CVE-2022-3740
- EPSS 0.06%
- Veröffentlicht 26.01.2023 21:15:58
- Zuletzt bearbeitet 02.04.2025 15:15:45
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. A group owner may be able to bypass External Authorization check, if it is enabled, to access git ...
CVE-2022-3820
- EPSS 0.08%
- Veröffentlicht 26.01.2023 21:15:58
- Zuletzt bearbeitet 02.04.2025 15:15:46
An issue has been discovered in GitLab affecting all versions starting from 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. GitLab was not performing correct authentication with some Package Registries when IP address restrictions were configured, al...
CVE-2022-3572
- EPSS 7.55%
- Veröffentlicht 26.01.2023 21:15:54
- Zuletzt bearbeitet 02.04.2025 15:15:45
A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions from 13.5 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. It was possible to exploit a vulnerability in setting the Jira Connect integration whic...
CVE-2022-3478
- EPSS 0.07%
- Veröffentlicht 26.01.2023 21:15:51
- Zuletzt bearbeitet 02.04.2025 15:15:45
An issue has been discovered in GitLab affecting all versions starting from 12.8 before 15.4.6, all versions starting from 15.5 before 15.5.5, all versions starting from 15.6 before 15.6.1. It was possible to trigger a DoS attack by uploading a malic...
CVE-2022-3482
- EPSS 0.31%
- Veröffentlicht 26.01.2023 21:15:51
- Zuletzt bearbeitet 21.11.2024 07:19:37
An improper access control issue in GitLab CE/EE affecting all versions from 11.3 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allowed an unauthorized user to see release names even when releases we set to be restricted to project ...
CVE-2022-2907
- EPSS 1.13%
- Veröffentlicht 17.01.2023 21:15:12
- Zuletzt bearbeitet 04.04.2025 18:15:41
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. It was possible to read repository content by an unaut...
CVE-2022-4131
- EPSS 0.1%
- Veröffentlicht 12.01.2023 04:15:10
- Zuletzt bearbeitet 08.04.2025 17:15:33
An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.8 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. An attacker may cause Denial of Service on a GitLab in...
CVE-2022-4167
- EPSS 0.14%
- Veröffentlicht 12.01.2023 04:15:10
- Zuletzt bearbeitet 08.04.2025 17:15:33
Incorrect Authorization check affecting all versions of GitLab EE from 13.11 prior to 15.5.7, 15.6 prior to 15.6.4, and 15.7 prior to 15.7.2 allows group access tokens to continue working even after the group owner loses the ability to revoke them.
CVE-2022-4342
- EPSS 1.02%
- Veröffentlicht 12.01.2023 04:15:10
- Zuletzt bearbeitet 21.11.2024 07:35:05
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.1 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A malicious Maintainer can leak masked webhook secrets...
CVE-2022-4365
- EPSS 0.58%
- Veröffentlicht 12.01.2023 04:15:10
- Zuletzt bearbeitet 08.04.2025 14:15:29
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A malicious Maintainer can leak the sentry token by ch...