Skip to main content

Vendor archive

gitlab CVEs

Beta · best-effort

1,422 CVEs tagged to vendor gitlab57 Critical, 295 High, 889 Medium, 180 Low, 1 Unrated.

CVE-2019-19313

Published Jan 5, 2020

GitLab EE 12.3 through 12.5, 12.4.3, and 12.3.6 allows Denial of Service. Certain characters were making it impossible to create, edit, or view issues and commits.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-19312

Published Jan 5, 2020

GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 has Incorrect Access Control. After a project changed to private, previously forked repositories were still able to get information…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19310

Published Jan 3, 2020

GitLab Enterprise Edition (EE) 9.0 and later through 12.5 allows Information Disclosure.

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19309

Published Jan 3, 2020

GitLab Enterprise Edition (EE) 8.90 and later through 12.5 has Incorrect Access Control.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19263

Published Jan 3, 2020

GitLab Enterprise Edition (EE) 8.2 and later through 12.5 has Insecure Permissions.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19262

Published Jan 3, 2020

GitLab Enterprise Edition (EE) 11.9 and later through 12.5 has Insecure Permissions.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19261

Published Jan 3, 2020

GitLab Enterprise Edition (EE) 6.7 and later through 12.5 allows SSRF.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-19260

Published Jan 3, 2020

GitLab Community Edition (CE) and Enterprise Edition (EE) through 12.5 has Incorrect Access Control (issue 2 of 2).

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19259

Published Jan 3, 2020

GitLab Enterprise Edition (EE) 11.3 and later through 12.5 allows an Insecure Direct Object Reference (IDOR).

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19258

Published Jan 3, 2020

GitLab Enterprise Edition (EE) 10.8 and later through 12.5 has Incorrect Access Control.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19257

Published Jan 3, 2020

GitLab Community Edition (CE) and Enterprise Edition (EE) through 12.5 has Incorrect Access Control (issue 1 of 2).

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19256

Published Jan 3, 2020

GitLab Enterprise Edition (EE) 12.2 and later through 12.5 has Incorrect Access Control.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19255

Published Jan 3, 2020

GitLab Enterprise Edition (EE) 12.3 and later through 12.5 has Incorrect Access Control.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19311

Published Jan 3, 2020

GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 allows XSS in group and profile fields.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19254

Published Jan 3, 2020

GitLab Community Edition (CE) and Enterprise Edition (EE). 9.6 and later through 12.5 has Incorrect Access Control.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19088

Published Jan 3, 2020

Gitlab Enterprise Edition (EE) 11.3 through 12.4.2 allows Directory Traversal.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-19087

Published Jan 3, 2020

Gitlab Enterprise Edition (EE) before 12.5.1 has Insecure Permissions (issue 2 of 2).

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19086

Published Jan 3, 2020

Gitlab Enterprise Edition (EE) before 12.5.1 has Insecure Permissions (issue 1 of 2).

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20507

Published Dec 30, 2019

An issue was discovered in GitLab Enterprise Edition 11.2.x through 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20501

Published Dec 30, 2019

An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20499

Published Dec 30, 2019

An issue was discovered in GitLab Community and Enterprise Edition before 11.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows SSRF.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2018-20498

Published Dec 30, 2019

An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20497

Published Dec 30, 2019

An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows SSRF.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20496

Published Dec 30, 2019

An issue was discovered in GitLab Community and Enterprise Edition 11.2.x through 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows XSS.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20495

Published Dec 30, 2019

An issue was discovered in GitLab Community and Enterprise Edition 11.3.x and 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows Information Exposure.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1,176-1,200 of 1,422 CVEsPage 48 of 57