CVE-2020-8795
- EPSS 1.16%
- Veröffentlicht 17.02.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 05:39:27
In GitLab Enterprise Edition (EE) 12.5.0 through 12.7.5, sharing a group with a group could grant project access to unauthorized users.
CVE-2019-12825
- EPSS 1.1%
- Veröffentlicht 17.02.2020 14:15:11
- Zuletzt bearbeitet 21.11.2024 04:23:39
Unauthorized Access to the Container Registry of other groups was discovered in GitLab Enterprise 12.0.0-pre. In other words, authenticated remote attackers can read Docker registries of other groups. When a legitimate user changes the path of a grou...
CVE-2019-15592
- EPSS 1.04%
- Veröffentlicht 14.02.2020 22:15:10
- Zuletzt bearbeitet 21.11.2024 04:29:05
GitLab 12.2.2 and below contains a security vulnerability that allows a guest user in a private project to see the merge request ID associated to an issue via the activity timeline.
CVE-2019-15594
- EPSS 0.82%
- Veröffentlicht 14.02.2020 22:15:10
- Zuletzt bearbeitet 21.11.2024 04:29:05
GitLab 11.8 and later contains a security vulnerability that allows a user to obtain details of restricted pipelines via the merge request endpoint.
CVE-2020-6833
- EPSS 1.17%
- Veröffentlicht 05.02.2020 17:15:10
- Zuletzt bearbeitet 21.11.2024 05:36:15
An issue was discovered in GitLab EE 11.3 and later. A GitLab Workhorse bypass could lead to package and file disclosure via request smuggling.
CVE-2020-7971
- EPSS 0.69%
- Veröffentlicht 05.02.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:38:06
GitLab EE 11.0 and later through 12.7.2 allows XSS.
CVE-2020-7972
- EPSS 0.9%
- Veröffentlicht 05.02.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:38:07
GitLab EE 12.2 has Insecure Permissions (issue 2 of 2).
CVE-2020-7973
- EPSS 0.88%
- Veröffentlicht 05.02.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:38:07
GitLab through 12.7.2 allows XSS.
CVE-2020-7974
- EPSS 0.93%
- Veröffentlicht 05.02.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:38:07
GitLab EE 10.1 through 12.7.2 allows Information Disclosure.
CVE-2020-7976
- EPSS 0.93%
- Veröffentlicht 05.02.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:38:07
GitLab EE 12.4 and later through 12.7.2 has Incorrect Access Control.