Known vulnerabilities in GitLab Enterprise Edition - page 36

Software CPE: cpe:2.3:a:gitlab:gitlab-ee:*:*:*:*:*:*:*:*
Total vulnerabilities: 1052
Public exploits: 16
Known exploited (KEV): 4
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting GitLab Enterprise Edition GitLab Enterprise Edition is affected by 1052 known vulnerabilities: 1 critical, 31 high, 481 medium, 539 low Critical High Medium Low

Vulnerabilities (1052)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU65894 - Data Handling
CVE-2022-2534
CWE-19 Low
No
No
15.0.5, 15.1.4, 15.2.1 29.07.2022 SB2022072918
#VU65893 - Improper Access Control
CVE-2022-2459
CWE-284 Low
No
No
15.0.5, 15.1.4, 15.2.1 29.07.2022 SB2022072918
#VU65889 - Improper input validation
CVE-2022-2307
CWE-20 Low
No
No
15.0.5, 15.1.4, 15.2.1 29.07.2022 SB2022072918
#VU65887 - Exposure of sensitive information to an unauthorized actor
CVE-2022-2499
CWE-200 Low
No
No
15.0.5, 15.1.4, 15.2.1 29.07.2022 SB2022072918
#VU64855 - Exposure of sensitive information to an unauthorized actor
CVE-2022-2281
CWE-200 Low
No
No
14.10.5, 15.0.4, 15.1.1 01.07.2022 SB2022070111
#VU64854 - Improper Access Control
CVE-2022-2227
CWE-284 Low
No
No
14.10.5, 15.0.4, 15.1.1 01.07.2022 SB2022070111
#VU64853 - Improper input validation
CVE-2022-1999
CWE-20 Low
No
No
14.10.5, 15.0.4, 15.1.1 01.07.2022 SB2022070111
#VU64852 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2022-2250
CWE-601 Medium
No
No
14.10.5, 15.0.4, 15.1.1 01.07.2022 SB2022070111
#VU64851 - Exposure of sensitive information to an unauthorized actor
CVE-2022-2270
CWE-200 Low
No
No
14.10.5, 15.0.4, 15.1.1 01.07.2022 SB2022070111
#VU64850 - Improper input validation
CVE-2022-1954
CWE-20 Low
No
No
14.10.5, 15.0.4, 15.1.1 01.07.2022 SB2022070111
#VU64849 - Improper Authorization
CVE-2022-2244
CWE-285 Low
No
No
14.10.5, 15.0.4, 15.1.1 01.07.2022 SB2022070111
#VU64848 - Improper Access Control
CVE-2022-2243
CWE-284 Medium
No
No
14.10.5, 15.0.4, 15.1.1 01.07.2022 SB2022070111
#VU64847 - Improper Access Control
CVE-2022-1981
CWE-284 Low
No
No
14.10.5, 15.0.4, 15.1.1 01.07.2022 SB2022070111
#VU64846 - Exposure of sensitive information to an unauthorized actor
CVE-2022-2228
CWE-200 Medium
No
No
14.10.5, 15.0.4, 15.1.1 01.07.2022 SB2022070111
#VU64845 - Exposure of sensitive information to an unauthorized actor
CVE-2022-1963
CWE-200 Medium
No
No
14.10.5, 15.0.4, 15.1.1 01.07.2022 SB2022070111
#VU64844 - Improper Authorization
CVE-2022-1983
CWE-285 Low
No
No
14.10.5, 15.0.4, 15.1.1 01.07.2022 SB2022070111
#VU64843 - Improper Authorization
CVE-2022-2229
CWE-285 Medium
No
No
14.10.5, 15.0.4, 15.1.1 01.07.2022 SB2022070111
#VU64842 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-2230
CWE-79 Low
No
No
14.10.5, 15.0.4, 15.1.1 01.07.2022 SB2022070111
#VU64841 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-2235
CWE-79 Low
No
No
14.10.5, 15.0.4, 15.1.1 01.07.2022 SB2022070111
#VU64840 - Command injection
CVE-2022-2185
CWE-77 Medium
Available
No
14.10.5, 15.0.4, 15.1.1 01.07.2022 SB2022070111


Showing elements 701 - 720 out of 1052