Known vulnerabilities in GitLab Enterprise Edition - page 19

Software CPE: cpe:2.3:a:gitlab:gitlab-ee:*:*:*:*:*:*:*:*
Total vulnerabilities: 1052
Public exploits: 16
Known exploited (KEV): 4
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting GitLab Enterprise Edition GitLab Enterprise Edition is affected by 1052 known vulnerabilities: 1 critical, 31 high, 481 medium, 539 low Critical High Medium Low

Vulnerabilities (1052)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU98344 - Exposure of sensitive information to an unauthorized actor
CVE-2024-9596
CWE-200 Low
No
No
17.2.9, 17.3.5, 17.4.2 10.10.2024 SB2024101017
#VU98342 - Exposure of sensitive information to an unauthorized actor
CVE-2024-5005
CWE-200 Low
No
No
17.2.9, 17.3.5, 17.4.2 10.10.2024 SB2024101017
#VU98339 - Security Features
CVE-2024-9623
CWE-254 Low
No
No
17.2.9, 17.3.5, 17.4.2 10.10.2024 SB2024101017
#VU98338 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-6530
CWE-79 Low
No
No
17.2.9, 17.3.5, 17.4.2 10.10.2024 SB2024101017
#VU98337 - Improper input validation
CVE-2024-9631
CWE-20 Medium
No
No
17.2.9, 17.3.5, 17.4.2 10.10.2024 SB2024101017
#VU97717 - Exposure of sensitive information to an unauthorized actor
CVE-2024-8974
CWE-200 Low
No
No
17.2.8, 17.3.4, 17.4.1 26.09.2024 SB2024092609
#VU97716 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2024-4099
CWE-74 Low
No
No
17.2.8, 17.3.4, 17.4.1 26.09.2024 SB2024092609
#VU97715 - Exposure of sensitive information to an unauthorized actor
CVE-2024-4278
CWE-200 Low
No
No
17.2.8, 17.3.4, 17.4.1 26.09.2024 SB2024092609
#VU97454 - Improper Verification of Cryptographic Signature
CVE-2024-45409
CWE-347 High
Available
No
16.11.10, 17.0.8, 17.1.8, 17.2.7, 17.3.3 18.09.2024 SB2024091805
SB2024091806
SB2024091807
and 1 more
#VU97221 - Exposure of sensitive information to an unauthorized actor
CVE-2024-6685
CWE-200 Low
No
No
17.1.7, 17.2.5, 17.3.2 12.09.2024 SB2024091269
#VU97220 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2024-6446
CWE-451 Low
No
No
17.1.7, 17.2.5, 17.3.2 12.09.2024 SB2024091269
#VU97219 - Cleartext Storage of Sensitive Information
CVE-2024-4472
CWE-312 Low
No
No
17.1.7, 17.2.5, 17.3.2 12.09.2024 SB2024091269
#VU97214 - Exposure of sensitive information to an unauthorized actor
CVE-2024-6389
CWE-200 Low
No
No
17.1.7, 17.2.5, 17.3.2 12.09.2024 SB2024091269
#VU97213 - Exposure of sensitive information to an unauthorized actor
CVE-2024-5435
CWE-200 Low
No
No
17.1.7, 17.2.5, 17.3.2 12.09.2024 SB2024091269
#VU97212 - Exposure of sensitive information to an unauthorized actor
CVE-2024-2743
CWE-200 Medium
No
No
17.1.7, 17.2.5, 17.3.2 12.09.2024 SB2024091269
#VU97211 - Permissions, Privileges, and Access Controls
CVE-2024-8631
CWE-264 Low
No
No
17.1.7, 17.2.5, 17.3.2 12.09.2024 SB2024091269
#VU97210 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2024-4612
CWE-601 Medium
No
No
17.1.7, 17.2.5, 17.3.2 12.09.2024 SB2024091269
#VU97207 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2024-4283
CWE-601 Medium
No
No
17.1.7, 17.2.5, 17.3.2 12.09.2024 SB2024091269
#VU97206 - Exposure of sensitive information to an unauthorized actor
CVE-2024-4660
CWE-200 Medium
No
No
17.1.7, 17.2.5, 17.3.2 12.09.2024 SB2024091269
#VU97205 - Security Features
CVE-2024-8311
CWE-254 Medium
No
No
17.2.5, 17.3.2 12.09.2024 SB2024091269


Showing elements 361 - 380 out of 1052