Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Gitlab

1,451 known vulnerabilities

57
CRITICAL
303
HIGH
896
MEDIUM
181
LOW

Top Products

gitlab 1424 dynamic application security testing analyzer 4 runner 3 gitlab-vscode-extension 2 gitlab-shell 2 language server 1 dast api scanner 1 gitlab runner 1 gitaly 1 omnibus 1
1,438 CVEs · Page 24/29
9.8
CVE-2020-8113

GitLab 10.7 and later through 12.7.2 has Incorrect Access Control.

7.5
CVE-2020-8795

In GitLab Enterprise Edition (EE) 12.5.0 through 12.7.5, sharing a group with a group could grant project access to unau

4.3
CVE-2019-12825

Unauthorized Access to the Container Registry of other groups was discovered in GitLab Enterprise 12.0.0-pre. In other w

4.3
CVE-2019-15594

GitLab 11.8 and later contains a security vulnerability that allows a user to obtain details of restricted pipelines via

4.3
CVE-2019-15592

GitLab 12.2.2 and below contains a security vulnerability that allows a guest user in a private project to see the merge

7.5
CVE-2020-6833

An issue was discovered in GitLab EE 11.3 and later. A GitLab Workhorse bypass could lead to package and file disclosure

7.5
CVE-2020-7978

GitLab EE 12.6 and later through 12.7.2 allows Denial of Service.

5.3
CVE-2020-7977

GitLab EE 8.8 and later through 12.7.2 has Insecure Permissions.

5.3
CVE-2020-7976

GitLab EE 12.4 and later through 12.7.2 has Incorrect Access Control.

5.3
CVE-2020-7974

GitLab EE 10.1 through 12.7.2 allows Information Disclosure.

6.1
CVE-2020-7973

GitLab through 12.7.2 allows XSS.

7.5
CVE-2020-7972

GitLab EE 12.2 has Insecure Permissions (issue 2 of 2).

6.1
CVE-2020-7971

GitLab EE 11.0 and later through 12.7.2 allows XSS.

7.5
CVE-2020-7969

GitLab EE 8.0 and later through 12.7.2 allows Information Disclosure.

7.5
CVE-2020-7968

GitLab EE 8.0 through 12.7.2 has Incorrect Access Control.

4.3
CVE-2020-7967

GitLab EE 8.0 through 12.7.2 has Insecure Permissions (issue 1 of 2).

7.5
CVE-2020-7966

GitLab EE 11.11 and later through 12.7.2 allows Directory Traversal.

9.8
CVE-2020-8114

GitLab EE 8.9 and later through 12.7.2 has Insecure Permission

5.3
CVE-2020-7979

GitLab EE 8.9 and later through 12.7.2 has Insecure Permission

8.8
CVE-2013-4583

The parse_cmd function in lib/gitlab_shell.rb in GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, and Enterprise

6.5
CVE-2013-4582

The (1) create_branch, (2) create_tag, (3) import_project, and (4) fork_project functions in lib/gitlab_projects.rb in G

6.5
CVE-2019-5474

An authorization issue was discovered in GitLab EE < 12.1.2, < 12.0.4, and < 11.11.6 allowing the merge request approval

7.5
CVE-2019-5472

An authorization issue was discovered in Gitlab versions < 12.1.2, < 12.0.4, and < 11.11.6 that prevented owners and mai

7.5
CVE-2019-5470

An information disclosure issue was discovered GitLab versions < 12.1.2, < 12.0.4, and < 11.11.6 in the security dashboa

8.8
CVE-2019-5468

An privilege escalation issue was discovered in Gitlab versions < 12.1.2, < 12.0.4, and < 11.11.6 when Mattermost slash

4.3
CVE-2019-5466

An IDOR was discovered in GitLab CE/EE 11.5 and later that allowed new merge requests endpoint to disclose label names.

4.3
CVE-2019-5465

An information disclosure issue was discovered in GitLab CE/EE 8.14 and later, by using the move issue feature which cou

9.8
CVE-2019-5464

A flawed DNS rebinding protection issue was discovered in GitLab CE/EE 10.2 and later in the `url_blocker.rb` which coul

8.8
CVE-2019-5462

A privilege escalation issue was discovered in GitLab CE/EE 9.0 and later when trigger tokens are not rotated once owner

7.5
CVE-2019-15590

An access control issue exists in < 12.3.5, < 12.2.8, and < 12.1.14 for GitLab Community Edition (CE) and Enterprise Edi

6.1
CVE-2019-15586

A XSS exists in Gitlab CE/EE < 12.1.10 in the Mermaid plugin.

9.8
CVE-2019-15585

Improper authentication exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edi

7.5
CVE-2019-15583

An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise E

5.3
CVE-2019-15582

An IDOR was discovered in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE

5.3
CVE-2019-15581

An IDOR exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) that a

5.3
CVE-2019-15579

An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise E

5.3
CVE-2019-15578

An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise E

4.3
CVE-2019-20144

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 10.8 through 12.6.1. It has Incorre

5.3
CVE-2019-20143

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 12.6. It has Incorrect Access Contr

4.3
CVE-2019-20142

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 12.3 through 12.6.1. It allows Deni

5.3
CVE-2020-6832

An issue was discovered in GitLab Enterprise Edition (EE) 8.9.0 through 12.6.1. Using the project import feature, it was

4.3
CVE-2020-5197

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 5.1 through 12.6.1. It has Incorrec

5.3
CVE-2019-20148

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 8.13 through 12.6.1. It has Incorre

5.3
CVE-2019-20147

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 9.1 through 12.6.1. It has Incorrec

5.3
CVE-2019-20146

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 11.0 through 12.6. It allows Uncont

4.3
CVE-2019-20145

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 11.4 through 12.6.1. It has Incorre

7.5
CVE-2019-19629

In GitLab EE 10.5 through 12.5.3, 12.4.5, and 12.3.8, when transferring a public project to a private group, private cod

9.8
CVE-2019-19628

In GitLab EE 11.3 through 12.5.3, 12.4.5, and 12.3.8, insufficient parameter sanitization for the Maven package registry

7.5
CVE-2019-19314

GitLab EE 8.4 through 12.5, 12.4.3, and 12.3.6 stored several tokens in plaintext.

7.5
CVE-2019-19313

GitLab EE 12.3 through 12.5, 12.4.3, and 12.3.6 allows Denial of Service. Certain characters were making it impossible t

Frequently Asked Questions

How many CVEs affect Gitlab?

Gitlab has 1,451 CVE records in our database, including 57 critical and 304 high severity vulnerabilities. 4 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Gitlab vulnerabilities?

Gitlab has 57 critical severity (CVSS 9.0+) and 304 high severity (CVSS 7.0-8.9) vulnerabilities. 4 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Gitlab vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Gitlab products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Gitlab Vulnerabilities

CyberStrike scans your infrastructure for Gitlab vulnerabilities and provides real-time remediation guidance.

Get Started