Known vulnerabilities in GitLab Enterprise Edition 11.3.14 - page 9

Version: 11.3.14
Software CPE: cpe:2.3:a:gitlab:gitlab-ee:*:*:*:*:*:*:*:*
Total vulnerabilities: 309
Public exploits: 4
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting GitLab Enterprise Edition version 11.3.14 GitLab Enterprise Edition 11.3.14 is affected by 309 vulnerabilities: 10 high, 161 medium, 138 low Critical High Medium Low

Vulnerabilities (309)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU65894 - Data Handling
CVE-2022-2534
CWE-19 Low
No
No
15.0.5, 15.1.4, 15.2.1 29.07.2022 SB2022072918
#VU65893 - Improper Access Control
CVE-2022-2459
CWE-284 Low
No
No
15.0.5, 15.1.4, 15.2.1 29.07.2022 SB2022072918
#VU65885 - Improper Authentication
CVE-2022-2303
CWE-287 Low
No
No
15.0.5, 15.1.4, 15.2.1 29.07.2022 SB2022072918
#VU64854 - Improper Access Control
CVE-2022-2227
CWE-284 Low
No
No
14.10.5, 15.0.4, 15.1.1 01.07.2022 SB2022070111
#VU64853 - Improper input validation
CVE-2022-1999
CWE-20 Low
No
No
14.10.5, 15.0.4, 15.1.1 01.07.2022 SB2022070111
#VU64852 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2022-2250
CWE-601 Medium
No
No
14.10.5, 15.0.4, 15.1.1 01.07.2022 SB2022070111
#VU64850 - Improper input validation
CVE-2022-1954
CWE-20 Low
No
No
14.10.5, 15.0.4, 15.1.1 01.07.2022 SB2022070111
#VU64844 - Improper Authorization
CVE-2022-1983
CWE-285 Low
No
No
14.10.5, 15.0.4, 15.1.1 01.07.2022 SB2022070111
#VU63936 - Exposure of sensitive information to an unauthorized actor
CVE-2022-1821
CWE-200 Low
No
No
14.9.5, 14.10.4, 15.0.1 02.06.2022 SB2022060202
#VU63933 - Improper Authorization
CVE-2022-1944
CWE-285 Medium
No
No
14.9.5, 14.10.4, 15.0.1 02.06.2022 SB2022060202
#VU62745 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-1416
CWE-79 Low
No
No
14.8.6 03.05.2022 SB2022050309
#VU62744 - Improper Authorization
CVE-2022-1124
CWE-285 Low
No
No
14.8.6, 14.9.4, 14.10.1 03.05.2022 SB2022050309
#VU62743 - Improper Access Control
CVE-2022-1417
CWE-284 Low
No
No
14.8.6, 14.9.4, 14.10.1 03.05.2022 SB2022050309
#VU62742 - Improper input validation
CVE-2022-1428
CWE-20 Low
No
No
14.8.6, 14.9.4, 14.10.1 03.05.2022 SB2022050309
#VU62740 - Exposure of sensitive information to an unauthorized actor
CVE-2022-1352
CWE-200 Medium
No
No
14.8.6, 14.9.4, 14.10.1 03.05.2022 SB2022050309
#VU62738 - Exposure of sensitive information to an unauthorized actor
CVE-2022-1413
CWE-200 Low
No
No
14.8.6 03.05.2022 SB2022050309
#VU62736 - Improper Authorization
CVE-2022-1460
CWE-285 Low
No
No
14.8.6, 14.9.4, 14.10.1 03.05.2022 SB2022050309
#VU62733 - Improper input validation
CVE-2022-1406
CWE-20 Medium
No
No
14.8.6, 14.9.4, 14.10.1 03.05.2022 SB2022050309
#VU62731 - Improper Access Control
CVE-2022-1423
CWE-284 Medium
No
No
14.8.6 03.05.2022 SB2022050309
#VU61778 - Improper input validation
CVE-2022-1185
CWE-20 Medium
No
No
14.7.7, 14.8.5, 14.9.2 01.04.2022 SB2022040106


Showing elements 161 - 180 out of 309