← All credits
Thanks [joaxcar](https://hackerone.com/joaxcar) for reporting this vulnerability through our HackerOne bug bounty program
104 vulnerability records and advisories credit this contributor.
CVE-2023-3950
Cleartext Storage of Sensitive Information in GitLab
CVE-2023-3915
Incorrect Execution-Assigned Permissions in GitLab
CVE-2023-3914
Incorrect User Management in GitLab
CVE-2023-3210
Inefficient Regular Expression Complexity in GitLab
CVE-2023-3205
Inefficient Regular Expression Complexity in GitLab
CVE-2023-1836
A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. When viewing an XML file in a repository i
CVE-2023-1733
A denial of service condition exists in the Prometheus server bundled with GitLab affecting all versions from 11.10 to 15.8.5, 15.9 to 15.9.4 and 15.10 to 15.10.1.
CVE-2023-1401
Insertion of Sensitive Information Into Sent Data in GitLab
CVE-2023-1265
An issue has been discovered in GitLab affecting all versions starting from 11.9 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. The condition allows for a privileged attacker, under certain
CVE-2023-0632
Inefficient Regular Expression Complexity in GitLab