CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

Search Vulnerabilities

 Software

Searching vulnerabilities affecting “gitlab”

226 vulnerabilities found for “gitlab”

Page 1 of 12

CVE-2025-8279
HIGH8.7

Insufficient input validation within GitLab Language Server 7.6.0 and later before 7.30.0 allows arbitrary GraphQL query execution

gitlab / language_server
Network
Published Jul 28, 2025
Page 1 of 12
CVE-2025-24397
MEDIUM4.3

An incorrect permission check in Jenkins GitLab Plugin 1.9.6 and earlier allows attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate credential IDs of GitLab API token and Secret text credentials stored in Jenkins.

jenkins / gitlab
Network
Published Jan 22, 2025
CVE-2023-39153
MEDIUM5.4

A cross-site request forgery (CSRF) vulnerability in Jenkins GitLab Authentication Plugin 1.17.1 and earlier allows attackers to trick users into logging in to the attacker's account.

jenkins / gitlab_authentication
Network
Published Jul 26, 2023
CVE-2022-4317
MEDIUM5.0

An issue has been discovered in GitLab DAST analyzer affecting all versions starting from 1.47 before 3.0.51, which sends custom request headers in redirects.

gitlab / dynamic_application_security_testing_analyzer
Network
Published Mar 9, 2023
CVE-2022-4315
MEDIUM5.0

An issue has been discovered in GitLab DAST analyzer affecting all versions starting from 2.0 before 3.0.55, which sends custom request headers with every request on the authentication page.

gitlab / dynamic_application_security_testing_analyzer
Network
Published Mar 8, 2023
CVE-2022-4206
MEDIUM5.0

A sensitive information leak issue has been discovered in all versions of DAST API scanner from 1.6.50 prior to 2.0.102, exposing the Authorization header in the vulnerability report

gitlab / dast_api_scanner
Network
Published Feb 1, 2023
CVE-2022-2251
MEDIUM4.8

Improper sanitization of branch names in GitLab Runner affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows a user who creates a branch with a specially crafted name and gets another user to trigger a pipeline to execute commands in the runner as that other user.

gitlab / runner+2
Network
Published Jan 17, 2023
CVE-2022-43411
MEDIUM5.3

Jenkins GitLab Plugin 1.5.35 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook token.

jenkins / gitlab
Network
Published Oct 19, 2022
CVE-2022-34777
MEDIUM5.4

Jenkins GitLab Plugin 1.5.34 and earlier does not escape multiple fields inserted into the description of webhook-triggered builds, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

jenkins / gitlab
Network
Published Jun 30, 2022
CVE-2021-39947
MEDIUM5.3

In specific circumstances, trace file buffers in GitLab Runner versions up to 14.3.4, 14.4 to 14.4.2, and 14.5 to 14.5.2 would re-use the file descriptor 0 for multiple traces and mix the output of several jobs

gitlab / gitlab_runner+2
Network
Published Jun 6, 2022
CVE-2022-30955
MEDIUM6.5

Jenkins GitLab Plugin 1.5.31 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

jenkins / gitlab
Network
Published May 17, 2022
CVE-2022-27206
MEDIUM6.5

Jenkins GitLab Authentication Plugin 1.13 and earlier stores the GitLab client secret unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

jenkins / gitlab_authentication
Network
Published Mar 15, 2022
CVE-2022-25196
MEDIUM5.4

Jenkins GitLab Authentication Plugin 1.13 and earlier records the HTTP Referer header as part of the URL query parameters when the authentication process starts, allowing attackers with access to Jenkins to craft a URL that will redirect users to an attacker-specified URL after logging in.

jenkins / gitlab_authentication
Network
Published Feb 15, 2022
CVE-2020-13327
MEDIUM6.0

An issue has been discovered in GitLab Runner affecting all versions starting from 13.4.0 before 13.4.2, all versions starting from 13.3.0 before 13.3.7, all versions starting from 13.2.0 before 13.2.10. Insecure Runner Configuration in Kubernetes Environments

gitlab / runner+2
Network
Published Oct 22, 2020
CVE-2020-13295
MEDIUM5.4

For GitLab Runner before 13.0.12, 13.1.6, 13.2.3, by replacing dockerd with a malicious server, the Shared Runner is susceptible to SSRF.

gitlab / runner+2
Network
Published Aug 10, 2020
CVE-2020-2228
HIGH8.8

Jenkins Gitlab Authentication Plugin 1.5 and earlier does not perform group authorization checks properly, resulting in a privilege escalation vulnerability.

jenkins / gitlab_authentication
Network
Published Jul 15, 2020
CVE-2019-10429
MEDIUM5.5

Jenkins GitLab Logo Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.

jenkins / gitlab_logo
Local
Published Sep 25, 2019
CVE-2019-5485
CRITICAL10.0

NPM package gitlabhook version 0.0.17 is vulnerable to a Command Injection vulnerability. Arbitrary commands can be injected through the repository name.

gitlabhook_project / gitlabhook
Network
Published Sep 13, 2019
CVE-2019-10300
HIGH8.0

A cross-site request forgery vulnerability in Jenkins GitLab Plugin 1.5.11 and earlier in the GitLabConnectionConfig#doTestConnection form validation method allowed attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

jenkins / gitlab
Network
Published Apr 18, 2019
CVE-2019-10301
HIGH8.8

A missing permission check in Jenkins GitLab Plugin 1.5.11 and earlier in the GitLabConnectionConfig#doTestConnection form validation method allowed attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

jenkins / gitlab
Network
Published Apr 18, 2019