Skip to main content

Vendor archive

gitlab CVEs

Beta · best-effort

1,422 CVEs tagged to vendor gitlab57 Critical, 295 High, 889 Medium, 180 Low, 1 Unrated.

CVE-2020-13273

Published Jun 19, 2020

A Denial of Service vulnerability allowed exhausting the system resources in GitLab CE/EE 12.0 and later through 13.0.1

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13272

Published Jun 19, 2020

OAuth flow missing verification checks CE/EE 12.3 and later through 13.0.1 allows unverified user to use OAuth authorization code flow

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13265

Published Jun 19, 2020

User email verification bypass in GitLab CE/EE 12.5 and later through 13.0.1 allows user to bypass email verification

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13262

Published Jun 19, 2020

Client-Side code injection through Mermaid markup in GitLab CE/EE 12.9 and later through 13.0.1 allows a specially crafted Mermaid payload to PUT requests on behalf of other users…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13277

Published Jun 19, 2020

An authorization issue in the mirroring logic allowed read access to private repositories in GitLab CE/EE 10.6 and later through 13.0.5

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13271

Published Jun 10, 2020

A Stored Cross-Site Scripting vulnerability allowed the execution of arbitrary Javascript code in the blobs API in all previous GitLab CE/EE versions through 13.0.1

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13270

Published Jun 10, 2020

Missing permission check on fork relation creation in GitLab CE/EE 11.3 and later through 13.0.1 allows guest users to create a fork relation on restricted public projects via API

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13269

Published Jun 10, 2020

A Reflected Cross-Site Scripting vulnerability allowed the execution of arbitrary Javascript code on the Static Site Editor in GitLab CE/EE 12.10 and later through 13.0.1

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13268

Published Jun 10, 2020

A specially crafted request could be used to confirm the existence of files hosted on object storage services, without disclosing their contents. This vulnerability affects GitLab…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13267

Published Jun 10, 2020

A Stored Cross-Site Scripting vulnerability allowed the execution on Javascript payloads on the Metrics Dashboard in GitLab CE/EE 12.8 and later through 13.0.1

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13266

Published Jun 9, 2020

Insecure authorization in Project Deploy Keys in GitLab CE/EE 12.8 and later through 13.0.1 allows users to update permissions of other users' deploy keys under certain conditions

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-12448

Published May 7, 2020

GitLab EE 12.8 and later allows Exposure of Sensitive Information to an Unauthorized Actor via NuGet.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-12277

Published Apr 29, 2020

GitLab 10.8 through 12.9 has a vulnerability that allows someone to mirror a repository even if the feature is not activated.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-12276

Published Apr 29, 2020

GitLab 9.5.9 through 12.9 is vulnerable to stored XSS in an admin notification feature.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-12275

Published Apr 29, 2020

GitLab 12.6 through 12.9 is vulnerable to a privilege escalation that allows an external user to create a personal snippet through the API.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-11649

Published Apr 22, 2020

An issue was discovered in GitLab CE and EE 8.15 through 12.9.2. Members of a group could still have access after the group is deleted.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-11506

Published Apr 22, 2020

An issue was discovered in GitLab 10.7.0 and later through 12.9.2. A Workhorse bypass could lead to job artifact uploads and file disclosure (Exposure of Sensitive Information) vi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-11505

Published Apr 22, 2020

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) before 12.7.9, 12.8.x before 12.8.9, and 12.9.x before 12.9.3. A Workhorse bypass could lead t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-10981

Published Apr 8, 2020

GitLab EE/CE 9.0 to 12.9 allows a maintainer to modify other maintainers' pipeline trigger descriptions within the same project.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-10980

Published Apr 8, 2020

GitLab EE/CE 8.0.rc1 to 12.9 is vulnerable to a blind SSRF in the FogBugz integration.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-10979

Published Apr 8, 2020

GitLab EE/CE 11.10 to 12.9 is leaking information on restricted CI pipelines metrics to unauthorized users.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-10978

Published Apr 8, 2020

GitLab EE/CE 8.11 to 12.9 is leaking information on Issues opened in a public project and then moved to a private project through Web-UI and GraphQL API.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-10977

Published Apr 8, 2020

GitLab EE/CE 8.5 to 12.9 is vulnerable to a an path traversal when moving an issue between projects.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-10976

Published Apr 8, 2020

GitLab EE/CE 8.17 to 12.9 is vulnerable to information leakage when querying a merge request widget.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1,051-1,075 of 1,422 CVEsPage 43 of 57