Gitlab
1,451 known vulnerabilities
Top Products
In all versions of GitLab CE/EE since version 10.6, a project export leaks the external webhook token value which may al
Improper access control in GitLab CE/EE version 10.5 and above allowed subgroup members with inherited access to a proje
In all versions of GitLab CE/EE since version 8.0, an attacker can set the pipeline schedules to be active in a project
A stored Cross-Site Scripting vulnerability in the DataDog integration in all versions of GitLab CE/EE starting from 13.
A regular expression denial of service issue in GitLab versions 8.13 to 14.2.5, 14.3.0 to 14.3.3 and 14.4.0 could cause
In all versions of GitLab CE/EE since version 13.0, a privileged user, through an API call, can change the visibility le
Incorrect Authorization in GitLab CE/EE 13.4 or above allows a user with guest membership in a project to modify the sev
An issue has been discovered in GitLab affecting all versions starting from 13.0 before 14.0.9, all versions starting fr
A Denial Of Service vulnerability in the apollo_upload_server Ruby gem in GitLab CE/EE all versions starting from 11.9 b
In all versions of GitLab CE/EE since version 8.0, access tokens created as part of admin's impersonation of a user are
In all versions of GitLab EE since version 14.1, due to an insecure direct object reference vulnerability, an endpoint m
Permissions rules were not applied while issues were moved between projects of the same group in GitLab versions startin
In all versions of GitLab CE/EE since version 7.7, the application may let a malicious user create an OAuth client appli
In all versions of GitLab CE/EE since version 11.11, an instance that has the setting to disable Repo by URL import enab
An issue has been discovered in GitLab affecting all versions starting from 13.8 before 14.0.9, all versions starting fr
Missing access control in all GitLab versions starting from 13.12 before 14.0.9, all versions starting from 14.1 before
A stored Cross-Site Scripting vulnerability in the Jira integration in all GitLab versions starting from 13.9 before 14.
The project import/export feature in GitLab 8.9 and greater could be used to obtain otherwise private email addresses
An issue has been discovered in GitLab affecting all versions starting from 14.0 before 14.0.9, all versions starting fr
In all versions of GitLab CE/EE since version 8.0, a DNS rebinding vulnerability exists in Fogbugz importer which may be
A potential DOS vulnerability was discovered in GitLab starting with version 9.1 that allowed parsing files without auth
In all versions of GitLab EE starting from 13.10 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all v
In all versions of GitLab EE since version 8.13, an endpoint discloses names of private groups that have access to a pro
In all versions of GitLab CE/EE, provided a user ID, anonymous users can use a few endpoints to retrieve information abo
A stored Reflected Cross-Site Scripting vulnerability in the Jira integration in GitLab version 13.0 up to 14.3.1 allowe
In all versions of GitLab CE/EE since version 13.6, it is possible to see pending invitations of any public group or pub
In all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired p
In all versions of GitLab CE/EE since version 8.9, project exports may expose trigger tokens configured on that project.
In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vulnerability in Gitea Importer may be exploited by
A business logic error in the project deletion process in GitLab 13.6 and later allows persistent access via project acc
A stored Cross-Site Scripting vulnerability in the GitLab Flavored Markdown in GitLab CE/EE version 8.4 and above allowe
Information disclosure from SendEntry in GitLab starting with 10.8 allowed exposure of full URL of artifacts stored in o
In all versions of GitLab CE/EE, an attacker with physical access to a user’s machine may brute force the user’s passwor
In all versions of GitLab CE/EE since version 8.0, when an admin uses the impersonate feature twice and stops impersonat
A Stored XSS in merge request creation page in all versions of Gitlab EE starting from 13.7 before 14.1.7, all versions
Improper authorization checks in all versions of GitLab EE starting from 13.11 before 14.1.7, all versions starting from
Missing authentication in all versions of GitLab CE/EE since version 7.11.0 allows an attacker with access to a victim's
A vulnerability was discovered in GitLab starting with version 12.2 that allows an attacker to cause uncontrolled resour
In all versions of GitLab CE/EE since version 11.0, the requirement to enforce 2FA is not honored when using git command
In all versions of GitLab CE/EE, there exists a content spoofing vulnerability which may be leveraged by attackers to tr
In all versions of GitLab CE/EE since version 13.0, an instance that has the setting to disable Bitbucket Server import
In all versions of GitLab CE/EE since version 8.12, an authenticated low-privileged malicious user may create a project
A potential DOS vulnerability was discovered in GitLab EE starting with version 12.6 due to lack of pagination in depend
An unauthorized user was able to insert metadata when creating new issue on GitLab CE/EE 14.0 and later.
Improper authorization in GitLab CE/EE affecting all versions since 12.6 allowed guest users to create issues for Sentry
Improper authorization in GitLab CE/EE affecting all versions since 13.3 allowed users to view and delete impersonation
Improper authorization in GitLab CE/EE affecting all versions since 13.0 allows guests in private projects to view CI/CD
Improper validation of commit author in GitLab CE/EE affecting all versions allowed an attacker to make several pages in
Improper authorization in the vulnerability report feature in GitLab EE affecting all versions since 13.1 allowed a repo
Under specialized conditions, GitLab CE/EE versions starting 7.10 may allow existing GitLab users to use an invite URL m
Frequently Asked Questions
How many CVEs affect Gitlab?
Gitlab has 1,451 CVE records in our database, including 57 critical and 304 high severity vulnerabilities. 4 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Gitlab vulnerabilities?
Gitlab has 57 critical severity (CVSS 9.0+) and 304 high severity (CVSS 7.0-8.9) vulnerabilities. 4 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Gitlab vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Gitlab products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Gitlab Vulnerabilities
CyberStrike scans your infrastructure for Gitlab vulnerabilities and provides real-time remediation guidance.
Get Started