CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Vendor: gitlab
1,044 result(s) · page 38 of 53
CVE-2020-13273
HIGH

A Denial of Service vulnerability allowed exhausting the system resources in GitLab CE/EE 12.0 and later through 13.0.1

CVSS 7.5 Gitlab gitlab 2020-06-19
CVE-2020-13274
HIGH

A security issue allowed achieving Denial of Service attacks through memory exhaustion by uploading malicious artifacts in all previous GitLab versions through 13.0.1

CVSS 7.5 Gitlab gitlab 2020-06-19
CVE-2020-13262
MEDIUM

Client-Side code injection through Mermaid markup in GitLab CE/EE 12.9 and later through 13.0.1 allows a specially crafted Mermaid payload to PUT requests on behalf of other users ...

CVSS 6.1 Gitlab gitlab 2020-06-19
CVE-2020-13265
MEDIUM

User email verification bypass in GitLab CE/EE 12.5 and later through 13.0.1 allows user to bypass email verification

CVSS 5.3 Gitlab gitlab 2020-06-19
CVE-2020-13277
MEDIUM

An authorization issue in the mirroring logic allowed read access to private repositories in GitLab CE/EE 10.6 and later through 13.0.5

CVSS 6.5 Gitlab gitlab 2020-06-19
CVE-2020-14155
MEDIUM

libpcre in PCRE before 8.44 allows an integer overflow via a large number after a (?C substring.

CVSS 5.3 Gitlab gitlab 2020-06-15
CVE-2020-13270
HIGH

Missing permission check on fork relation creation in GitLab CE/EE 11.3 and later through 13.0.1 allows guest users to create a fork relation on restricted public projects via API

CVSS 8.8 Gitlab gitlab 2020-06-10
CVE-2020-13267
MEDIUM

A Stored Cross-Site Scripting vulnerability allowed the execution on Javascript payloads on the Metrics Dashboard in GitLab CE/EE 12.8 and later through 13.0.1

CVSS 6.1 Gitlab gitlab 2020-06-10
CVE-2020-13269
MEDIUM

A Reflected Cross-Site Scripting vulnerability allowed the execution of arbitrary Javascript code on the Static Site Editor in GitLab CE/EE 12.10 and later through 13.0.1

CVSS 6.1 Gitlab gitlab 2020-06-10
CVE-2020-13271
MEDIUM

A Stored Cross-Site Scripting vulnerability allowed the execution of arbitrary Javascript code in the blobs API in all previous GitLab CE/EE versions through 13.0.1

CVSS 6.1 Gitlab gitlab 2020-06-10
CVE-2020-13268
MEDIUM

A specially crafted request could be used to confirm the existence of files hosted on object storage services, without disclosing their contents. This vulnerability affects GitLab ...

CVSS 5.3 Gitlab gitlab 2020-06-10
CVE-2020-12448
MEDIUM

GitLab EE 12.8 and later allows Exposure of Sensitive Information to an Unauthorized Actor via NuGet.

CVSS 5.3 Gitlab gitlab 2020-05-07
CVE-2020-12277
MEDIUM

GitLab 10.8 through 12.9 has a vulnerability that allows someone to mirror a repository even if the feature is not activated.

CVSS 5.3 Gitlab gitlab 2020-04-29
CVE-2020-12275
MEDIUM

GitLab 12.6 through 12.9 is vulnerable to a privilege escalation that allows an external user to create a personal snippet through the API.

CVSS 5.3 Gitlab gitlab 2020-04-29
CVE-2020-11505
HIGH

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) before 12.7.9, 12.8.x before 12.8.9, and 12.9.x before 12.9.3. A Workhorse bypass could lead to...

CVSS 7.5 Gitlab gitlab 2020-04-22
CVE-2020-11506
HIGH

An issue was discovered in GitLab 10.7.0 and later through 12.9.2. A Workhorse bypass could lead to job artifact uploads and file disclosure (Exposure of Sensitive Information) via...

CVSS 7.5 Gitlab gitlab 2020-04-22
CVE-2020-11649
MEDIUM

An issue was discovered in GitLab CE and EE 8.15 through 12.9.2. Members of a group could still have access after the group is deleted.

CVSS 6.5 Gitlab gitlab 2020-04-22
CVE-2020-10980
CRITICAL

GitLab EE/CE 8.0.rc1 to 12.9 is vulnerable to a blind SSRF in the FogBugz integration.

CVSS 9.8 Gitlab gitlab 2020-04-08
CVE-2020-10978
MEDIUM

GitLab EE/CE 8.11 to 12.9 is leaking information on Issues opened in a public project and then moved to a private project through Web-UI and GraphQL API.

CVSS 5.3 Gitlab gitlab 2020-04-08
CVE-2020-10976
HIGH

GitLab EE/CE 8.17 to 12.9 is vulnerable to information leakage when querying a merge request widget.

CVSS 7.5 Gitlab gitlab 2020-04-08
1 36 37 38 39 40 53
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.