Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:gem/gitlab-org/gitlab

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could allow an authenticated user with Duo Chat access to obtain Advanced Search instance configurations and sensitive credentials using a specially crafted GraphQL subscription argument to bypass serialization and perform server object lookup.

Join the discussion

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.

Join the discussion

A path traversal vulnerability in GitLab CE/EE versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 could allow an authenticated user to execute remote code via the package registry. This issue has been remediated in the specified fixed versions.

Join the discussion

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an unauthenticated user to cause a denial of service due to improper input validation.

Join the discussion

A vulnerability in GitLab CE/EE versions from 10.1.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 allows an authenticated user with Developer role to access unauthorized information due to insufficient access controls on internal request handling. This issue has been remediated in the specified versions.

Join the discussion

A race condition vulnerability in GitLab Enterprise Edition versions 17.0 up to but not including 19.0.5, 19.1 up to 19.1.3, and 19.2 up to 19.2.1 could allow an authenticated user to merge code into a protected branch without the required approvals. This issue arises from a time-of-check to time-of-use (TOCTOU) flaw in the approval rule processing logic. The vulnerability has been remediated in fixed versions.

Join the discussion

A vulnerability in GitLab CE/EE versions from 14.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 allows an attacker to execute arbitrary JavaScript in another user's browser via a crafted URL. This occurs due to improper sanitization of user-controlled input, leading to a cross-site scripting (XSS) issue. The vulnerability has been remediated in the specified fixed versions.

Join the discussion

A vulnerability in GitLab CE/EE versions from 12.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 allows an authenticated user with Maintainer role to modify protected branch configurations due to improper authorization in a project API endpoint. This issue has been remediated by GitLab in the specified fixed versions.

Join the discussion

A vulnerability in GitLab CE/EE versions from 10.6 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 allowed an authenticated user with developer-role permissions to commit changes to a project even after being removed as a member. This was due to improper authorization checks on merge request collaboration settings. The issue has been remediated in the specified fixed versions.

Join the discussion

A vulnerability in GitLab CE/EE versions from 11.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 could allow an unauthenticated user to cause a denial of service. The issue arises from insufficient resource throttling when processing merge request discussions. This vulnerability has been remediated in the specified fixed versions.

Join the discussion

Showing 1 to 10 of 10 results

Filters:Package: pkg:gem/gitlab-org/gitlab
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses