CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Vendor: gitlab
1,044 result(s) · page 39 of 53
CVE-2020-10977
MEDIUM

GitLab EE/CE 8.5 to 12.9 is vulnerable to a an path traversal when moving an issue between projects.

CVSS 5.5 Gitlab gitlab 2020-04-08
CVE-2020-10956
CRITICAL

GitLab 8.10 and later through 12.9 is vulnerable to an SSRF in a project import note feature.

CVSS 9.8 Gitlab gitlab 2020-03-27
CVE-2020-10953
HIGH

In GitLab EE 11.7 through 12.9, the NPM feature is vulnerable to a path traversal issue.

CVSS 7.5 Gitlab gitlab 2020-03-27
CVE-2020-10954
HIGH

GitLab through 12.9 is affected by a potential DoS in repository archive download.

CVSS 7.5 Gitlab gitlab 2020-03-27
CVE-2020-10952
MEDIUM

GitLab EE/CE 8.11 through 12.9.1 allows blocked users to pull/push docker images.

CVSS 6.5 Gitlab gitlab 2020-03-27
CVE-2020-10955
MEDIUM

GitLab EE/CE 11.1 through 12.9 is vulnerable to parameter tampering on an upload feature that allows an unauthorized user to read content available under specific folders.

CVSS 6.5 Gitlab gitlab 2020-03-27
CVE-2020-10077
CRITICAL

GitLab EE 3.0 through 12.8.1 allows SSRF. An internal investigation revealed that a particular deprecated service was creating a server side request forgery risk.

CVSS 9.8 Gitlab gitlab 2020-03-13
CVE-2020-10075
MEDIUM

GitLab 12.5 through 12.8.1 allows HTML Injection. A particular error header was potentially susceptible to injection or potentially other vulnerabilities via unescaped input.

CVSS 6.1 Gitlab gitlab 2020-03-13
CVE-2020-10076
MEDIUM

GitLab 12.1 through 12.8.1 allows XSS. A stored cross-site scripting vulnerability was discovered when displaying merge requests.

CVSS 6.1 Gitlab gitlab 2020-03-13
CVE-2020-10074
CRITICAL

GitLab 10.1 through 12.8.1 has Incorrect Access Control. A scenario was discovered in which a GitLab account could be taken over through an expired link.

CVSS 9.8 Gitlab gitlab 2020-03-13
CVE-2020-10073
HIGH

GitLab EE 12.4.2 through 12.8.1 allows Denial of Service. It was internally discovered that a potential denial of service involving permissions checks could impact a project home p...

CVSS 7.5 Gitlab gitlab 2020-03-13
CVE-2020-10092
MEDIUM

GitLab 12.1 through 12.8.1 allows XSS. A cross-site scripting vulnerability was present in a particular view relating to the Grafana integration.

CVSS 6.1 Gitlab gitlab 2020-03-13
CVE-2020-10083
CRITICAL

GitLab 12.7 through 12.8.1 has Insecure Permissions. Under certain conditions involving groups, project authorization changes were not being applied.

CVSS 9.1 Gitlab gitlab 2020-03-13
CVE-2020-10088
HIGH

GitLab 12.5 through 12.8.1 has Insecure Permissions. Depending on particular group settings, it was possible for invited groups to be given the incorrect permission level.

CVSS 8.1 Gitlab gitlab 2020-03-13
CVE-2020-10087
HIGH

GitLab before 12.8.2 allows Information Disclosure. Badge images were not being proxied, causing mixed content warnings as well as leaking the IP address of the user.

CVSS 7.5 Gitlab gitlab 2020-03-13
CVE-2020-10089
HIGH

GitLab 8.11 through 12.8.1 allows a Denial of Service when using several features to recursively request eachother,

CVSS 7.5 Gitlab gitlab 2020-03-13
CVE-2020-10091
MEDIUM

GitLab 9.3 through 12.8.1 allows XSS. A cross-site scripting vulnerability was found when viewing particular file types.

CVSS 6.1 Gitlab gitlab 2020-03-13
CVE-2020-10082
MEDIUM

GitLab 12.2 through 12.8.1 allows Denial of Service. A denial of service vulnerability impacting the designs for public issues was discovered.

CVSS 5.3 Gitlab gitlab 2020-03-13
CVE-2020-10084
MEDIUM

GitLab EE 11.6 through 12.8.1 allows Information Disclosure. Sending a specially crafted request to the vulnerability_feedback endpoint could result in the exposure of a private pr...

CVSS 5.3 Gitlab gitlab 2020-03-13
CVE-2020-10085
MEDIUM

GitLab 12.3.5 through 12.8.1 allows Information Disclosure. A particular view was exposing merge private merge request titles.

CVSS 5.3 Gitlab gitlab 2020-03-13
1 37 38 39 40 41 53
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.