Skip to main content

Vendor archive

gitlab CVEs

Beta · best-effort

1,422 CVEs tagged to vendor gitlab57 Critical, 295 High, 889 Medium, 180 Low, 1 Unrated.

CVE-2019-5468

Published Jan 28, 2020

An privilege escalation issue was discovered in Gitlab versions < 12.1.2, < 12.0.4, and < 11.11.6 when Mattermost slash commands are used with a blocked account.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-5466

Published Jan 28, 2020

An IDOR was discovered in GitLab CE/EE 11.5 and later that allowed new merge requests endpoint to disclose label names.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-5465

Published Jan 28, 2020

An information disclosure issue was discovered in GitLab CE/EE 8.14 and later, by using the move issue feature which could result in disclosure of the newly created issue ID.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-5464

Published Jan 28, 2020

A flawed DNS rebinding protection issue was discovered in GitLab CE/EE 10.2 and later in the `url_blocker.rb` which could result in SSRF where the library is utilized.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-5462

Published Jan 28, 2020

A privilege escalation issue was discovered in GitLab CE/EE 9.0 and later when trigger tokens are not rotated once ownership of them has changed.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-15590

Published Jan 28, 2020

An access control issue exists in < 12.3.5, < 12.2.8, and < 12.1.14 for GitLab Community Edition (CE) and Enterprise Edition (EE) where private merge requests and issues would be…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-15585

Published Jan 28, 2020

Improper authentication exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) in the GitLab SAML integration had a validation i…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-15583

Published Jan 28, 2020

An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE). When an issue was moved to a public project fr…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-15582

Published Jan 28, 2020

An IDOR was discovered in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) that allowed a maintainer to add any private group to a p…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-15581

Published Jan 28, 2020

An IDOR exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) that allowed a project owner or maintainer to see the members of…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-15579

Published Jan 28, 2020

An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) where the assignee(s) of a confidential issue i…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-15578

Published Jan 28, 2020

An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE). The path of a private project, that used to be…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-20144

Published Jan 13, 2020

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 10.8 through 12.6.1. It has Incorrect Access Control.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-20143

Published Jan 13, 2020

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 12.6. It has Incorrect Access Control.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-20142

Published Jan 13, 2020

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 12.3 through 12.6.1. It allows Denial of Service.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-6832

Published Jan 13, 2020

An issue was discovered in GitLab Enterprise Edition (EE) 8.9.0 through 12.6.1. Using the project import feature, it was possible for someone to obtain issues from private project…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-5197

Published Jan 13, 2020

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 5.1 through 12.6.1. It has Incorrect Access Control.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-20148

Published Jan 13, 2020

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 8.13 through 12.6.1. It has Incorrect Access Control.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-20147

Published Jan 13, 2020

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 9.1 through 12.6.1. It has Incorrect Access Control.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-20146

Published Jan 13, 2020

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 11.0 through 12.6. It allows Uncontrolled Resource Consumption.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-20145

Published Jan 13, 2020

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 11.4 through 12.6.1. It has Incorrect Access Control.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19629

Published Jan 5, 2020

In GitLab EE 10.5 through 12.5.3, 12.4.5, and 12.3.8, when transferring a public project to a private group, private code would be disclosed via the Group Search API provided by t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-19628

Published Jan 5, 2020

In GitLab EE 11.3 through 12.5.3, 12.4.5, and 12.3.8, insufficient parameter sanitization for the Maven package registry could lead to privilege escalation and remote code executi…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-19314

Published Jan 5, 2020

GitLab EE 8.4 through 12.5, 12.4.3, and 12.3.6 stored several tokens in plaintext.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1,151-1,175 of 1,422 CVEsPage 47 of 57