CVE-2019-12433
- EPSS 0.07%
- Veröffentlicht 10.03.2020 14:15:11
- Zuletzt bearbeitet 21.11.2024 04:22:50
An issue was discovered in GitLab Community and Enterprise Edition 11.7 through 11.11. It has Improper Input Validation. Restricted visibility settings allow creating internal projects in private groups, leading to multiple permission issues.
CVE-2019-12434
- EPSS 0.07%
- Veröffentlicht 10.03.2020 14:15:11
- Zuletzt bearbeitet 21.11.2024 04:22:50
An issue was discovered in GitLab Community and Enterprise Edition 10.6 through 11.11. Users could guess the URL slug of private projects through the contrast of the destination URLs of issues linked in comments. It allows Information Disclosure.
CVE-2020-8113
- EPSS 0.18%
- Veröffentlicht 06.03.2020 18:15:11
- Zuletzt bearbeitet 21.11.2024 05:38:19
GitLab 10.7 and later through 12.7.2 has Incorrect Access Control.
CVE-2020-8795
- EPSS 0.08%
- Veröffentlicht 17.02.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 05:39:27
In GitLab Enterprise Edition (EE) 12.5.0 through 12.7.5, sharing a group with a group could grant project access to unauthorized users.
CVE-2019-12825
- EPSS 0.06%
- Veröffentlicht 17.02.2020 14:15:11
- Zuletzt bearbeitet 21.11.2024 04:23:39
Unauthorized Access to the Container Registry of other groups was discovered in GitLab Enterprise 12.0.0-pre. In other words, authenticated remote attackers can read Docker registries of other groups. When a legitimate user changes the path of a grou...
CVE-2019-15592
- EPSS 0.74%
- Veröffentlicht 14.02.2020 22:15:10
- Zuletzt bearbeitet 21.11.2024 04:29:05
GitLab 12.2.2 and below contains a security vulnerability that allows a guest user in a private project to see the merge request ID associated to an issue via the activity timeline.
CVE-2019-15594
- EPSS 0.34%
- Veröffentlicht 14.02.2020 22:15:10
- Zuletzt bearbeitet 21.11.2024 04:29:05
GitLab 11.8 and later contains a security vulnerability that allows a user to obtain details of restricted pipelines via the merge request endpoint.
CVE-2020-6833
- EPSS 0.08%
- Veröffentlicht 05.02.2020 17:15:10
- Zuletzt bearbeitet 21.11.2024 05:36:15
An issue was discovered in GitLab EE 11.3 and later. A GitLab Workhorse bypass could lead to package and file disclosure via request smuggling.
CVE-2020-7971
- EPSS 0.1%
- Veröffentlicht 05.02.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:38:06
GitLab EE 11.0 and later through 12.7.2 allows XSS.
CVE-2020-7972
- EPSS 0.05%
- Veröffentlicht 05.02.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:38:07
GitLab EE 12.2 has Insecure Permissions (issue 2 of 2).