Skip to main content

Vendor archive

gitlab CVEs

Beta · best-effort

1,422 CVEs tagged to vendor gitlab57 Critical, 295 High, 889 Medium, 180 Low, 1 Unrated.

CVE-2019-15726

Published Sep 16, 2019

An issue was discovered in GitLab Community and Enterprise Edition through 12.2.1. Embedded images and media files in markdown could be pointed to an arbitrary server, which would…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-15725

Published Sep 16, 2019

An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1. An IDOR in the epic notes API that could result in disclosure of private milestones, labels…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-15724

Published Sep 16, 2019

An issue was discovered in GitLab Community and Enterprise Edition 11.10 through 12.2.1. Label descriptions are vulnerable to HTML injection.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-15723

Published Sep 16, 2019

An issue was discovered in GitLab Community and Enterprise Edition 11.9.x and 11.10.x before 11.10.1. Merge requests created by email could be used to bypass push rules in certain…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-15722

Published Sep 16, 2019

An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.2.1. Particular mathematical expressions in GitLab Markdown can exhaust client resources.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-15721

Published Sep 16, 2019

An issue was discovered in GitLab Community and Enterprise Edition 10.8 through 12.2.1. An internal endpoint unintentionally allowed group maintainers to view and edit group runne…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-16170

Published Sep 16, 2019

An issue was discovered in GitLab Enterprise Edition 11.x and 12.x before 12.0.9, 12.1.x before 12.1.9, and 12.2.x before 12.2.5. It has Incorrect Access Control.

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2019-7176

Published Sep 9, 2019

An issue was discovered in GitLab Community and Enterprise Edition 8.x (starting in 8.9), 9.x, 10.x, and 11.x before 11.5.9, 11.6.x before 11.6.7, and 11.7.x before 11.7.2. It has…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2019-6791

Published Sep 9, 2019

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control (issue 3 of 3). W…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-6997

Published Sep 9, 2019

An issue was discovered in GitLab Community and Enterprise Edition 10.x (starting in 10.7) and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-6996

Published Sep 9, 2019

An issue was discovered in GitLab Enterprise Edition 10.x (starting in 10.6) and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Contro…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-6995

Published Sep 9, 2019

An issue was discovered in GitLab Community and Enterprise Edition 8.x, 9.x, 10.x, and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-6960

Published Sep 9, 2019

An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Contr…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-6795

Published Sep 9, 2019

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Insufficient Visual Distinction of Homogly…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-6794

Published Sep 9, 2019

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Information Disclosure (issue 5 of 6).…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-6793

Published Sep 9, 2019

An issue was discovered in GitLab Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. The Jira integration feature is vulnerable to an unauthenticate…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2019-6792

Published Sep 9, 2019

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Path Disclosure. When an error is encou…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-6789

Published Sep 9, 2019

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Information Disclosure (issue 4 of 6).…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-6788

Published Sep 9, 2019

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Information Disclosure (issue 3 of 6).…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-6786

Published Sep 9, 2019

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control (issue 1 of 3). T…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-6785

Published Sep 9, 2019

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Denial of Service. Inputting an overly…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-6784

Published Sep 9, 2019

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows XSS (issue 1 of 2). Markdown fields con…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-6783

Published Sep 9, 2019

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. GitLab Pages contains a directory traversal vulne…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-6782

Published Sep 9, 2019

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Information Disclosure (issue 1 of 6).…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-11605

Published Sep 9, 2019

An issue was discovered in GitLab Community and Enterprise Edition 11.8.x before 11.8.10, 11.9.x before 11.9.11, and 11.10.x before 11.10.3. It allows Information Disclosure. A sm…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1,251-1,275 of 1,422 CVEsPage 51 of 57