Gitlab
Top 1K siteProgram Details
- Handle
- gitlab
- Managed
- Yes
Response Metrics
- Response Time
- 3 days
- Bounty Time
- 999 days
- Resolution Time
- 1677 days
Scope (19 targets)
web: 10 other: 9 In Scope
- *.gitlab.net web bounty-eligible
- *.gitlab.org web bounty-eligible
- *.gitlap.com web bounty-eligible
- GitLab for Jira Cloud other bounty-eligible
- Other non-production infrastructure other bounty-eligible
- Your Own GitLab Instance other bounty-eligible
- about.gitlab.com web bounty-eligible
- advisories.gitlab.com web bounty-eligible
- customers.gitlab.com web bounty-eligible
- design.gitlab.com web bounty-eligible
- docs.gitlab.com web bounty-eligible
- gitlab.com web bounty-eligible
- https://gitlab.com/gitlab-org/gitaly other bounty-eligible
- https://gitlab.com/gitlab-org/gitlab other bounty-eligible
- https://gitlab.com/gitlab-org/gitlab-pages other bounty-eligible
- https://gitlab.com/gitlab-org/gitlab-runner other bounty-eligible
- https://gitlab.com/gitlab-org/gitlab-shell other bounty-eligible
- https://gitlab.com/gitlab-org/gitlab-vscode-extension other bounty-eligible
- registry.gitlab.com web bounty-eligible
Out of Scope
*.gitlab-private.org, *.gitlab.cn, *.runway.gitlab.net, *.service-now.com, alerts.gitlab.com, aptly.gitlab.com, dashboards.gitlab.com, federal-support.gitlab.com, forum.gitlab.com, gitlab.biterg.io, gitlabdemo.cloud, gitlabsandbox.net, gitlabtraining.cloud, https://gitlab.com/gitlab-org/cli/, https://gitlab.com/gitlab-org/opstrace/opstrace, https://gitlab.com/gitlab-org/opstrace/opstrace-ui, ir.gitlab.com, levelup.gitlab.com, packages.gitlab.com, partners.gitlab.com, shop.gitlab.com, status.gitlab.com, support.gitlab.com, translate.gitlab.com, us-federal-gitlab.com
Known Exploited Vulnerabilities 5CVEs
1 linked to ransomware campaigns
GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability that allows an unauthenticated user to read arbitrary files due to an improper path confinement and missing authentication enforcement in the repository commits API.
GitLab contains a server-side request forgery (SSRF) vulnerability when requests to the internal network for webhooks are enabled.
GitLab Community and Enterprise Editions contain a server-side request forgery vulnerability which could allow unauthorized external users to perform Server Side Requests via the CI Lint API.
GitLab Community and Enterprise Editions contain an improper access control vulnerability. This allows an attacker to trigger password reset emails to be sent to an unverified email address to ultimately facilitate an account takeover.
GitHub Community and Enterprise Editions that utilize the ability to upload images through GitLab Workhorse are vulnerable to remote code execution. Workhorse passes image file extensions through ExifTool, which improperly validates the image files.