Skip to main content

Vendor archive

gitlab CVEs

Beta · best-effort

1,422 CVEs tagged to vendor gitlab57 Critical, 295 High, 889 Medium, 180 Low, 1 Unrated.

CVE-2018-20494

Published Dec 30, 2019

An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-20493

Published Dec 30, 2019

An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20491

Published Dec 30, 2019

An issue was discovered in GitLab Enterprise Edition 11.3.x and 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows XSS.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20490

Published Dec 30, 2019

An issue was discovered in GitLab Community and Enterprise Edition 11.2.x through 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows XSS.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20489

Published Dec 30, 2019

An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20488

Published Dec 30, 2019

An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows Information Exposure.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20492

Published Dec 26, 2019

An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control (issue 2 of 6).

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-15584

Published Dec 20, 2019

A denial of service exists in gitlab <v12.3.2, <v12.2.6, and <v12.1.10 that would let an attacker bypass input validation in markdown fields take down the affected page.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-5487

Published Dec 18, 2019

An improper access control vulnerability exists in Gitlab EE <v12.3.3, <v12.2.7, & <v12.1.13 that allowed the group search feature with Elasticsearch to return private code, merge…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-5486

Published Dec 18, 2019

A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.10 in the Salesforce login integration that could be used by an attacker to create an a…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-5469

Published Dec 18, 2019

An IDOR vulnerability exists in GitLab <v12.1.2, <v12.0.4, and <v11.11.6 that allowed uploading files from project archive to replace other users files potentially allowing an att…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-15591

Published Dec 18, 2019

An improper access control vulnerability exists in GitLab <12.3.3 that allows an attacker to obtain container and dependency scanning reports through the merge request widget even…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-15589

Published Dec 18, 2019

An improper access control vulnerability exists in Gitlab <v12.3.2, <v12.2.6, <v12.1.12 which would allow a blocked user would be able to use GIT clone and pull if he had obtained…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-15580

Published Dec 18, 2019

An information exposure vulnerability exists in gitlab.com <v12.3.2, <v12.2.6, and <v12.1.10 when using the blocking merge request feature, it was possible for an unauthenticated…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-15577

Published Dec 18, 2019

An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed project milestones to be disclosed via groups browsing.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-15576

Published Dec 18, 2019

An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to view private system notes from a GraphQL endpoint.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-15575

Published Dec 18, 2019

A command injection exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to inject commands via the API through the blobs scope.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-18456

Published Nov 26, 2019

An issue was discovered in GitLab Community and Enterprise Edition 8.17 through 12.4 in the Search feature provided by Elasticsearch integration.. It has Insecure Permissions (iss…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-18455

Published Nov 26, 2019

An issue was discovered in GitLab Community and Enterprise Edition 11 through 12.4 when building Nested GraphQL queries. It has a large or infinite loop.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-18454

Published Nov 26, 2019

An issue was discovered in GitLab Community and Enterprise Edition 10.5 through 12.4 in link validation for RDoc wiki pages feature. It has XSS.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-18453

Published Nov 26, 2019

An issue was discovered in GitLab Community and Enterprise Edition 11.6 through 12.4 in the add comments via email feature. It has Insecure Permissions.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-18452

Published Nov 26, 2019

An issue was discovered in GitLab Community and Enterprise Edition 11.3 through 12.4 when moving an issue to a public project from a private one. It has Insecure Permissions.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-18451

Published Nov 26, 2019

An issue was discovered in GitLab Community and Enterprise Edition 10.7.4 through 12.4 in the InternalRedirect filtering feature. It has an Open Redirect.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-18450

Published Nov 26, 2019

An issue was discovered in GitLab Community and Enterprise Edition before 12.4 in the Project labels feature. It has Insecure Permissions.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-18449

Published Nov 26, 2019

An issue was discovered in GitLab Community and Enterprise Edition before 12.4 in the autocomplete feature. It has Insecure Permissions (issue 2 of 2).

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1,201-1,225 of 1,422 CVEsPage 49 of 57