Known vulnerabilities in GitLab Enterprise Edition - page 21

Software CPE: cpe:2.3:a:gitlab:gitlab-ee:*:*:*:*:*:*:*:*
Total vulnerabilities: 1052
Public exploits: 16
Known exploited (KEV): 4
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting GitLab Enterprise Edition GitLab Enterprise Edition is affected by 1052 known vulnerabilities: 1 critical, 31 high, 481 medium, 539 low Critical High Medium Low

Vulnerabilities (1052)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU95547 - Exposure of sensitive information to an unauthorized actor
CWE-200 Low
No
No
17.0.6, 17.1.4, 17.2.2 08.08.2024 SB2024080830
#VU95546 - Incorrect Regular Expression
CWE-185 Low
No
No
17.0.6, 17.1.4, 17.2.2 08.08.2024 SB2024080830
#VU95521 - Permissions, Privileges, and Access Controls
CVE-2024-3035
CWE-264 Medium
No
No
17.0.6, 17.1.4, 17.2.2 08.08.2024 SB2024080830
#VU94724 - Exposure of sensitive information to an unauthorized actor
CWE-200 Low
No
No
17.0.5, 17.1.3, 17.2.1 25.07.2024 SB2024072509
#VU94723 - Exposure of sensitive information to an unauthorized actor
CWE-200 Low
No
No
17.0.5, 17.1.3, 17.2.1 25.07.2024 SB2024072509
#VU94721 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-79 Low
No
No
17.0.5, 17.1.3, 17.2.1 25.07.2024 SB2024072509
#VU94719 - Improper Control of Resource Identifiers ('Resource Injection')
CVE-2024-0231
CWE-99 Low
No
No
17.0.5, 17.1.3, 17.2.1 25.07.2024 SB2024072509
#VU94718 - Exposure of sensitive information to an unauthorized actor
CVE-2024-7057
CWE-200 Low
No
No
17.0.5, 17.1.3, 17.2.1 25.07.2024 SB2024072509
#VU94717 - Exposure of sensitive information to an unauthorized actor
CVE-2024-5067
CWE-200 Low
No
No
17.0.5, 17.1.3, 17.2.1 25.07.2024 SB2024072509
#VU94098 - Improper Access Control
CVE-2024-5528
CWE-284 Low
No
No
16.11.6, 17.0.4, 17.1.2 11.07.2024 SB2024071112
#VU94096 - Improper Access Control
CVE-2024-2880
CWE-284 Low
No
No
16.11.6, 17.0.4, 17.1.2 11.07.2024 SB2024071112
#VU94095 - Improper Access Control
CVE-2024-6595
CWE-284 Low
No
No
16.11.6, 17.0.4, 17.1.2 11.07.2024 SB2024071112
#VU94094 - Improper Access Control
CVE-2024-5470
CWE-284 Low
No
No
17.0.4, 17.1.2 11.07.2024 SB2024071112
#VU94093 - Improper Access Control
CVE-2024-5257
CWE-284 Low
No
No
17.0.4, 17.1.2 11.07.2024 SB2024071112
#VU94092 - Improper Access Control
CVE-2024-6385
CWE-284 Medium
No
No
16.11.6, 17.0.4, 17.1.2 11.07.2024 SB2024071112
#VU93411 - Cross-Site Request Forgery (CSRF)
CVE-2024-2177
CWE-352 Low
No
No
16.11.5, 17.0.3, 17.1.1 27.06.2024 SB2024062719
#VU93410 - Improper Authorization
CVE-2024-6323
CWE-285 Medium
No
No
16.11.5, 17.0.3, 17.1.1 27.06.2024 SB2024062719
#VU93409 - Cross-Site Request Forgery (CSRF)
CVE-2024-4994
CWE-352 Low
No
No
16.11.5, 17.0.3, 17.1.1 27.06.2024 SB2024062719
#VU93408 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-4901
CWE-79 Low
No
No
16.11.5, 17.0.3, 17.1.1 27.06.2024 SB2024062719
#VU93407 - Improper Access Control
CVE-2024-5655
CWE-284 Medium
No
No
16.11.5, 17.0.3, 17.1.1 27.06.2024 SB2024062719


Showing elements 401 - 420 out of 1052