Gitlab

GitLab

1474 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.16%
  • Veröffentlicht 17.02.2020 15:15:11
  • Zuletzt bearbeitet 21.11.2024 05:39:27

In GitLab Enterprise Edition (EE) 12.5.0 through 12.7.5, sharing a group with a group could grant project access to unauthorized users.

  • EPSS 1.1%
  • Veröffentlicht 17.02.2020 14:15:11
  • Zuletzt bearbeitet 21.11.2024 04:23:39

Unauthorized Access to the Container Registry of other groups was discovered in GitLab Enterprise 12.0.0-pre. In other words, authenticated remote attackers can read Docker registries of other groups. When a legitimate user changes the path of a grou...

  • EPSS 1.04%
  • Veröffentlicht 14.02.2020 22:15:10
  • Zuletzt bearbeitet 21.11.2024 04:29:05

GitLab 12.2.2 and below contains a security vulnerability that allows a guest user in a private project to see the merge request ID associated to an issue via the activity timeline.

  • EPSS 0.82%
  • Veröffentlicht 14.02.2020 22:15:10
  • Zuletzt bearbeitet 21.11.2024 04:29:05

GitLab 11.8 and later contains a security vulnerability that allows a user to obtain details of restricted pipelines via the merge request endpoint.

  • EPSS 1.17%
  • Veröffentlicht 05.02.2020 17:15:10
  • Zuletzt bearbeitet 21.11.2024 05:36:15

An issue was discovered in GitLab EE 11.3 and later. A GitLab Workhorse bypass could lead to package and file disclosure via request smuggling.

  • EPSS 0.69%
  • Veröffentlicht 05.02.2020 16:15:12
  • Zuletzt bearbeitet 21.11.2024 05:38:06

GitLab EE 11.0 and later through 12.7.2 allows XSS.

  • EPSS 0.9%
  • Veröffentlicht 05.02.2020 16:15:12
  • Zuletzt bearbeitet 21.11.2024 05:38:07

GitLab EE 12.2 has Insecure Permissions (issue 2 of 2).

  • EPSS 0.88%
  • Veröffentlicht 05.02.2020 16:15:12
  • Zuletzt bearbeitet 21.11.2024 05:38:07

GitLab through 12.7.2 allows XSS.

  • EPSS 0.93%
  • Veröffentlicht 05.02.2020 16:15:12
  • Zuletzt bearbeitet 21.11.2024 05:38:07

GitLab EE 10.1 through 12.7.2 allows Information Disclosure.

  • EPSS 0.93%
  • Veröffentlicht 05.02.2020 16:15:12
  • Zuletzt bearbeitet 21.11.2024 05:38:07

GitLab EE 12.4 and later through 12.7.2 has Incorrect Access Control.