2024

2023

2022

2021

2020

2019

CVE-2019-12430 (v3: 8.8) 10 Mar 2020
An issue was discovered in GitLab Community and Enterprise Edition 11.11. A specially crafted payload would allow an authenticated malicious user to execute commands remotely through the repository download feature. It allows Command Injection.
CVE-2019-5485 (v3: 10) 13 Sep 2019
NPM package gitlabhook version 0.0.17 is vulnerable to a Command Injection vulnerability. Arbitrary commands can be injected through the repository name.

2018

2017

2016

2015