1018 vulnerabilidades · DevOps Orden: CVSS EPSS Año ID
CVE-2021-39936
GitLab DevOps
3.5
LOW
EPSS
0.3%
2021 1 PoC

Improper access control in GitLab CE/EE affecting all versions starting from 10.7 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker in possession of a deploy token to access a project's disabled wiki.

CVE-2022-0489
GitLab DevOps
3.5
LOW
EPSS
0.2%
2022 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions starting with 8.15 . It was possible to trigger a DOS by using the math feature with a specific formula in issue comments.

CVE-2022-4201
GitLab DevOps
3.5
LOW
EPSS
0.1%
2022 1 PoC

A blind SSRF in GitLab CE/EE affecting all from 11.3 prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 allows an attacker to connect to local addresses when configuring a malicious GitLab Runner.

CVE-2022-3288
GitLab DevOps
3.5
LOW
EPSS
0.1%
2022 1 PoC

A branch/tag name confusion in GitLab CE/EE affecting all versions prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an attacker to manipulate pages where the content of the default branch would be expected.

CVE-2025-14594
GitLab DevOps Web
3.5
LOW
EPSS
0.0%
2025 CWE-639 1 PoC

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.11 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to view certain pipeline values by querying the API.

CVE-2025-5069
GitLab DevOps
3.5
LOW
EPSS
0.0%
2025 CWE-708 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions from 17.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that could have allowed an authenticated user to gain unauthorized access to confidential issues by creating a project with an identical name to the victim's project.

CVE-2025-6945
GitLab DevOps
3.5
LOW
EPSS
0.0%
2025 CWE-77 1 PoC

GitLab has remediated an issue in GitLab EE affecting all versions from 17.8 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated attacker to leak sensitive information from confidential issues by injecting hidden prompts into merge request comments.

CVE-2021-39881
GitLab DevOps
3.5
LOW
EPSS
0.3%
2021 1 PoC

In all versions of GitLab CE/EE since version 7.7, the application may let a malicious user create an OAuth client application with arbitrary scope names which may allow the malicious user to trick unsuspecting users to authorize the malicious client application using the spoofed scope name and description.

CVE-2022-2227
GitLab DevOps Web
3.1
LOW
EPSS
0.2%
2022 1 PoC

Improper access control in the runner jobs API in GitLab CE/EE affecting all versions prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows a previous maintainer of a project with a specific runner to access job and project meta data under certain conditions

CVE-2022-0740
GitLab DevOps
3.1
LOW
EPSS
0.1%
2022 1 PoC

Incorrect authorization in the Asana integration's branch restriction feature in all versions of GitLab CE/EE starting from version 7.8.0 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 makes it possible to close Asana tasks from unrestricted branches.

CVE-2023-4777
Container Scanning Connector Jenkins Plugin DevOps
3.1
LOW
EPSS
0.0%
2023 CWE-732 1 PoC

An incorrect permission check in Qualys Container Scanning Connector Plugin 1.6.2.6 and earlier allows attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate credentials IDs of credentials stored in Jenkins and to connect to an attacker-specified URL using attacker-specified credentials IDs, capturing credentials stored in Jenkins. 

CVE-2023-3979
GitLab DevOps
3.1
LOW
EPSS
0.1%
2023 CWE-863 1 PoC

An issue has been discovered in GitLab affecting all versions starting from 10.6 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible that upstream members to collaborate with you on your branch get permission to write to the merge request’s source branch.

CVE-2023-2233
GitLab DevOps
3.1
LOW
EPSS
0.1%
2023 CWE-862 1 PoC

An improper authorization issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 16.2.8, all versions starting from 16.3 before 16.3.5 and all versions starting from 16.4 before 16.4.1. It allows a project reporter to leak the owner's Sentry instance projects.

CVE-2023-4658
GitLab DevOps
3.1
LOW
EPSS
0.1%
2023 CWE-863 1 PoC

An issue has been discovered in GitLab EE affecting all versions starting from 8.13 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to abuse the `Allowed to merge` permission as a guest user, when granted the permission through a group.

CVE-2020-13350
GitLab CE/EE DevOps Web
3.1
LOW
EPSS
0.2%
2020 1 PoC

CSRF in runner administration page in all versions of GitLab CE/EE allows an attacker who's able to target GitLab instance administrators to pause/resume runners. Affected versions are >=13.5.0, <13.5.2,>=13.4.0, <13.4.5,<13.3.9.

CVE-2020-13282
GitLab DevOps
3.1
LOW
EPSS
0.1%
2020 1 PoC

For GitLab before 13.0.12, 13.1.6, 13.2.3 after a group transfer occurs, members from a parent group keep their access level on the subgroup leading to improper access.

CVE-2024-10043
GitLab DevOps
3.1
LOW
EPSS
0.3%
2024 CWE-863 1 PoC

An issue has been discovered in GitLab EE affecting all versions starting from 14.3 before 17.4.6, all versions starting from 17.5 before 17.5.4 all versions starting from 17.6 before 17.6.2, that allows group users to view confidential incident title through the Wiki History Diff feature, potentially leading to information disclosure.

CVE-2025-7736
GitLab DevOps
3.1
LOW
EPSS
0.0%
2025 CWE-863 1 PoC

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.9 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated attacker to bypass access control restrictions and view GitLab Pages content intended only for project members by authenticating through OAuth providers.

CVE-2024-9633
GitLab DevOps
3.1
LOW
EPSS
0.0%
2024 CWE-708 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.3 before 17.4.2, all versions starting from 17.5 before 17.5.4, all versions starting from 17.6 before 17.6.2. This issue allows an attacker to create a group with a name matching an existing unique Pages domain, potentially leading to domain confusion attacks.

CVE-2024-7598
kube-apiserver DevOps Web
3.1
LOW
EPSS
0.0%
2024 CWE-362 2 PoCs

A security issue was discovered in Kubernetes where a malicious or compromised pod could bypass network restrictions enforced by network policies during namespace deletion. The order in which objects are deleted during namespace termination is not defined, and it is possible for network policies to be deleted before the pods that they protect. This can lead to a brief period in which the pods are running, but network policies that should apply to connections to and from the pods are not enforced.