CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Vendor: gitlab
1,044 result(s) · page 37 of 53
CVE-2020-13300
CRITICAL

GitLab CE/EE version 13.3 prior to 13.3.4 was vulnerable to an OAuth authorization scope change without user consent in the middle of the authorization flow.

CVSS 10 Gitlab gitlab 2020-09-14
CVE-2020-13299
HIGH

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. The revocation feature was not revoking all session tokens and one could re-use it to obtain a ...

CVSS 8.1 Gitlab gitlab 2020-09-14
CVE-2020-13284
MEDIUM

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. API Authorization Using Outdated CI Job Token

CVSS 6.5 Gitlab gitlab 2020-09-14
CVE-2020-13289
MEDIUM

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. In certain cases an invalid username could be accepted when 2FA is activated.

CVSS 5.4 Gitlab gitlab 2020-09-14
CVE-2020-13281
MEDIUM

For GitLab before 13.0.12, 13.1.6, 13.2.3 a denial of service exists in the project import feature

CVSS 6.5 Gitlab gitlab 2020-08-13
CVE-2020-13285
MEDIUM

For GitLab before 13.0.12, 13.1.6, 13.2.3 a cross-site scripting (XSS) vulnerability exists in the issue reference number tooltip.

CVSS 5.4 Gitlab gitlab 2020-08-13
CVE-2020-13280
MEDIUM

For GitLab before 13.0.12, 13.1.6, 13.2.3 a memory exhaustion flaw exists due to excessive logging of an invite email error message.

CVSS 6.5 Gitlab gitlab 2020-08-13
CVE-2020-13283
MEDIUM

For GitLab before 13.0.12, 13.1.6, 13.2.3 a cross-site scripting vulnerability exists in the issues list via milestone title.

CVSS 5.4 Gitlab gitlab 2020-08-13
CVE-2020-13291
HIGH

In GitLab before 13.2.3, project sharing could temporarily allow too permissive access.

CVSS 8.1 Gitlab gitlab 2020-08-12
CVE-2020-13290
HIGH

In GitLab before 13.0.12, 13.1.6, and 13.2.3, improper access control was used on the Applications page

CVSS 7.2 Gitlab gitlab 2020-08-12
CVE-2020-13295
HIGH

For GitLab Runner before 13.0.12, 13.1.6, 13.2.3, by replacing dockerd with a malicious server, the Shared Runner is susceptible to SSRF.

CVSS 8.8 Gitlab runner 2020-08-10
CVE-2020-13292
CRITICAL

In GitLab before 13.0.12, 13.1.6 and 13.2.3, it is possible to bypass E-mail verification which is required for OAuth Flow.

CVSS 9.6 Gitlab gitlab 2020-08-10
CVE-2020-13293
HIGH

In GitLab before 13.0.12, 13.1.6 and 13.2.3 using a branch with a hexadecimal name could override an existing hash.

CVSS 7.1 Gitlab gitlab 2020-08-10
CVE-2020-13294
MEDIUM

In GitLab before 13.0.12, 13.1.6 and 13.2.3, access grants were not revoked when a user revoked access to an application.

CVSS 5.4 Gitlab gitlab 2020-08-10
CVE-2020-15525
MEDIUM

GitLab EE 11.3 through 13.1.2 has Incorrect Access Control because of the Maven package upload endpoint.

CVSS 5.3 Gitlab gitlab 2020-07-07
CVE-2020-13279
HIGH

Client side code execution in gitlab-vscode-extension v2.2.0 allows attacker to execute code on user system

CVSS 8.6 Gitlab gitlab-vscode-extension 2020-06-22
CVE-2020-13263
HIGH

An authorization issue relating to project maintainer impersonation was identified in GitLab EE 9.5 and later through 13.0.1 that could allow unauthorized users to impersonate as a...

CVSS 8.8 Gitlab gitlab 2020-06-19
CVE-2020-13264
MEDIUM

Kubernetes cluster token disclosure in GitLab CE/EE 10.3 and later through 13.0.1 allows other group maintainers to view Kubernetes cluster token

CVSS 5.3 Gitlab gitlab 2020-06-19
CVE-2020-13272
HIGH

OAuth flow missing verification checks CE/EE 12.3 and later through 13.0.1 allows unverified user to use OAuth authorization code flow

CVSS 8.8 Gitlab gitlab 2020-06-19
CVE-2020-13275
HIGH

A user with an unverified email address could request an access to domain restricted groups in GitLab EE 12.2 and later through 13.0.1

CVSS 8.1 Gitlab gitlab 2020-06-19
1 35 36 37 38 39 53
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.