracking","Permissions Required"]}]}},{"cve":{"id":"CVE-2026-7487","sourceIdentifier":"cve@gitlab.com","published":"2026-08-26T14:17:16.570","lastModified":"2026-08-31T15:43:30.173","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 13.1 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with reporter-role permissions who authored a merge request could have reset merge request approval rules due to improper authorization checks."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"13.1","lessThan":"19.1.7","versionType":"semver","status":"affected"},{"version":"19.2","lessThan":"19.2.5","versionType":"semver","status":"affected"},{"version":"19.3","lessThan":"19.3.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N","baseScore":3.5,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-26T15:41:03.557575Z","id":"CVE-2026-7487","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1280"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.1.0","versionEndExcluding":"19.1.7","matchCriteriaId":"0BA8776A-8D89-4452-B1BA-3C2934920790"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.2.0","versionEndExcluding":"19.2.5","matchCriteriaId":"80975E60-F9E7-41D6-A1CA-384E3CA3964D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:19.3.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"99734371-8B08-4207-88EB-D23AE5608E9D"}]}]}],"references":[{"url":"https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-1-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/598657","source":"cve@gitlab.com","tags":["Issue Tracking","Permissions Required"]},{"url":"https://hackerone.com/reports/3669140","source":"cve@gitlab.com","tags":["Permissions Required","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2026-75871","sourceIdentifier":"cve@gitlab.com","published":"2026-08-27T17:20:01.503","lastModified":"2026-09-01T20:32:55.990","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.10 to 19.0.12, 19.1 to 19.1.7, and 19.2 to 19.2.2 that could have allowed an authenticated user with Duo Agent Platform access to redirect outbound model requests to an externally-controlled endpoint via a crafted inline flow configuration that overrides the HTTP Host header, resulting in disclosure of Google Cloud Vertex cloud service credentials and private signing keys."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab AI Gateway","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:ai-gateway:*:*:*:*:*:*:*:*"],"versions":[{"version":"18.10","lessThan":"19.0.12","versionType":"semver","status":"affected"},{"version":"19.1","lessThan":"19.1.7","versionType":"semver","status":"affected"},{"version":"19.2","lessThan":"19.2.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N","baseScore":8.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.8,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N","baseScore":9.6,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":5.8}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-27T18:57:49.816563Z","id":"CVE-2026-75871","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"19.0.12","matchCriteriaId":"5EF25EDB-3901-4168-A2F3-245692D1BE49"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"19.1.0","versionEndExcluding":"19.1.7","matchCriteriaId":"2ACFE013-2319-46BB-B8CC-9C661AC933FB"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*","versionStartIncluding":"19.2.0","versionEndExcluding":"19.2.2","matchCriteriaId":"781686C8-AE07-45BF-B237-3CDEEA62BE4F"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/616990","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3945100","source":"cve@gitlab.com","tags":["Broken Link"]}]}},{"cve":{"id":"CVE-2026-85706","sourceIdentifier":"cve@gitlab.com","published":"2026-09-12T03:16:30.473","lastModified":"2026-09-14T14:22:15.323","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.7","lessThan":"19.1.8","versionType":"semver","status":"affected"},{"version":"19.2","lessThan":"19.2.6","versionType":"semver","status":"affected"},{"version":"19.3","lessThan":"19.3.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N","baseScore":10.0,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":5.8}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-12T03:55:28.970728Z","id":"CVE-2026-85706","options":[{"exploitation":"active"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"cisaExploitAdd":"2026-09-11","cisaActionDue":"2026-09-14","cisaRequiredAction":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","cisaVulnerabilityName":"GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability","weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-22"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.7.0","versionEndExcluding":"19.1.8","matchCriteriaId":"8308AEE0-FFC1-48F0-8E66-E3D6E3EF301E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.7.0","versionEndExcluding":"19.1.8","matchCriteriaId":"D19F6592-4940-46BE-A140-BCD284B0EC37"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"19.2.0","versionEndExcluding":"19.2.6","matchCriteriaId":"4A6AAECA-E557-43EF-B109-B92D1281E48B"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.2.0","versionEndExcluding":"19.2.6","matchCriteriaId":"8598AF82-D212-4B5D-ABC3-C12C9B217BF3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"19.3.0","versionEndExcluding":"19.3.2","matchCriteriaId":"198FF0EF-1A45-484F-9268-F7821E006BA8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"19.3.0","versionEndExcluding":"19.3.2","matchCriteriaId":"03B1901F-AAF4-421E-B704-5345CB840DEF"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/627748","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3909881","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-85706","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Third Party Advisory","US Government Resource"]}]}}]}