CVE-2024-2880
- EPSS 0.04%
- Published 11.07.2024 07:15:02
- Last modified 21.11.2024 09:10:44
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.5 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2 in which a user with `admin_group_member` custom role permission could ban ...
CVE-2024-2177
- EPSS 0.08%
- Published 09.07.2024 14:15:03
- Last modified 12.12.2024 20:17:46
A Cross Window Forgery vulnerability exists within GitLab CE/EE affecting all versions from 16.3 prior to 16.11.5, 17.0 prior to 17.0.3, and 17.1 prior to 17.1.1. This condition allows for an attacker to abuse the OAuth authentication flow via a craf...
CVE-2024-6323
- EPSS 0.05%
- Published 27.06.2024 00:15:13
- Last modified 21.11.2024 09:49:25
Improper authorization in global search in GitLab EE affecting all versions from 16.11 prior to 16.11.5 and 17.0 prior to 17.0.3 and 17.1 prior to 17.1.1 allows an attacker leak content of a private repository in a public project.
CVE-2024-4901
- EPSS 4.02%
- Published 27.06.2024 00:15:12
- Last modified 21.11.2024 09:43:49
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, where a stored XSS vulnerability could be imported from a project with mal...
CVE-2024-5430
- EPSS 0.02%
- Published 27.06.2024 00:15:12
- Last modified 21.11.2024 09:47:40
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.10 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows a project maintainer can delete the merge request approval p...
CVE-2024-5655
- EPSS 0.63%
- Published 27.06.2024 00:15:12
- Last modified 21.11.2024 09:48:06
An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows an attacker to trigger a pipeline as another user under certa...
CVE-2024-3115
- EPSS 0.1%
- Published 27.06.2024 00:15:11
- Last modified 21.11.2024 09:28:56
An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows an attacker to access issues and epics without having an SSO ses...
CVE-2024-3959
- EPSS 0.03%
- Published 27.06.2024 00:15:11
- Last modified 21.11.2024 09:30:46
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.7 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows private job artifacts can be accessed by any user.
CVE-2024-4011
- EPSS 0.06%
- Published 27.06.2024 00:15:11
- Last modified 21.11.2024 09:42:01
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows non-project member to promote key results to objectives.
CVE-2024-4557
- EPSS 0.18%
- Published 27.06.2024 00:15:11
- Last modified 21.11.2024 09:43:06
Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE affecting all versions starting from 1.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1 which allowed an attacker to cause r...