CVE-2019-10114
- EPSS 0.28%
- Veröffentlicht 16.05.2019 15:29:00
- Zuletzt bearbeitet 21.11.2024 04:18:26
An Information Exposure issue (issue 2 of 2) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. During the OAuth authentication process, the application attempts to validate a para...
CVE-2019-10115
- EPSS 0.17%
- Veröffentlicht 16.05.2019 15:29:00
- Zuletzt bearbeitet 21.11.2024 04:18:26
An Insecure Permissions issue (issue 2 of 3) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. The GitLab Releases feature could allow guest users access to private information li...
CVE-2019-10108
- EPSS 0.16%
- Veröffentlicht 15.05.2019 20:29:00
- Zuletzt bearbeitet 21.11.2024 04:18:25
An Incorrect Access Control (issue 1 of 2) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. It allowed non-members of a private project/group to add and read labels.
CVE-2019-10109
- EPSS 0.17%
- Veröffentlicht 15.05.2019 20:29:00
- Zuletzt bearbeitet 21.11.2024 04:18:25
An Information Exposure issue (issue 1 of 2) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. EXIF geolocation data were not removed from images when uploaded to GitLab. As a res...
CVE-2019-10110
- EPSS 0.12%
- Veröffentlicht 15.05.2019 20:29:00
- Zuletzt bearbeitet 21.11.2024 04:18:25
An Insecure Permissions issue (issue 1 of 3) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. The "move issue" feature may allow a user to create projects under any namespace on ...
CVE-2019-10111
- EPSS 0.11%
- Veröffentlicht 15.05.2019 20:29:00
- Zuletzt bearbeitet 21.11.2024 04:18:25
An issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. It allows persistent XSS in the merge request "resolve conflicts" page.
CVE-2019-10640
- EPSS 0.21%
- Veröffentlicht 15.05.2019 19:29:00
- Zuletzt bearbeitet 21.11.2024 04:19:38
An issue was discovered in GitLab Community and Enterprise Edition before 11.7.10, 11.8.x before 11.8.6, and 11.9.x before 11.9.4. A regex input validation issue for the .gitlab-ci.yml refs value allows Uncontrolled Resource Consumption.
CVE-2019-11000
- EPSS 0.61%
- Veröffentlicht 10.05.2019 20:29:00
- Zuletzt bearbeitet 21.11.2024 04:20:19
An issue was discovered in GitLab Enterprise Edition before 11.7.11, 11.8.x before 11.8.7, and 11.9.x before 11.9.7. It allows Information Disclosure.
CVE-2018-18643
- EPSS 0.12%
- Veröffentlicht 25.04.2019 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:56:17
GitLab CE & EE 11.2 and later and before 11.5.0-rc12, 11.4.6, and 11.3.10 have Persistent XSS.
CVE-2018-19359
- EPSS 0.34%
- Veröffentlicht 25.04.2019 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:57:48
GitLab Community and Enterprise Edition 8.9 and later and before 11.5.0-rc12, 11.4.6, and 11.3.10 has Incorrect Access Control.