Where
-Infinity
0
Severity
10
EPSS
4.48%
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could be delivered to an unverified email address.

1 / 3
Source: NVD
First published (updated )
Severity
9.9
EPSS
0.02%
AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

An issue has been discovered in GitLab CE/EE affecting all versions from 17.11 before 17.11.4 and 18.0 before 18.0.2. A missing authorization check may have allowed compliance frameworks to be applied to projects outside the compliance framework's group.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 17.11.4, 18.0.2 or above.
First published (updated )
Severity
9.9
Integer Overflow
AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary code on the GitLab server due to an integer overflow issue when compiling a specially crafted regular expression in a CI/CD configuration.

First published (updated )
Severity
9.9
Double Free
AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary code on the GitLab server due to a double free issue when parsing a specially crafted regular expression in a CI/CD configuration.

First published (updated )
Severity
9.6
EPSS
0.06%
XSS
AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

An issue has been discovered in GitLab CE/EE affecting all versions from 14.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that could allow an attacker to inject malicious content that may lead to account takeover.

1 / 2
Source: NVD

Remedy

Upgrade to version 18.2.7, 18.3.3 or 18.4.1 or above.
First published (updated )
Severity
9.4
Code Injection
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive.

First published (updated )
Severity
9
XSS
AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to escalate privileges due to improper sanitization of HTML content rendered in a CI job modal.

First published (updated )
Severity
8.8
CSRF
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.6 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2 in which cross-site request forgery may have been possible on GitLab instances configured to use JWT as an OmniAuth provider.

1 / 2
Source: NVD
First published (updated )
Severity
8.8
AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

An improper access control vulnerability in GitLab CE/EE affecting all versions from 17.4 prior to 17.8.6, 17.9 prior to 17.9.3, and 17.10 prior to 17.10.1 allows a user who was an instance admin before but has since been downgraded to a regular user to continue to maintain elevated privileges to groups and projects.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 17.8.6, 17.9.3, 17.10.1 or above.
First published (updated )
Severity
8.8
AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N

An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated users to gain elevated project privileges by requesting access to projects where role modifications during the approval process resulted in unintended permission grants.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 17.11.5, 18.0.3, 18.1.1 or above.
First published (updated )
Severity
8.8
SSRF
AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

An issue has been discovered in GitLab CE/EE affecting all versions from 16.11 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed authenticated users to make unintended internal requests through proxy environments by injecting crafted sequences.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 18.1.6, 18.2.6, 18.3.2 or above.
First published (updated )
Severity
8.7
AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 before 17.4.6, starting from 17.5 before 17.5.4, and starting from 17.6 before 17.6.2, injection of Network Error Logging (NEL) headers in kubernetes proxy response could lead to session data exfiltration. This is a high severity issue (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, 8.7). It is now mitigated in the latest release and is assigned CVE-2024-11274.

1 / 2
Source: GitLab

Remedy

Upgrade to versions 17.4.6, 17.5.4, 17.6.2 or above.
First published (updated )
Severity
8.7
XSS
AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.6.4, 17.7 before 17.7.3, and 17.8 before 17.8.1. Improper rendering of certain file types lead to cross-site scripting.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 17.6.4, 17.7.3, 17.8.1 or above.
First published (updated )
Severity
8.7
XSS
AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

An XSS vulnerability exists in GitLab CE/EE affecting all versions from 13.3 prior to 17.6.5, 17.7 prior to 17.7.4 and 17.8 prior to 17.8.2 that allows an attacker to execute unauthorized actions via a change page.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 17.6.5, 17.7.4, 17.8.2 or above.
First published (updated )
Severity
8.7
XSS
AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1. A proxy feature could potentially allow unintended content rendering leading to XSS under specific circumstances.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 17.7.6, 17.8.4, 17.9.1 or above.
First published (updated )
Severity
8.7
XSS
AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. Improper rendering of certain file types leads to cross-site scripting.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 17.8.6, 17.9.3, 17.10.1 or above.
First published (updated )
Severity
8.7
AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

An issue has been discovered in GitLab CE/EE affecting all versions starting with 18.0 before 18.0.2. Under certain conditions html injection in new search page could lead to account takeover.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 18.0.2 or above.
First published (updated )
Severity
8.7
XSS
AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. Improper output encoding in the snipper viewer functionality lead to Cross-Site scripting attacks.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 17.10.8, 17.11.4, 18.0.2 or above.
First published (updated )
Severity
8.7
EPSS
0.06%
XSS
AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

An issue has been discovered in GitLab CE/EE affecting all versions from 17.11 before 17.11.6, 18.0 before 18.0.4, and 18.1 before 18.1.2 that, under certain conditions, could have allowed a successful attacker to execute actions on behalf of users by injecting malicious content.

1 / 2
Source: MITRE
First published (updated )
Severity
8.7
XSS
AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that, under specific circumstances, could have potentially allowed a successful attacker to trigger unintended content rendering leading to XSS.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 18.0.5, 18.1.3, 18.2.1 or above.
First published (updated )
Severity
8.7
EPSS
0.06%
XSS
AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

An issue has been discovered in GitLab CE/EE affecting all versions from 14.2 before 18.0.6, 18.1 before 18.1.4 and 18.2 before 18.2.2 that, under certain conditions, could have allowed a successful attacker to execute actions on behalf of users by injecting malicious content.

1 / 2
Source: NVD

Remedy

Upgrade to versions 18.0.6, 18.1.4, 18.2.2 or above.
First published (updated )
Severity
8.7
XSS
AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

An issue has been discovered in GitLab CE/EE affecting all versions from 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed authenticated users to achieve account takeover by injecting malicious HTML into work item names.

1 / 2
Source: NVD

Remedy

Upgrade to versions 18.1.4, 18.2.2 or above.
First published (updated )
Severity
8.7
EPSS
0.06%
XSS
AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

An issue has been discovered in GitLab CE/EE affecting all versions from 18.2 before 18.2.2 that, under certain conditions, could have allowed authenticated users to achieve stored cross-site scripting by injecting malicious HTML content in scoped label descriptions.

1 / 2
Source: NVD

Remedy

Upgrade to version 18.2.2 or above.
First published (updated )
Severity
8.5
AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with Developer role to access unauthorized information due to insufficient access controls on internal request handling.

First published (updated )
Severity
8.4
AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to modify CI/CD configuration belonging to another user due to improper validation of user-supplied attributes when processing pipeline schedule inputs.

First published (updated )
Severity
8.2
XSS
AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:L

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an authenticated user could have induced a targeted user to perform unintended state-changing HTTP requests due to improper sanitization of user-controlled data in the Markdown JSON table renderer.

First published (updated )
Severity
8.1
CSRF
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1.0 before 16.11.5, all versions starting from 17.0 before 17.0.3, all versions starting from 17.1.0 before 17.1.1 which allowed for a CSRF attack on GitLab's GraphQL API leading to the execution of arbitrary GraphQL mutations.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 16.11.5, 17.0.3, 17.1.1 or above.
First published (updated )
Severity
8
EPSS
0.05%
XSS, Input Validation
AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.1.0 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that under certain conditions could have allowed an unauthenticated user to access tokens in the Storybook development environment due to improper input validation.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 18.9.6, 18.10.4, 18.11.1 or above.
First published (updated )
Severity
7.7
XSS
AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N

An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that could have allowed an authenticated user to perform cross-site scripting attacks when the instance is served through certain content delivery networks.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 18.0.5, 18.1.3, 18.2.1 or above.
First published (updated )
Severity
7.7
EPSS
0.01%
AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

An issue has been discovered in GitLab CE/EE affecting all versions from 14.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1, that could have allowed Guest users to access sensitive information stored in virtual registry configurations.

1 / 2
Source: NVD

Remedy

Upgrade to version 18.2.7, 18.3.3 or 18.4.1 or above.
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203