Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

GitLab — Vulnerabilities & Security Advisories 1109

Browse all 1109 CVE security advisories affecting GitLab. AI-powered Chinese analysis, POCs, and references for each vulnerability.

GitLab operates as a comprehensive DevOps platform, providing version control, continuous integration, and deployment capabilities primarily for software development teams. With over one thousand recorded CVEs, the software has historically been susceptible to critical vulnerability classes, including remote code execution, cross-site scripting, and privilege escalation attacks. These flaws often stem from complex integrations and API endpoints, allowing attackers to bypass authentication or execute arbitrary commands on affected servers. Notable incidents have included unauthorized access to private repositories and data exfiltration due to improper access controls. The high volume of vulnerabilities reflects the platform’s extensive feature set and frequent updates, necessitating rigorous patch management. Security assessments consistently highlight the importance of configuring secure defaults and monitoring for known exploit patterns to mitigate risks associated with its broad attack surface.

CVE ID Title CVSS Severity Published
CVE-2023-3509 Incorrect Authorization in GitLab — GitLab CWE-863 3.7 Low 2024-02-21
CVE-2024-1250 Privilege Chaining in GitLab — GitLab CWE-268 6.5 Medium 2024-02-12
CVE-2023-6564 Incorrect Authorization in GitLab — GitLab CWE-863 6.5 Medium 2024-02-08
CVE-2023-6736 Inefficient Regular Expression Complexity in GitLab — GitLab CWE-1333 6.5 Medium 2024-02-07
CVE-2023-6840 Missing Authorization in GitLab — GitLab CWE-862 6.7 Medium 2024-02-07
CVE-2024-1066 Allocation of Resources Without Limits or Throttling in GitLab — GitLab CWE-770 6.5 Medium 2024-02-07
CVE-2023-5612 Missing Authorization in GitLab — GitLab CWE-862 5.3 Medium 2024-01-26
CVE-2023-6159 Inefficient Regular Expression Complexity in GitLab — GitLab CWE-1333 6.5 Medium 2024-01-26
CVE-2023-5933 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in GitLab — GitLab CWE-80 6.4 Medium 2024-01-26
CVE-2024-0456 Direct Request ('Forced Browsing') in GitLab — GitLab CWE-425 4.3 Medium 2024-01-26
CVE-2024-0402 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab — GitLab CWE-22 9.9 Critical 2024-01-26
CVE-2023-2030 Improper Verification of Cryptographic Signature in GitLab — GitLab CWE-347 3.5 Low 2024-01-12
CVE-2023-4812 Incorrect Authorization in GitLab — GitLab CWE-863 7.6 High 2024-01-12
CVE-2023-5356 Incorrect Authorization in GitLab — GitLab CWE-863 7.3 High 2024-01-12
CVE-2023-7028 Weak Password Recovery Mechanism for Forgotten Password in GitLab — GitLab CWE-640 10.0 Critical 2024-01-12
CVE-2023-6955 Missing Authorization in GitLab — GitLab CWE-862 6.6 Medium 2024-01-12
CVE-2023-3907 Improper User Management in GitLab — GitLab CWE-286 4.9 Medium 2023-12-17
CVE-2023-3904 Improper Validation of Specified Type of Input in GitLab — GitLab CWE-1287 4.3 Medium 2023-12-15
CVE-2023-5061 Missing Authorization in GitLab — GitLab CWE-862 4.3 Medium 2023-12-15
CVE-2023-5512 Improper Control of Generation of Code ('Code Injection') in GitLab — GitLab CWE-94 4.8 Medium 2023-12-15
CVE-2023-6051 Improper Control of Generation of Code ('Code Injection') in GitLab — GitLab CWE-94 5.7 Medium 2023-12-15
CVE-2023-6680 Improper Certificate Validation in GitLab — GitLab CWE-295 7.4 High 2023-12-15
CVE-2023-3511 Incorrect Authorization in GitLab — GitLab CWE-863 2.0 Low 2023-12-15
CVE-2023-5332 Dependency on Vulnerable Third-Party Component in GitLab — GitLab CWE-1395 5.9 Medium 2023-12-04
CVE-2023-3443 Incorrect Authorization in GitLab — GitLab CWE-863 3.1 Low 2023-12-01
CVE-2023-3964 Incorrect Authorization in GitLab — GitLab CWE-863 4.3 Medium 2023-12-01
CVE-2023-3949 Insertion of Sensitive Information Into Sent Data in GitLab — GitLab CWE-201 5.3 Medium 2023-12-01
CVE-2023-4317 Incorrect Authorization in GitLab — GitLab CWE-863 4.3 Medium 2023-12-01
CVE-2023-4658 Incorrect Authorization in GitLab — GitLab CWE-863 3.1 Low 2023-12-01
CVE-2023-4912 Allocation of Resources Without Limits or Throttling in GitLab — GitLab CWE-770 2.6 Low 2023-12-01

This page lists every published CVE security advisory associated with GitLab. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.