CVE-2019-14942
- EPSS 0.46%
- Veröffentlicht 16.04.2023 00:15:07
- Zuletzt bearbeitet 06.02.2025 17:15:10
An issue was discovered in GitLab Community and Enterprise Edition before 11.11.8, 12 before 12.0.6, and 12.1 before 12.1.6. Cookies for GitLab Pages (which have access control) could be sent over cleartext HTTP.
CVE-2019-14944
- EPSS 1.57%
- Veröffentlicht 16.04.2023 00:15:07
- Zuletzt bearbeitet 06.02.2025 17:15:11
An issue was discovered in GitLab Community and Enterprise Edition before 11.11.8, 12 before 12.0.6, and 12.1 before 12.1.6. Gitaly allows injection of command-line flags. This sometimes leads to privilege escalation or remote code execution.
CVE-2018-15472
- EPSS 0.72%
- Veröffentlicht 15.04.2023 23:15:13
- Zuletzt bearbeitet 10.02.2025 16:15:32
An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. The diff formatter using rouge can block for a long time in Sidekiq jobs without any timeout.
CVE-2018-17449
- EPSS 0.84%
- Veröffentlicht 15.04.2023 23:15:13
- Zuletzt bearbeitet 07.02.2025 17:15:11
An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Remote attackers could obtain sensitive information about issues, comments, and project titles via events API insecure d...
CVE-2018-17450
- EPSS 0.44%
- Veröffentlicht 15.04.2023 23:15:13
- Zuletzt bearbeitet 06.02.2025 21:15:10
An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Server-Side Request Forgery (SSRF) via the Kubernetes integration, leading (for example) to disclosure of a GCP...
CVE-2018-17451
- EPSS 0.32%
- Veröffentlicht 15.04.2023 23:15:13
- Zuletzt bearbeitet 06.02.2025 21:15:11
An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Cross Site Request Forgery (CSRF) in the Slack integration for issuing slash commands.
CVE-2018-17452
- EPSS 0.74%
- Veröffentlicht 15.04.2023 23:15:13
- Zuletzt bearbeitet 06.02.2025 21:15:11
An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Server-Side Request Forgery (SSRF) via a loopback address to the validate_localhost function in url_blocker.rb.
CVE-2018-17453
- EPSS 0.52%
- Veröffentlicht 15.04.2023 23:15:13
- Zuletzt bearbeitet 06.02.2025 21:15:11
An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Attackers may have been able to obtain sensitive access-token data from Sentry logs via the GRPC::Unknown exception.
CVE-2018-17454
- EPSS 0.4%
- Veröffentlicht 15.04.2023 23:15:13
- Zuletzt bearbeitet 06.02.2025 21:15:11
An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is stored XSS on the issue details screen.
CVE-2018-17455
- EPSS 0.62%
- Veröffentlicht 15.04.2023 23:15:13
- Zuletzt bearbeitet 06.02.2025 21:15:11
An issue was discovered in GitLab Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Attackers could obtain sensitive information about group names, avatars, LDAP settings, and descriptions via an insecure direct object...