CVE-2019-5486
- EPSS 0.04%
- Veröffentlicht 18.12.2019 21:15:14
- Zuletzt bearbeitet 21.11.2024 04:45:01
A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.10 in the Salesforce login integration that could be used by an attacker to create an account that bypassed domain restrictions and email verification require...
CVE-2019-5487
- EPSS 0.35%
- Veröffentlicht 18.12.2019 21:15:14
- Zuletzt bearbeitet 21.11.2024 04:45:01
An improper access control vulnerability exists in Gitlab EE <v12.3.3, <v12.2.7, & <v12.1.13 that allowed the group search feature with Elasticsearch to return private code, merge requests and commits.
CVE-2019-15589
- EPSS 0.11%
- Veröffentlicht 18.12.2019 21:15:12
- Zuletzt bearbeitet 21.11.2024 04:29:04
An improper access control vulnerability exists in Gitlab <v12.3.2, <v12.2.6, <v12.1.12 which would allow a blocked user would be able to use GIT clone and pull if he had obtained a CI/CD token before.
CVE-2019-15591
- EPSS 0.21%
- Veröffentlicht 18.12.2019 21:15:12
- Zuletzt bearbeitet 21.11.2024 04:29:05
An improper access control vulnerability exists in GitLab <12.3.3 that allows an attacker to obtain container and dependency scanning reports through the merge request widget even though public pipelines were disabled.
CVE-2019-15575
- EPSS 2.68%
- Veröffentlicht 18.12.2019 21:15:11
- Zuletzt bearbeitet 21.11.2024 04:29:03
A command injection exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to inject commands via the API through the blobs scope.
CVE-2019-15576
- EPSS 0.57%
- Veröffentlicht 18.12.2019 21:15:11
- Zuletzt bearbeitet 21.11.2024 04:29:03
An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to view private system notes from a GraphQL endpoint.
CVE-2019-15577
- EPSS 0.13%
- Veröffentlicht 18.12.2019 21:15:11
- Zuletzt bearbeitet 21.11.2024 04:29:03
An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed project milestones to be disclosed via groups browsing.
CVE-2019-15580
- EPSS 0.32%
- Veröffentlicht 18.12.2019 21:15:11
- Zuletzt bearbeitet 21.11.2024 04:29:03
An information exposure vulnerability exists in gitlab.com <v12.3.2, <v12.2.6, and <v12.1.10 when using the blocking merge request feature, it was possible for an unauthenticated user to see the head pipeline data of a public project even though pipe...
CVE-2019-18447
- EPSS 0.07%
- Veröffentlicht 26.11.2019 17:15:12
- Zuletzt bearbeitet 21.11.2024 04:33:14
An issue was discovered in GitLab Community and Enterprise Edition before 12.4. It has Insecure Permissions.
CVE-2019-18448
- EPSS 0.09%
- Veröffentlicht 26.11.2019 17:15:12
- Zuletzt bearbeitet 21.11.2024 04:33:14
An issue was discovered in GitLab Community and Enterprise Edition before 12.4. It has Incorrect Access Control.