QID 379222
Date Published: 2024-01-31
QID 379222: GitLab Multiple Security Vulnerabilities (gitlab- 13.0.1, 12.10.7, 12.9.8)
GitLab Inc. is an open-core company that operates GitLab, a DevOps software package which can develop, secure, and operate software
Affected Versions:
CVE-2022-2826: GitLab affecting all versions starting from 10.0 before 12.9.8, all versions starting from 12.10 before 12.10.7, all versions starting from 13.0 before 13.0.1
CVE-2020-13265: Affects GitLab CE/EE 12.5 and later
CVE-2020-13272: Affects GitLab CE/EE 12.3+ and later
CVE-2020-13276: Affects all previous GitLab CE/EE versions
CVE-2020-13275: Affects GitLab EE/CE 12.2 and later
CVE-2020-13263: Affects GitLab EE 9.5 and later
CVE-2020-13270: Affects GitLab CE/EE 11.3 and later
CVE-2020-13271: Affects all previous GitLab EE versions
CVE-2020-13264: Affects GitLab CE/EE between 10.3 and later
CVE-2020-13268: Affects GitLab CE/EE 12.10 and later
CVE-2020-13266: Affects GitLab CE/EE 12.8 and later
CVE-2020-13267: Affects GitLab CE/EE 12.8 and later
CVE-2020-13273: Affects GitLab CE/EE 12.0 and later
CVE-2020-13262: Affects GitLab CE/EE 12.9 and later
CVE-2020-13269: Affects GitLab CE/EE 12.10 and later
CVE-2020-13261: Affects GitLab CE/EE 12.6 and later
CVE-2020-13274: Affects all previous GitLab CE/EE versions
CVE-2020-8130: Affects GitLab CE/EE 12.0 and later
CVE-2020-13379: Affects GitLab EE/CE 11.9 and later
Patch Versions:
GitLab Security Release: 13.0.1, 12.10.7 and 12.9.8
QID Detection Logic:(Authenticated)
It fires gitlab-rake gitlab:env:info command to check vulnerable version of GitLab.
Successful exploitation of this vulnerability affects Confidentiality, Integrity, Availability.
- GitLab Security Advisory -
about.gitlab.com/releases/2020/05/27/security-release-13-0-1-released/
CVEs related to QID 379222
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GitLab Security Advisory |
|