Skip to content
VulniPulse

GitLab Security Advisories & CVEs

136 advisories tracked · GitLab (cve@gitlab.com CNA) via NVD · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor GitLab CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your GitLab device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in GitLab's recent advisories.

Official source

GitLab (cve@gitlab.com CNA) via NVD

GitLab is its own CVE Numbering Authority and publishes prolifically — it ships coordinated security releases roughly every month, so VulniPulse ingests GitLab's CVEs from the NVD CNA feed (cve@gitlab.com), a high-volume, authoritative source where each record names the affected CE/EE version range. Covers GitLab Community Edition and Enterprise Edition (self-managed), plus GitLab Runner and Pages — self-hosted DevOps platforms that are a repeated RCE / auth-bypass target, so a patch-now audience.

Latest GitLab advisories

Low3.7GitLab

Low [CVE-2023-3509] Incorrect Authorization in GitLab

An issue has been discovered in GitLab affecting all versions before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. It was possible for group members with sub-maintainer role to change the title of privately accessible deploy keys associated with projects in the group.

CVE-2023-3509
Unclassified
Feb 21, 2024
Medium5.3GitLab

Medium [CVE-2023-5612] Missing Authorization in GitLab

An issue has been discovered in GitLab affecting all versions before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. It was possible to read the user email address via tags feed although the visibility in the user profile has been disabled.

CVE-2023-5612
Unclassified
Jan 26, 2024
Medium6.5GitLab

Medium [CVE-2023-6159] Inefficient Regular Expression Complexity in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions from 12.7 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 It was possible for an attacker to trigger a Regular Expression Denial of Service via a `Cargo.toml` containing maliciously crafted input.

CVE-2023-6159
Unclassified
Jan 26, 2024
Critical10.0GitLab Exploited CISA KEV

Critical [CVE-2023-7028] Weak Password Recovery Mechanism for Forgotten Password in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could be delivered to an unverified email address.

CVE-2023-7028
Unclassified
Jan 12, 2024
Medium4.3GitLab

Medium [CVE-2023-3904] Improper Validation of Specified Type of Input in GitLab

An issue has been discovered in GitLab EE affecting all versions starting before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. It was possible to overflow the time spent on an issue that altered the details shown in the issue boards.

CVE-2023-3904
Unclassified
Dec 15, 2023
Medium4.8GitLab

Medium [CVE-2023-5226] Improper Control of Generation of Code ('Code Injection') in GitLab

An issue has been discovered in GitLab affecting all versions before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. Under certain circumstances, a malicious actor bypass prohibited branch checks using a specially crafted branch name to manipulate repository content in the UI.

CVE-2023-5226
Unclassified
Dec 1, 2023
Low3.1GitLab

Low [CVE-2023-3443] Incorrect Authorization in GitLab

An issue has been discovered in GitLab affecting all versions starting from 12.1 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for a Guest user to add an emoji on confidential work items.

CVE-2023-3443
Unclassified
Dec 1, 2023
High8.2GitLab

High [CVE-2023-5207] Execution with Unnecessary Privileges in GitLab

A vulnerability was discovered in GitLab CE and EE affecting all versions starting 16.0 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. An authenticated attacker could perform arbitrary pipeline execution under the context of another user.

CVE-2023-5207
Unclassified
Sep 30, 2023
Medium4.3GitLab

Medium [CVE-2023-3920] Incorrect Authorization in GitLab

An issue has been discovered in GitLab affecting all versions starting from 11.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible that a maintainer to create a fork relationship between existing projects contrary to the documentation.

CVE-2023-3920
Unclassified
Sep 29, 2023
Medium5.4GitLab

Medium [CVE-2023-3914] Incorrect User Management in GitLab

A business logic error in GitLab EE affecting all versions prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows access to internal projects. A service account is not deleted when a namespace is deleted, allowing access to internal projects.

CVE-2023-3914
Unclassified
Sep 29, 2023
Low3.5GitLab

Low [CVE-2023-3906] Improper Validation of Specified Type of Input in GitLab

An input validation issue in the asset proxy in GitLab EE, affecting all versions from 12.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1, allowed an authenticated attacker to craft image urls which bypass the asset proxy.

CVE-2023-3906
Unclassified
Sep 29, 2023
Low3.1GitLab

Low [CVE-2023-3979] Incorrect Authorization in GitLab

An issue has been discovered in GitLab affecting all versions starting from 10.6 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible that upstream members to collaborate with you on your branch get permission to write to the merge request’s source branch.

CVE-2023-3979
Unclassified
Sep 29, 2023
Medium4.3GitLab

Medium [CVE-2023-4018] Direct Request ('Forced Browsing') in GitLab

An issue has been discovered in GitLab affecting all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. Due to improper permission validation it was possible to create model experiments in public projects.

CVE-2023-4018
Unclassified
Sep 1, 2023
Medium4.8GitLab

Medium [CVE-2023-3401] Improper Control of Generation of Code ('Code Injection') in GitLab

An issue has been discovered in GitLab affecting all versions before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. The main branch of a repository with a specially designed name allows an attacker to create repositories with malicious code.

CVE-2023-3401
Unclassified
Aug 2, 2023
Medium5.4GitLab

Medium [CVE-2023-2164] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab

An issue has been discovered in GitLab affecting all versions starting from 15.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for an attacker to trigger a stored XSS vulnerability via user interaction with a crafted URL in the WebIDE beta.

CVE-2023-2164
Unclassified
Aug 1, 2023
Critical10.0GitLab Exploited CISA KEV

Critical [CVE-2021-22205] issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution.

CVE-2021-22205
Unclassified
Apr 23, 2021

← All vendors