Gitlab

Gitlab

1222 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.04%
  • Published 18.12.2019 21:15:14
  • Last modified 21.11.2024 04:45:01

A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.10 in the Salesforce login integration that could be used by an attacker to create an account that bypassed domain restrictions and email verification require...

Exploit
  • EPSS 0.35%
  • Published 18.12.2019 21:15:14
  • Last modified 21.11.2024 04:45:01

An improper access control vulnerability exists in Gitlab EE <v12.3.3, <v12.2.7, & <v12.1.13 that allowed the group search feature with Elasticsearch to return private code, merge requests and commits.

Exploit
  • EPSS 0.11%
  • Published 18.12.2019 21:15:12
  • Last modified 21.11.2024 04:29:04

An improper access control vulnerability exists in Gitlab <v12.3.2, <v12.2.6, <v12.1.12 which would allow a blocked user would be able to use GIT clone and pull if he had obtained a CI/CD token before.

Exploit
  • EPSS 0.21%
  • Published 18.12.2019 21:15:12
  • Last modified 21.11.2024 04:29:05

An improper access control vulnerability exists in GitLab <12.3.3 that allows an attacker to obtain container and dependency scanning reports through the merge request widget even though public pipelines were disabled.

Exploit
  • EPSS 2.68%
  • Published 18.12.2019 21:15:11
  • Last modified 21.11.2024 04:29:03

A command injection exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to inject commands via the API through the blobs scope.

Exploit
  • EPSS 0.57%
  • Published 18.12.2019 21:15:11
  • Last modified 21.11.2024 04:29:03

An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to view private system notes from a GraphQL endpoint.

Exploit
  • EPSS 0.13%
  • Published 18.12.2019 21:15:11
  • Last modified 21.11.2024 04:29:03

An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed project milestones to be disclosed via groups browsing.

Exploit
  • EPSS 0.32%
  • Published 18.12.2019 21:15:11
  • Last modified 21.11.2024 04:29:03

An information exposure vulnerability exists in gitlab.com <v12.3.2, <v12.2.6, and <v12.1.10 when using the blocking merge request feature, it was possible for an unauthenticated user to see the head pipeline data of a public project even though pipe...

  • EPSS 0.07%
  • Published 26.11.2019 17:15:12
  • Last modified 21.11.2024 04:33:14

An issue was discovered in GitLab Community and Enterprise Edition before 12.4. It has Insecure Permissions.

  • EPSS 0.09%
  • Published 26.11.2019 17:15:12
  • Last modified 21.11.2024 04:33:14

An issue was discovered in GitLab Community and Enterprise Edition before 12.4. It has Incorrect Access Control.