GitLab / Gitlab Ce/ee
18 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2020-26408 | A limited information disclosure vulnerability exists in Gitlab CE/EE from >= 12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2 that allows an attacker… | MEDIUM | 5.3 | Dec 11, 2020 |
| CVE-2020-13357 | An issue was discovered in Gitlab CE/EE versions >= 13.1 to <13.4.7, >= 13.5 to <13.5.5, and >= 13.6 to <13.6.2 allowed an unauthorized user to access the user… | MEDIUM | 4.3 | Dec 11, 2020 |
| CVE-2020-26413 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 13.6.2. Information disclosure via GraphQL results in user email… | MEDIUM | 5.3 | Dec 11, 2020 |
| CVE-2020-26417 | Information disclosure via GraphQL in GitLab CE/EE 13.1 and later exposes private group and project membership. This affects versions >=13.6 to <13.6.2, >=13.5… | MEDIUM | 5.3 | Dec 11, 2020 |
| CVE-2020-26409 | A DOS vulnerability exists in Gitlab CE/EE >=10.3, <13.4.7,>=13.5, <13.5.5,>=13.6, <13.6.2 that allows an attacker to trigger uncontrolled resource by bypassin… | MEDIUM | 6.5 | Dec 11, 2020 |
| CVE-2020-26407 | A XSS vulnerability exists in Gitlab CE/EE from 12.4 before 13.4.7, 13.5 before 13.5.5, and 13.6 before 13.6.2 that allows an attacker to perform cross-site sc… | MEDIUM | 5.5 | Dec 10, 2020 |
| CVE-2020-13359 | The Terraform API in GitLab CE/EE 12.10+ exposed the object storage signed URL on the delete operation allowing a malicious project maintainer to overwrite the… | HIGH | 7.6 | Nov 18, 2020 |
| CVE-2020-13356 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.8.9. A specially crafted request could bypass Multipart protection and read… | HIGH | 8.2 | Nov 18, 2020 |
| CVE-2020-13355 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.14. A path traversal is found in LFS Upload that allows attacker to overwri… | HIGH | 8.1 | Nov 18, 2020 |
| CVE-2020-26405 | Path traversal vulnerability in package upload functionality in GitLab CE/EE starting from 12.8 allows an attacker to save packages in arbitrary locations. Aff… | HIGH | 7.1 | Nov 17, 2020 |
| CVE-2020-13350 | CSRF in runner administration page in all versions of GitLab CE/EE allows an attacker who's able to target GitLab instance administrators to pause/resume runne… | MEDIUM | 4.3 | Nov 17, 2020 |
| CVE-2020-13351 | Insufficient permission checks in scheduled pipeline API in GitLab CE/EE 13.0+ allows an attacker to read variable names and values for scheduled pipelines on… | MEDIUM | 6.5 | Nov 17, 2020 |
| CVE-2020-13354 | A potential DOS vulnerability was discovered in GitLab CE/EE starting with version 12.6. The container registry name check could cause exponential number of ba… | MEDIUM | 4.3 | Nov 17, 2020 |
| CVE-2020-13352 | Private group info is leaked leaked in GitLab CE/EE version 10.2 and above, when the project is moved from private to public group. Affected versions are: >=10… | MEDIUM | 5.3 | Nov 17, 2020 |
| CVE-2020-13358 | A vulnerability in the internal Kubernetes agent api in GitLab CE/EE version 13.3 and above allows unauthorized access to private projects. Affected versions a… | MEDIUM | 5.5 | Nov 17, 2020 |
| CVE-2019-15578 | An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE). The path of a private proj… | MEDIUM | 5.3 | Jan 28, 2020 |
| CVE-2019-15579 | An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) where the assignee(s) of a… | MEDIUM | 5.3 | Jan 28, 2020 |
| CVE-2019-5465 | An information disclosure issue was discovered in GitLab CE/EE 8.14 and later, by using the move issue feature which could result in disclosure of the newly cr… | MEDIUM | 4.3 | Jan 28, 2020 |
| CVE-2019-15583 | An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE). When an issue was moved to… | HIGH | 7.5 | Jan 28, 2020 |
| CVE-2019-5464 | A flawed DNS rebinding protection issue was discovered in GitLab CE/EE 10.2 and later in the `url_blocker.rb` which could result in SSRF where the library is u… | CRITICAL | 9.8 | Jan 28, 2020 |
| CVE-2019-15585 | Improper authentication exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) in the GitLab SAML integratio… | CRITICAL | 9.8 | Jan 28, 2020 |
| CVE-2019-15586 | A XSS exists in Gitlab CE/EE < 12.1.10 in the Mermaid plugin. | MEDIUM | 6.1 | Jan 28, 2020 |
Showing 1 to 18 of 18 CVEs