CVE-2019-15738
- EPSS 0.26%
- Veröffentlicht 16.09.2019 18:15:11
- Zuletzt bearbeitet 21.11.2024 04:29:22
An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1. Under certain conditions, merge request IDs were being disclosed via email.
CVE-2019-15739
- EPSS 0.16%
- Veröffentlicht 16.09.2019 18:15:11
- Zuletzt bearbeitet 21.11.2024 04:29:22
An issue was discovered in GitLab Community and Enterprise Edition 8.1 through 12.2.1. Certain areas displaying Markdown were not properly sanitizing some XSS payloads.
CVE-2019-15740
- EPSS 0.26%
- Veröffentlicht 16.09.2019 18:15:11
- Zuletzt bearbeitet 21.11.2024 04:29:22
An issue was discovered in GitLab Community and Enterprise Edition 7.9 through 12.2.1. EXIF Geolocation data was not being removed from certain image uploads.
CVE-2019-15731
- EPSS 0.24%
- Veröffentlicht 16.09.2019 17:15:14
- Zuletzt bearbeitet 21.11.2024 04:29:21
An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1. Non-members were able to comment on merge requests despite the repository being set to allow only project members to do so.
CVE-2019-15732
- EPSS 0.26%
- Veröffentlicht 16.09.2019 17:15:14
- Zuletzt bearbeitet 21.11.2024 04:29:21
An issue was discovered in GitLab Community and Enterprise Edition 12.2 through 12.2.1. The project import API could be used to bypass project visibility restrictions.
CVE-2019-15733
- EPSS 0.14%
- Veröffentlicht 16.09.2019 17:15:14
- Zuletzt bearbeitet 21.11.2024 04:29:21
An issue was discovered in GitLab Community and Enterprise Edition 7.12 through 12.2.1. The specified default branch name could be exposed to unauthorized users.
CVE-2019-15721
- EPSS 0.08%
- Veröffentlicht 16.09.2019 17:15:13
- Zuletzt bearbeitet 21.11.2024 04:29:19
An issue was discovered in GitLab Community and Enterprise Edition 10.8 through 12.2.1. An internal endpoint unintentionally allowed group maintainers to view and edit group runner settings.
CVE-2019-15722
- EPSS 0.3%
- Veröffentlicht 16.09.2019 17:15:13
- Zuletzt bearbeitet 21.11.2024 04:29:19
An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.2.1. Particular mathematical expressions in GitLab Markdown can exhaust client resources.
CVE-2019-15723
- EPSS 0.24%
- Veröffentlicht 16.09.2019 17:15:13
- Zuletzt bearbeitet 21.11.2024 04:29:20
An issue was discovered in GitLab Community and Enterprise Edition 11.9.x and 11.10.x before 11.10.1. Merge requests created by email could be used to bypass push rules in certain situations.
CVE-2019-15724
- EPSS 0.12%
- Veröffentlicht 16.09.2019 17:15:13
- Zuletzt bearbeitet 21.11.2024 04:29:20
An issue was discovered in GitLab Community and Enterprise Edition 11.10 through 12.2.1. Label descriptions are vulnerable to HTML injection.