CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Vendor: gitlab
1,044 result(s) · page 35 of 53
CVE-2020-13356
HIGH

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.8.9. A specially crafted request could bypass Multipart protection and read files in certain spe...

CVSS 8.2 Gitlab gitlab 2020-11-19
CVE-2020-13359
HIGH

The Terraform API in GitLab CE/EE 12.10+ exposed the object storage signed URL on the delete operation allowing a malicious project maintainer to overwrite the Terraform state, byp...

CVSS 7.6 Gitlab gitlab 2020-11-19
CVE-2020-13355
HIGH

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.14. A path traversal is found in LFS Upload that allows attacker to overwrite certain specific p...

CVSS 8.1 Gitlab gitlab 2020-11-19
CVE-2020-26405
HIGH

Path traversal vulnerability in package upload functionality in GitLab CE/EE starting from 12.8 allows an attacker to save packages in arbitrary locations. Affected versions are >=...

CVSS 7.1 Gitlab gitlab 2020-11-17
CVE-2020-13348
MEDIUM

An issue has been discovered in GitLab EE affecting all versions starting from 10.2. Required CODEOWNERS approval could be bypassed by targeting a branch without the CODEOWNERS fil...

CVSS 5.7 Gitlab gitlab 2020-11-17
CVE-2020-13351
MEDIUM

Insufficient permission checks in scheduled pipeline API in GitLab CE/EE 13.0+ allows an attacker to read variable names and values for scheduled pipelines on projects visible to t...

CVSS 6.5 Gitlab gitlab 2020-11-17
CVE-2020-13358
MEDIUM

A vulnerability in the internal Kubernetes agent api in GitLab CE/EE version 13.3 and above allows unauthorized access to private projects. Affected versions are: >=13.4, <13.4.5,>...

CVSS 5.5 Gitlab gitlab 2020-11-17
CVE-2020-13352
MEDIUM

Private group info is leaked leaked in GitLab CE/EE version 10.2 and above, when the project is moved from private to public group. Affected versions are: >=10.2, <13.3.9,>=13.4, <...

CVSS 5.3 Gitlab gitlab 2020-11-17
CVE-2020-26406
MEDIUM

Certain SAST CiConfiguration information could be viewed by unauthorized users in GitLab EE starting with 13.3. This information was exposed through GraphQL to non-members of publi...

CVSS 5.3 Gitlab gitlab 2020-11-17
CVE-2020-13327
HIGH

An issue has been discovered in GitLab Runner affecting all versions starting from 13.4.0 before 13.4.2, all versions starting from 13.3.0 before 13.3.7, all versions starting from...

CVSS 7.5 Gitlab runner 2020-10-22
CVE-2020-13340
HIGH

An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2: Stored XSS in CI Job Log

CVSS 8.7 Gitlab gitlab 2020-10-08
CVE-2020-13339
MEDIUM

An issue has been discovered in GitLab affecting all versions before 13.2.10, 13.3.7 and 13.4.2: XSS in SVG File Preview. Overall impact is limited due to the current user only bei...

CVSS 6.5 Gitlab gitlab 2020-10-08
CVE-2020-13347
CRITICAL

A command injection vulnerability was discovered in Gitlab runner versions prior to 13.2.4, 13.3.2 and 13.4.1. When the runner is configured on a Windows system with a docker execu...

CVSS 9.1 Gitlab gitlab 2020-10-07
CVE-2020-13334
HIGH

In GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, improper authorization checks allow a non-member of a project/group to change the confidentiality attribute of issue via mut...

CVSS 7.5 Gitlab gitlab 2020-10-07
CVE-2020-13346
MEDIUM

Membership changes are not reflected in ToDo subscriptions in GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, allowing guest users to access confidential issues through API.

CVSS 6.5 Gitlab gitlab 2020-10-07
CVE-2020-13343
HIGH

An issue has been discovered in GitLab affecting all versions starting from 11.2. Unauthorized Users Can View Custom Project Template

CVSS 8.8 Gitlab gitlab 2020-10-06
CVE-2020-13345
MEDIUM

An issue has been discovered in GitLab affecting all versions starting from 10.8. Reflected XSS on Multiple Routes

CVSS 5.4 Gitlab gitlab 2020-10-06
CVE-2020-13338
MEDIUM

An issue has been discovered in GitLab affecting versions prior to 12.10.13, 13.0.8, 13.1.2. A stored cross-site scripting vulnerability was discovered when editing references.

CVSS 5.4 Gitlab gitlab 2020-10-02
CVE-2020-13331
MEDIUM

An issue has been discovered in GitLab affecting versions prior to 12.10.13. GitLab was vulnerable to a stored XSS by in the Wiki pasges.

CVSS 5.4 Gitlab gitlab 2020-09-30
CVE-2020-13296
HIGH

An issue has been discovered in GitLab affecting versions >=10.7 <13.0.14, >=13.1.0 <13.1.8, >=13.2.0 <13.2.6. Improper Access Control for Deploy Tokens

CVSS 8.8 Gitlab gitlab 2020-09-30
1 33 34 35 36 37 53
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.