CVE-2019-15584
- EPSS 1.2%
- Veröffentlicht 20.12.2019 22:15:11
- Zuletzt bearbeitet 21.11.2024 04:29:04
A denial of service exists in gitlab <v12.3.2, <v12.2.6, and <v12.1.10 that would let an attacker bypass input validation in markdown fields take down the affected page.
CVE-2019-5469
- EPSS 0.77%
- Veröffentlicht 18.12.2019 21:15:14
- Zuletzt bearbeitet 21.11.2024 04:44:59
An IDOR vulnerability exists in GitLab <v12.1.2, <v12.0.4, and <v11.11.6 that allowed uploading files from project archive to replace other users files potentially allowing an attacker to replace project binaries or other uploaded assets.
CVE-2019-5486
- EPSS 1.51%
- Veröffentlicht 18.12.2019 21:15:14
- Zuletzt bearbeitet 21.11.2024 04:45:01
A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.10 in the Salesforce login integration that could be used by an attacker to create an account that bypassed domain restrictions and email verification require...
CVE-2019-5487
- EPSS 1.39%
- Veröffentlicht 18.12.2019 21:15:14
- Zuletzt bearbeitet 21.11.2024 04:45:01
An improper access control vulnerability exists in Gitlab EE <v12.3.3, <v12.2.7, & <v12.1.13 that allowed the group search feature with Elasticsearch to return private code, merge requests and commits.
CVE-2019-15589
- EPSS 1.05%
- Veröffentlicht 18.12.2019 21:15:12
- Zuletzt bearbeitet 21.11.2024 04:29:04
An improper access control vulnerability exists in Gitlab <v12.3.2, <v12.2.6, <v12.1.12 which would allow a blocked user would be able to use GIT clone and pull if he had obtained a CI/CD token before.
CVE-2019-15591
- EPSS 1.15%
- Veröffentlicht 18.12.2019 21:15:12
- Zuletzt bearbeitet 21.11.2024 04:29:05
An improper access control vulnerability exists in GitLab <12.3.3 that allows an attacker to obtain container and dependency scanning reports through the merge request widget even though public pipelines were disabled.
CVE-2019-15575
- EPSS 2.41%
- Veröffentlicht 18.12.2019 21:15:11
- Zuletzt bearbeitet 21.11.2024 04:29:03
A command injection exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to inject commands via the API through the blobs scope.
CVE-2019-15576
- EPSS 1.85%
- Veröffentlicht 18.12.2019 21:15:11
- Zuletzt bearbeitet 21.11.2024 04:29:03
An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to view private system notes from a GraphQL endpoint.
CVE-2019-15577
- EPSS 0.66%
- Veröffentlicht 18.12.2019 21:15:11
- Zuletzt bearbeitet 21.11.2024 04:29:03
An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed project milestones to be disclosed via groups browsing.
CVE-2019-15580
- EPSS 1.14%
- Veröffentlicht 18.12.2019 21:15:11
- Zuletzt bearbeitet 21.11.2024 04:29:03
An information exposure vulnerability exists in gitlab.com <v12.3.2, <v12.2.6, and <v12.1.10 when using the blocking merge request feature, it was possible for an unauthenticated user to see the head pipeline data of a public project even though pipe...