TOPGITLAB.md

June 11, 2026 ยท View on GitHub

Top reports from GitLab program at HackerOne:

  1. Arbitrary file read via the UploadsRewriter when moving and issue to GitLab - 1497 upvotes, $20000
  2. Account Takeover via Password Reset without user interactions to GitLab - 919 upvotes, $35000
  3. Git flag injection - local file overwrite to remote code execution to GitLab - 777 upvotes, $12000
  4. Exfiltrate and mutate repository and project data through injected templated service to GitLab - 757 upvotes, $11000
  5. Stored XSS in Wiki pages to GitLab - 621 upvotes, $0
  6. Local files could be overwritten in GitLab, leading to remote command execution to GitLab - 540 upvotes, $12000
  7. RCE when removing metadata with ExifTool to GitLab - 504 upvotes, $20000
  8. Project Template functionality can be used to copy private project data, such as repository, confidential issues, snippets, and merge requests to GitLab - 455 upvotes, $12000
  9. RCE via unsafe inline Kramdown options when rendering certain Wiki pages to GitLab - 426 upvotes, $20000
  10. gitlab-workhorse bypass in Gitlab::Middleware::Multipart allowing files in allowed_paths to be read to GitLab - 409 upvotes, $10000
  11. Remote Command Execution via Github import to GitLab - 379 upvotes, $33510
  12. RCE via the DecompressedArchiveSizeValidator and Project BulkImports (behind feature flag) to GitLab - 370 upvotes, $33510
  13. JSON serialization of any Project model results in all Runner tokens being exposed through Quick Actions to GitLab - 364 upvotes, $12000
  14. Bypass of GitLab CI runner slash fix in YAML validation to GitLab - 361 upvotes, $0
  15. SSRF on project import via the remote_attachment_url on a Note to GitLab - 355 upvotes, $10000
  16. Attacker is able to access commit title and team member comments which are supposed to be private to GitLab - 350 upvotes, $0
  17. Server Side Request Forgery mitigation bypass to GitLab - 347 upvotes, $0
  18. Arbitrary file read via the bulk imports UploadsPipeline to GitLab - 323 upvotes, $29000
  19. Stored XSS in markdown via the DesignReferenceFilter to GitLab - 315 upvotes, $16000
  20. An attacker can run pipeline jobs as arbitrary user to GitLab - 307 upvotes, $12000
  21. Full access to internal Gitlab instances at redash.gitlab.com, dashboards.gitlab.com, prometheus.gitlab.com to GitLab - 305 upvotes, $0
  22. Stored XSS via Kroki diagram to GitLab - 293 upvotes, $13950
  23. Cross-site Scripting (XSS) - Stored in RDoc wiki pages to GitLab - 282 upvotes, $3500
  24. RCE via github import to GitLab - 271 upvotes, $0
  25. Ability to bypass email verification for OAuth grants results in accounts takeovers on 3rd parties to GitLab - 256 upvotes, $3000
  26. Privilege escalation from any user (including external) to gitlab admin when admin impersonates you to GitLab - 254 upvotes, $0
  27. Bypass Email Verification -- Able to Access Internal Gitlab Services that use Login with Gitlab and Perform Check on email domain to GitLab - 247 upvotes, $0
  28. Steal private objects of other projects via project import to GitLab - 245 upvotes, $20000
  29. Unauthenticated blind SSRF in OAuth Jira authorization controller to GitLab - 234 upvotes, $4000
  30. Full Read SSRF on Gitlab's Internal Grafana to GitLab - 227 upvotes, $0
  31. Ability To Delete User(s) Account Without User Interaction to GitLab - 219 upvotes, $0
  32. Group search leaks private MRs, code, commits to GitLab - 211 upvotes, $0
  33. Arbitrary file read during project import to GitLab - 194 upvotes, $16000
  34. Git flag injection leading to file overwrite and potential remote code execution to GitLab - 169 upvotes, $3500
  35. Stored-XSS with CSP-bypass via labels' color to GitLab - 169 upvotes, $0
  36. Snippet JS template allows attacker to read a user's private snippets to GitLab - 165 upvotes, $300
  37. Stored XSS in Notes (with CSP bypass for gitlab.com) to GitLab - 160 upvotes, $13950
  38. Importing GitLab project archives can replace uploads of other users to GitLab - 146 upvotes, $0
  39. information disclosure of secret_key_base via encoding charcters to GitLab - 145 upvotes, $3500
  40. DoS on the Issue page by exploiting Mermaid. to GitLab - 144 upvotes, $3000
  41. Path traversal, to RCE to GitLab - 141 upvotes, $12000
  42. Persistent XSS in Note objects to GitLab - 138 upvotes, $4500
  43. Send arbitrary PUT requests when user clicks on a link to GitLab - 135 upvotes, $0
  44. Mint Oauth2 access token for targeted user to GitLab - 133 upvotes, $5580
  45. Stored XSS in custom emoji to GitLab - 129 upvotes, $3000
  46. Git flag injection - Search API with scope 'blobs' to GitLab - 128 upvotes, $7000
  47. Private objects exposed through project import to GitLab - 126 upvotes, $20000
  48. Read files on application server, leads to RCE to GitLab - 114 upvotes, $0
  49. IDOR Exposes All Machine Learning Models to GitLab - 106 upvotes, $1160
  50. Able to view hackerone reports attachments to GitLab - 102 upvotes, $0
  51. Group search with Elastic search enable leaks unrelated data to GitLab - 99 upvotes, $0
  52. CSP-bypass XSS in project settings page to GitLab - 98 upvotes, $0
  53. XSS in request approvals to GitLab - 96 upvotes, $3000
  54. Account takeover due to insufficient URL validation on RelayState parameter to GitLab - 96 upvotes, $2450
  55. Bypass: Stored-XSS with CSP-bypass via scoped labels' color to GitLab - 96 upvotes, $0
  56. New /add_contacts /remove_contacts quick commands susseptible to XSS from Customer Contact firstname/lastname fields to GitLab - 92 upvotes, $13950
  57. Stored XSS in "Create Groups" to GitLab - 88 upvotes, $2500
  58. Path traversal in Nuget Package Registry to GitLab - 87 upvotes, $12000
  59. Unrestricted file upload leads to Stored XSS to GitLab - 87 upvotes, $0
  60. CSRF on /api/graphql allows executing mutations through GET requests to GitLab - 85 upvotes, $3370
  61. DoS attack via comment on Issue to GitLab - 84 upvotes, $1000
  62. RepositoryPipeline allows importing of local git repos to GitLab - 82 upvotes, $22300
  63. Cache poisoning Denial of Service affecting assets.gitlab-static.net to GitLab - 82 upvotes, $0
  64. XSS in ZenTao integration affecting self hosted instances without strict CSP to GitLab - 81 upvotes, $13950
  65. Stored XSS in main page of a project caused by arbitrary script payload in group "Default initial branch name" to GitLab - 80 upvotes, $3000
  66. Subdomain takeover in Gitlab pages to GitLab - 79 upvotes, $0
  67. GitLab-Runner on Windows DOCKER_AUTH_CONFIG container host Command Injection to GitLab - 77 upvotes, $0
  68. SSRF in CI after first run to GitLab - 72 upvotes, $0
  69. Remove obsolete domain from handbook subdomain to GitLab - 72 upvotes, $0
  70. Stored-XSS injected in Wiki page via Banzai pipeline to GitLab - 71 upvotes, $0
  71. GitLab::UrlBlocker validation bypass leading to full Server Side Request Forgery to GitLab - 69 upvotes, $0
  72. Login email verification bypass via /oauth/token. to GitLab - 66 upvotes, $0
  73. Privilege escalation of "external user" (with maintainer privilege) to internal access through project token to GitLab - 65 upvotes, $1020
  74. GraphQL query "namespace" leaks data to GitLab - 64 upvotes, $0
  75. DOS: taking down a 1k users Gitlab EE instance or multiple Sidekiq instances by importing a malicious repo from a Github EE self-hosted server to GitLab - 64 upvotes, $0
  76. Ability to access all user authentication tokens, leads to RCE to GitLab - 60 upvotes, $0
  77. HTML injection possible with soft email confirmations when Administrator manually confirms attacker email address to GitLab - 59 upvotes, $1060
  78. [Admin Panel] CSRF to resume/pause runner to GitLab - 59 upvotes, $0
  79. Stored-XSS on wiki pages to GitLab - 59 upvotes, $0
  80. Stored XSS via Mermaid Prototype Pollution vulnerability to GitLab - 57 upvotes, $3000
  81. Know whether private project name exists or not within a group using link comments to GitLab - 57 upvotes, $0
  82. FogBugz import attachment full SSRF requiring vulnerability in *.fogbugz.com to GitLab - 57 upvotes, $0
  83. Bypass Email Verification using Salesforce -- Reproducible in gitlab.com to GitLab - 55 upvotes, $0
  84. Arbitrary POST request as victim user from HTML injection in Jupyter notebooks to GitLab - 54 upvotes, $8690
  85. Content injection in Jira issue title enabling sending arbitrary POST request as victim to GitLab - 54 upvotes, $8690
  86. Access to GitLab's Slack by abusing issue creation from e-mail to GitLab - 54 upvotes, $0
  87. All functions that allow users to specify color code are vulnerable to ReDoS to GitLab - 53 upvotes, $1000
  88. EXIF metadata not stripped from JPG group logos to GitLab - 53 upvotes, $500
  89. Stored XSS in merge request pages to GitLab - 52 upvotes, $3500
  90. Change project visibility to a restricted option to GitLab - 51 upvotes, $1370
  91. Stored XSS in markdown when redacting references to GitLab - 50 upvotes, $5000
  92. Stored XSS on the job page to GitLab - 50 upvotes, $3000
  93. RCE via WikiCloth markdown rendering if the rubyluabridge gem is installed to GitLab - 50 upvotes, $3000
  94. Command injection by overwriting authorized_keys file through GitLab import to GitLab - 50 upvotes, $2000
  95. Clientside resource Exhausting by exploiting gitlab math rendering to GitLab - 50 upvotes, $0
  96. Guest users can create new test cases to GitLab - 49 upvotes, $650
  97. XSS on Issue reference numbers to GitLab - 49 upvotes, $0
  98. Stored XSS via Mermaid Prototype Pollution vulnerability to GitLab - 48 upvotes, $3000
  99. Improper access control for users with expired password, giving the user full access through API and Git to GitLab - 48 upvotes, $950
  100. View the Starred Projects in a Private Profile to GitLab - 48 upvotes, $500
  101. A deactivated user can access data through GraphQL to GitLab - 47 upvotes, $1370
  102. GitLab CI runner can read and poison cache of all other projects to GitLab - 43 upvotes, $2000
  103. XSS: v-safe-html is not safe enough to GitLab - 43 upvotes, $0
  104. Milestones leaked via search API to GitLab - 42 upvotes, $0
  105. Stored XSS in Mermaid when viewing Markdown files to GitLab - 42 upvotes, $0
  106. SQL injection in MilestoneFinder order method to GitLab - 41 upvotes, $2000
  107. Kroki Arbitrary File Read/Write to GitLab - 41 upvotes, $0
  108. When you call your branch the same name as a git hash, it could be checked out by dependents to GitLab - 39 upvotes, $2000
  109. Using GitLab to monitor and hijack domains in mass quantity. to GitLab - 39 upvotes, $750
  110. Stored XSS on issue comments and other pages which contain notes to GitLab - 38 upvotes, $3000
  111. Stored XSS in blob viewer to GitLab - 37 upvotes, $0
  112. Removed Guest role user who dosent have access to private project in members able to view jobs to GitLab - 37 upvotes, $0
  113. Injection of http.\<url\>.* git config settings leading to SSRF to GitLab - 36 upvotes, $3000
  114. Bypassing push rules via MRs created by Email to GitLab - 36 upvotes, $0
  115. Store-XSS in error message of build-dependencies to GitLab - 35 upvotes, $0
  116. Evaluating Ruby code by injecting Rescue job on the system_hook_push queue through web hook to GitLab - 34 upvotes, $750
  117. Clipboard DOM-based XSS to GitLab - 34 upvotes, $0
  118. IDOR in "external status check" API leaks data about any status check on the instance to GitLab - 33 upvotes, $610
  119. Stored-XSS in merge requests to GitLab - 33 upvotes, $0
  120. Exposure of a valid Gitlab-Workhorse JWT leading to various bad things to GitLab - 33 upvotes, $0
  121. Stored XSS in merge request creation page through payload in approval rule name to GitLab - 32 upvotes, $3000
  122. Insecure 2FA/authentication implementation creates a brute force vulnerability to GitLab - 32 upvotes, $0
  123. Vulnerability in project import leads to arbitrary command execution to GitLab - 32 upvotes, $0
  124. Privilege escalation due to insecure use of logrotate to GitLab - 32 upvotes, $0
  125. Maintainer can leak sentry token by changing the configured URL (fix bypass) to GitLab - 32 upvotes, $0
  126. Mailgun misconfiguration leads to email snooping and postmaster@-access on email.mg.gitlab.com to GitLab - 31 upvotes, $0
  127. Uncontrolled Resource Consumption in any Markdown field using Mermaid to GitLab - 31 upvotes, $0
  128. Remote hacker can download all the files of master branch in public projects where everything is members only. to GitLab - 31 upvotes, $0
  129. Stored XSS in repository file viewer to GitLab - 29 upvotes, $2000
  130. Guest Users can create issues for Sentry errors and track their status to GitLab - 29 upvotes, $610
  131. Able to leak private email of any user given his/her username via graphql to GitLab - 29 upvotes, $0
  132. Attacker is able to create,Edit & delete notes and leak the title of a victim's private personal snippet to GitLab - 28 upvotes, $1730
  133. Access Projects And create projects in gitlab pre production server to GitLab - 28 upvotes, $0
  134. Stored DOM XSS via Mermaid chart to GitLab - 27 upvotes, $3000
  135. GitLab's GitHub integration is vulnerable to SSRF vulnerability to GitLab - 27 upvotes, $2000
  136. Stored XSS in group issue list to GitLab - 27 upvotes, $2000
  137. Drive-by arbitrary file deletion in the GDK via letter_opener_web gem to GitLab - 27 upvotes, $750
  138. Claiming package names in GitLab's automatic package referencer. to GitLab - 26 upvotes, $1000
  139. A profile page of a user can be denied from loading by appending .html to the username to GitLab - 26 upvotes, $200
  140. Bypassing password authentication of users that have 2FA enabled to GitLab - 26 upvotes, $0
  141. Add and Access to Labels of any Private Projects/Groups of Gitlab(IDOR) to GitLab - 26 upvotes, $0
  142. No redirect_uri in the db for web-internal clientKey leads to one-click DoS on gitter.im to GitLab - 26 upvotes, $0
  143. DOS via issue preview to GitLab - 25 upvotes, $7640
  144. Stored XSS on PyPi simple API endpoint to GitLab - 25 upvotes, $3000
  145. Domain Takeover - gl-canary.freetls.fastly.net to GitLab - 25 upvotes, $200
  146. SafeParamsHelper::safe_params is not so safe to GitLab - 24 upvotes, $4000
  147. Unauthorized users may be able to view almost all informations related to Private projects. to GitLab - 24 upvotes, $0
  148. Persistent XSS via e-mail when creating merge requests to GitLab - 24 upvotes, $0
  149. Last build status and coverage leaked to unauthorized users to GitLab - 24 upvotes, $0
  150. Stealing data from customers.gitlab.com without user interaction to GitLab - 24 upvotes, $0
  151. Unauthorized access to private project security dashboard to GitLab - 24 upvotes, $0
  152. Possibilty to purchase Ultimate - 1 Year (EDU or OSS) to GitLab - 23 upvotes, $0
  153. ReDoS due to device-detector parsing user agents to GitLab - 23 upvotes, $0
  154. Race condition in GitLab import, giving access to other people their imports due to filename collision to GitLab - 22 upvotes, $0
  155. Attacker can create malicious child epics linked to a victim's epic in an unrelated group to GitLab - 21 upvotes, $1160
  156. Reporters can upload design to issues using the "Move to" feature to GitLab - 21 upvotes, $600
  157. CRLF injection & SSRF in git:// protocal lead to arbitrary code execution to GitLab - 21 upvotes, $0
  158. Stored XSS for Grafana dashboard URL to GitLab - 21 upvotes, $0
  159. Instant open redirect on Live preview WEB Ide opening to GitLab - 20 upvotes, $1000
  160. CSV injection in gitlab.com via issues export feature. to GitLab - 20 upvotes, $0
  161. Gitlab is vulnerable to impersonation attacks due to broken links to GitLab - 20 upvotes, $0
  162. all private tokens are leaked to an unauthenticated attacker to GitLab - 20 upvotes, $0
  163. [Markdown] Stored XSS via character encoding parser bypass to GitLab - 20 upvotes, $0
  164. DOS via move_issue to GitLab - 19 upvotes, $2300
  165. SSRF vulnerability in gitlab.com via project import. to GitLab - 18 upvotes, $0
  166. HTML TAG INJECTION ON PROFILE NAME to GitLab - 18 upvotes, $0
  167. Stored XSS in merge request pages to GitLab - 18 upvotes, $0
  168. Unauthorized access to GitLab - 18 upvotes, $0
  169. Privilege escalation to access all private groups and repositories to GitLab - 17 upvotes, $0
  170. Stored XSS on Files overview by abusing git submodule URL to GitLab - 17 upvotes, $0
  171. Private System Note Disclosure using GraphQL to GitLab - 17 upvotes, $0
  172. Unauthenticated IP allowlist bypass when accessing job artifacts through gitlab pages at {group_id}.gitlab.io to GitLab - 16 upvotes, $1990
  173. Stored XSS on Issue details page to GitLab - 16 upvotes, $0
  174. Insufficient Type Check leading to Developer ability to delete Project, Repository, Group, ... to GitLab - 16 upvotes, $0
  175. Insufficient Type Check on GraphQL leading to Maintainer delete repository to GitLab - 15 upvotes, $0
  176. GitHub import allows user to create child group under existing namespace to GitLab - 14 upvotes, $750
  177. Persistent XSS on public wiki pages to GitLab - 14 upvotes, $0
  178. Removing a user from a private group doesn't remove him from group's project, if his project's role was changed to GitLab - 14 upvotes, $0
  179. SSRF In plantuml (on plantuml.pre.gitlab.com) to GitLab - 14 upvotes, $0
  180. Sending Arbitrary Requests through Jupyter Notebooks on gitlab.com and Self-Hosted GitLab Instances to GitLab - 14 upvotes, $0
  181. Gitlab Pages token theft using service workers to GitLab - 13 upvotes, $1680
  182. "External status checks" can be accepted by users below developer access if the user is either author or assignee of the target merge request to GitLab - 13 upvotes, $610
  183. ReDoS in syntax highlighting due to Rouge to GitLab - 13 upvotes, $600
  184. Guest users can change the confidentiality attribute on those issues that have been assigned to them to GitLab - 13 upvotes, $100
  185. User with guest access can access private merge requests to GitLab - 13 upvotes, $0
  186. Inadequate cache control in gitter allows to view private chat room to GitLab - 13 upvotes, $0
  187. Transferring a public group to a private group doesn't remove code from the Elastichsearch API search result to GitLab - 13 upvotes, $0
  188. [information disclosure] Validate existence of a private project. to GitLab - 13 upvotes, $0
  189. Blind SSRF in FogBugz project import to GitLab - 13 upvotes, $0
  190. XSS by clicking Jira's link to GitLab - 12 upvotes, $1130
  191. Every user can delete public deploy keys to GitLab - 12 upvotes, $0
  192. SSRF when importing a project from a git repo by URL to GitLab - 12 upvotes, $0
  193. SSRF into Shared Runner, by replacing dockerd with malicious server in Executor to GitLab - 12 upvotes, $0
  194. GraphQL Query leads to sensitive information disclosure to GitLab - 12 upvotes, $0
  195. Container escape on public GitLab CI runners to GitLab - 12 upvotes, $0
  196. Blocked user Git access through CI/CD token to GitLab - 11 upvotes, $1500
  197. XSS On meta tags in profile page to GitLab - 11 upvotes, $0
  198. State filter in IssuableFinder allows attacker to delete all issues and merge requests to GitLab - 11 upvotes, $0
  199. Unfiltered class attribute in markdown code to GitLab - 11 upvotes, $0
  200. Impersonation attack via Broken Link in Resellers Page to GitLab - 11 upvotes, $0
  201. Persistent XSS - Selecting users as allowed merge request approvers to GitLab - 11 upvotes, $0
  202. Head pipeline leaked to unauthorized users via blocking merge request feature to GitLab - 11 upvotes, $0
  203. Attacker can extract list of private project's project members to GitLab - 10 upvotes, $0
  204. Boards leak private label names and desciptions to GitLab - 10 upvotes, $0
  205. Users can download old project exports due to unclaimed namespace to GitLab - 10 upvotes, $0
  206. [Subgroups] Unprivileged User Can Disclose Private Group Names to GitLab - 10 upvotes, $0
  207. SSRF vulnerability in gitlab.com webhook to GitLab - 10 upvotes, $0
  208. Last pipeline status for MR leaked to GitLab - 10 upvotes, $0
  209. Revoked User can still view the Merge Request created by him via API to GitLab - 9 upvotes, $1500
  210. Installing Gitlab runner with Docker-In-Docker allows root access to GitLab - 9 upvotes, $100
  211. Users with guest access can post notes to private merge requests, issues, and snippets to GitLab - 9 upvotes, $0
  212. Markdown based stored XSS (IE only) to GitLab - 9 upvotes, $0
  213. Container scanning and Dependency scanning report leaked to unauthorized users to GitLab - 9 upvotes, $0
  214. Unauthorized user is able to access schedule pipeline variables and values to GitLab - 9 upvotes, $0
  215. ReDoS in net/http affects webhooks: Sidekiq job stuck at 100% CPU for a year to GitLab - 9 upvotes, $0
  216. Persistent XSS on public project page to GitLab - 8 upvotes, $0
  217. [RDoc] XSS in project README files to GitLab - 8 upvotes, $0
  218. Gitlab.com is vulnerable to reverse tabnabbing. (#2) to GitLab - 8 upvotes, $0
  219. XSS (Persistent) - Selecting role(s) for protected branches to GitLab - 8 upvotes, $0
  220. Adding everyone to the repo due to the lack of rate limit to GitLab - 8 upvotes, $0
  221. Elasticsearch leaks data through the notes scope to GitLab - 8 upvotes, $0
  222. Path paths and file disclosure vulnerabilities at influxdb.quality.gitlab.net to GitLab - 8 upvotes, $0
  223. Private snippets in public / internal projects leaked though GitLab API to GitLab - 7 upvotes, $0
  224. Labels created in private projects are leaked to GitLab - 7 upvotes, $0
  225. [reStructuredText] XSS in project README files to GitLab - 7 upvotes, $0
  226. Gitlab.com is vulnerable to reverse tabnabbing. to GitLab - 7 upvotes, $0
  227. CSRF Token Bypass in Account Deletion to GitLab - 7 upvotes, $0
  228. Potensial SSRF via Git repository URL to GitLab - 7 upvotes, $0
  229. Persistent XSS - Deleting a project (No Longer Vulnerable in 10.7) to GitLab - 7 upvotes, $0
  230. Todos are not redacted when membership changes - Access to (confidential) issues and merge requests to GitLab - 7 upvotes, $0
  231. Responsible Disclosure of Privacy Leakage Issue to GitLab - 7 upvotes, $0
  232. Bypass for Domain-level redirects (Unvalidated Redirects and Forwar) to GitLab - 7 upvotes, $0
  233. Attacker can post notes on private MR, snippets, and issues to GitLab - 6 upvotes, $0
  234. Attacker can delete (and read) private project webhooks to GitLab - 6 upvotes, $0
  235. GFM renderer leaks external issue tracker URL of private project to GitLab - 6 upvotes, $0
  236. CSRF-Token leak by request forgery to GitLab - 6 upvotes, $0
  237. Cookie bomb to GitLab - 6 upvotes, $0
  238. Double linking cause XSS (but blokeced by CSP in gitlab.com) to GitLab - 6 upvotes, $0
  239. Stored-XSS in merge requests to GitLab - 6 upvotes, $0
  240. Found Origin IP's lead to access to gitlab to GitLab - 6 upvotes, $0
  241. Dependecy Confusion via Lookup Request Forwarding to PyPi.org to GitLab - 6 upvotes, $0
  242. Confidential issues leaked in public projects when attached to milestone to GitLab - 5 upvotes, $0
  243. [Textile] XSS in project README files to GitLab - 5 upvotes, $0
  244. Gitlab.com is vulnerable to reverse tabnabbing via AsciiDoc links. (#3) to GitLab - 5 upvotes, $0
  245. Guests Will Disclose the Private Project Full Activity Via Project Activity Feeds to GitLab - 5 upvotes, $0
  246. Project Milestones Disclosed Via Groups When the Victim disabled milestones access in project settings to GitLab - 5 upvotes, $0
  247. Members from parent group keep their access level on a subgroup transfer and are invisible to GitLab - 5 upvotes, $0
  248. Arbitrary escape sequence injection in docker-machine from worker nodes to GitLab - 5 upvotes, $0
  249. Initial mirror user can be assigned by other user even if the mirror was removed to GitLab - 4 upvotes, $3000
  250. [Repository Import] Open Redirect via "continue[to]" parameter to GitLab - 4 upvotes, $0
  251. Open redirect to GitLab - 4 upvotes, $0
  252. SSRF via git Repo by URL Abuse to GitLab - 3 upvotes, $0
  253. Email notification about login email changed is not received when using verified linked email address to GitLab - 3 upvotes, $0
  254. Lack of validation before assigning custom domain names leading to abuse of GitLab pages service to GitLab - 2 upvotes, $0
  255. Use of Ruby Forwardable module and runtime meta-programming may introduce vulnerabilities to GitLab - 2 upvotes, $0
  256. No Restriction on password to GitLab - 2 upvotes, $0
  257. Missing/Breach of Internal Security Boundary - Access to Job Queue Results in Remote Code Execution to GitLab - 0 upvotes, $0