Directory Traversal to Arbitrary File Read
Account Takeover Through Expired Link
Server Side Request Forgery Through Deprecated Service
Group Two-Factor Authentication Requirement Bypass
Stored XSS in Merge Request Pages
Stored XSS in Merge Request Submission Form
Stored XSS in File View
Stored XSS in Grafana Integration
Contribution Analytics Exposed to Non-members
Incorrect Access Control in Docker Registry via Deploy Tokens
Denial of Service via Permission Checks
Denial of Service in Design For Public Issue
Incorrect Access Control via LFS Import
Unescaped HTML in Header
Private Merge Request Titles Leaked via Widget
Project Namespace Exposed via Vulnerability Feedback Endpoint
Denial of Service Through Recursive Requests
Project Authorization Not Being Updated
Incorrect Permission Level For Group Invites
Disclosure of Private Group Epic Information
User IP Address Exposed via Badge images