Known vulnerabilities in GitLab Enterprise Edition - page 29

Software CPE: cpe:2.3:a:gitlab:gitlab-ee:*:*:*:*:*:*:*:*
Total vulnerabilities: 1052
Public exploits: 16
Known exploited (KEV): 4
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting GitLab Enterprise Edition GitLab Enterprise Edition is affected by 1052 known vulnerabilities: 1 critical, 31 high, 481 medium, 539 low Critical High Medium Low

Vulnerabilities (1052)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU77840 - Exposure of sensitive information to an unauthorized actor
CVE-2023-1936
CWE-200 Low
No
No
15.11.10, 16.0.6, 16.1.1 30.06.2023 SB2023063024
#VU77838 - Exposure of sensitive information to an unauthorized actor
CVE-2023-3363
CWE-200 Low
No
No
15.11.10, 16.0.6, 16.1.1 30.06.2023 SB2023063024
#VU77837 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-2200
CWE-79 Low
No
No
15.11.10, 16.0.6, 16.1.1 30.06.2023 SB2023063024
#VU77836 - Improper Access Control
CVE-2023-2576
CWE-284 Low
No
No
15.11.10, 16.0.6, 16.1.1 30.06.2023 SB2023063024
#VU77835 - Exposure of sensitive information to an unauthorized actor
CVE-2023-3102
CWE-200 Medium
No
No
16.0.6, 16.1.1 30.06.2023 SB2023063024
#VU77834 - Exposure of sensitive information to an unauthorized actor
CVE-2023-3362
CWE-200 Medium
No
No
16.0.6, 16.1.1 30.06.2023 SB2023063024
#VU77833 - Exposure of sensitive information to an unauthorized actor
CVE-2023-2620
CWE-200 Low
No
No
15.11.10, 16.0.6, 16.1.1 30.06.2023 SB2023063024
#VU77000 - Exposure of sensitive information to an unauthorized actor
CVE-2023-1825
CWE-200 Low
No
No
15.10.8, 15.11.7, 16.0.2 06.06.2023 SB2023060644
#VU76999 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2023-0508
CWE-601 Low
No
No
15.10.8, 15.11.7, 16.0.2 06.06.2023 SB2023060644
#VU76998 - Improper Access Control
CVE-2023-1204
CWE-284 Low
No
No
15.10.8, 15.11.7, 16.0.2 06.06.2023 SB2023060644
#VU76997 - Improper input validation
CVE-2023-0921
CWE-20 Low
No
No
15.10.8, 15.11.7, 16.0.2 06.06.2023 SB2023060644
#VU76996 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2023-2001
CWE-451 Low
No
No
15.10.8, 15.11.7, 16.0.2 06.06.2023 SB2023060644
#VU76995 - Permissions, Privileges, and Access Controls
CVE-2023-2485
CWE-264 Low
No
No
15.10.8, 15.11.7, 16.0.2 06.06.2023 SB2023060644
#VU76994 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-2015
CWE-79 Low
No
No
15.10.8, 15.11.7, 16.0.2 06.06.2023 SB2023060644
#VU76993 - Exposure of sensitive information to an unauthorized actor
CVE-2023-2589
CWE-200 Medium
No
No
15.10.8, 15.11.7, 16.0.2 06.06.2023 SB2023060644
#VU76991 - Resource exhaustion
CVE-2023-0121
CWE-400 Medium
No
No
15.10.8, 15.11.7, 16.0.2 06.06.2023 SB2023060644
#VU76988 - Incorrect Regular Expression
CVE-2023-2132
CWE-185 Medium
No
No
15.10.8, 15.11.7, 16.0.2 06.06.2023 SB2023060644
#VU76980 - Incorrect Regular Expression
CVE-2023-2198
CWE-185 Medium
No
No
15.10.8, 15.11.7, 16.0.2 06.06.2023 SB2023060644
#VU76974 - Incorrect Regular Expression
CVE-2023-2199
CWE-185 Medium
No
No
15.10.8, 15.11.7, 16.0.2 06.06.2023 SB2023060644
#VU76972 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-2442
CWE-79 Low
No
No
15.11.7, 16.0.2 06.06.2023 SB2023060644


Showing elements 561 - 580 out of 1052