Known vulnerabilities in GitLab Enterprise Edition - page 38

Software CPE: cpe:2.3:a:gitlab:gitlab-ee:*:*:*:*:*:*:*:*
Total vulnerabilities: 1052
Public exploits: 16
Known exploited (KEV): 4
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting GitLab Enterprise Edition GitLab Enterprise Edition is affected by 1052 known vulnerabilities: 1 critical, 31 high, 481 medium, 539 low Critical High Medium Low

Vulnerabilities (1052)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU62749 - Exposure of sensitive information to an unauthorized actor
CWE-200 Low
No
No
14.8.6, 14.9.4, 14.10.1 03.05.2022 SB2022050309
#VU62748 - Improper Authentication
CVE-2022-1426
CWE-287 Low
No
No
14.8.6, 14.9.4, 14.10.1 03.05.2022 SB2022050309
#VU61795 - Improper input validation
CVE-2022-1121
CWE-20 Medium
No
No
14.7.7, 14.8.5, 14.9.2 01.04.2022 SB2022040106
#VU61794 - Improper Authorization
CVE-2022-1148
CWE-285 Medium
No
No
14.7.7, 14.8.5, 14.9.2 01.04.2022 SB2022040106
#VU61793 - Business Logic Errors (3.0)
CVE-2022-1111
CWE-840 Low
No
No
14.7.7, 14.8.5, 14.9.2 01.04.2022 SB2022040106
#VU61792 - Exposure of sensitive information to an unauthorized actor
CVE-2022-1157
CWE-200 Low
No
No
14.7.7, 14.8.5, 14.9.2 01.04.2022 SB2022040106
#VU61787 - Exposure of sensitive information to an unauthorized actor
CVE-2022-1189
CWE-200 Low
No
No
14.7.7, 14.8.5, 14.9.2 01.04.2022 SB2022040106
#VU61786 - Improper Authorization
CVE-2022-0740
CWE-285 Low
No
No
14.7.7, 14.8.5, 14.9.2 01.04.2022 SB2022040106
#VU61785 - Server-Side Request Forgery (SSRF)
CVE-2022-1188
CWE-918 Low
No
No
14.7.7, 14.8.5, 14.9.2 01.04.2022 SB2022040106
#VU61784 - Improper input validation
CVE-2022-1174
CWE-20 Low
No
No
14.7.7, 14.8.5, 14.9.2 01.04.2022 SB2022040106
#VU61783 - Improper input validation
CVE-2022-1099
CWE-20 Low
No
No
14.7.7, 14.8.5, 14.9.2 01.04.2022 SB2022040106
#VU61782 - Improper Access Control
CVE-2022-1105
CWE-284 Low
No
No
14.7.7, 14.8.5, 14.9.2 01.04.2022 SB2022040106
#VU61781 - Improper Access Control
CVE-2022-1193
CWE-284 Low
No
No
14.7.7, 14.8.5, 14.9.2 01.04.2022 SB2022040106
#VU61780 - Improper input validation
CVE-2022-1100
CWE-20 Low
No
No
14.7.7, 14.8.5, 14.9.2 01.04.2022 SB2022040106
#VU61779 - Exposure of sensitive information to an unauthorized actor
CVE-2022-1120
CWE-200 Medium
No
No
14.7.7, 14.8.5, 14.9.2 01.04.2022 SB2022040106
#VU61778 - Improper input validation
CVE-2022-1185
CWE-20 Medium
No
No
14.7.7, 14.8.5, 14.9.2 01.04.2022 SB2022040106
#VU61777 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-1190
CWE-79 Low
No
No
14.7.7, 14.8.5, 14.9.2 01.04.2022 SB2022040106
#VU61776 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-1175
CWE-79 Low
Available
No
14.7.7, 14.8.5, 14.9.2 01.04.2022 SB2022040106
#VU61775 - Use of Hard-coded Credentials
CVE-2022-1162
CWE-798 High
Available
No
14.7.7, 14.8.5, 14.9.2 01.04.2022 SB2022040106
#VU60890 - Exposure of sensitive information to an unauthorized actor
CVE-2022-0735
CWE-200 Medium
No
No
14.6.5, 14.7.4, 14.8.2 28.02.2022 SB2022022801


Showing elements 741 - 760 out of 1052