CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Vendor: gitlab
1,044 result(s) · page 40 of 53
CVE-2020-10086
MEDIUM

GitLab 10.4 through 12.8.1 allows Directory Traversal. A particular endpoint was vulnerable to a directory traversal vulnerability, leading to arbitrary file read.

CVSS 5.3 Gitlab gitlab 2020-03-13
CVE-2020-10090
MEDIUM

GitLab 11.7 through 12.8.1 allows Information Disclosure. Under certain group conditions, group epic information was unintentionally being disclosed.

CVSS 5.3 Gitlab gitlab 2020-03-13
CVE-2020-10081
MEDIUM

GitLab before 12.8.2 has Incorrect Access Control. It was internally discovered that the LFS import process could potentially be used to incorrectly access LFS objects not owned by...

CVSS 6.5 Gitlab gitlab 2020-03-13
CVE-2020-10078
MEDIUM

GitLab 12.1 through 12.8.1 allows XSS. The merge request submission form was determined to have a stored cross-site scripting vulnerability.

CVSS 6.1 Gitlab gitlab 2020-03-13
CVE-2020-10079
MEDIUM

GitLab 7.10 through 12.8.1 has Incorrect Access Control. Under certain conditions where users should have been required to configure two-factor authentication, it was not being req...

CVSS 5.3 Gitlab gitlab 2020-03-13
CVE-2020-10080
MEDIUM

GitLab 8.3 through 12.8.1 allows Information Disclosure. It was possible for certain non-members to access the Contribution Analytics page of a private group.

CVSS 5.3 Gitlab gitlab 2020-03-13
CVE-2020-10535
MEDIUM

GitLab 12.8.x before 12.8.6, when sign-up is enabled, allows remote attackers to bypass email domain restrictions within the two-day grace period for an unconfirmed email address.

CVSS 5.3 Gitlab gitlab 2020-03-12
CVE-2019-13121
HIGH

An issue was discovered in GitLab Enterprise Edition 10.6 through 12.0.2. The GitHub project integration was vulnerable to an SSRF vulnerability which allowed an attacker to make r...

CVSS 7.5 Gitlab gitlab 2020-03-10
CVE-2019-13009
MEDIUM

An issue was discovered in GitLab Community and Enterprise Edition 9.2 through 12.0.2. Uploaded files associated with unsaved personal snippets were accessible to unauthorized user...

CVSS 6.5 Gitlab gitlab 2020-03-10
CVE-2019-13010
MEDIUM

An issue was discovered in GitLab Enterprise Edition 8.3 through 12.0.2. The color codes decoder was vulnerable to a resource depletion attack if specific formats were used. It all...

CVSS 5.9 Gitlab gitlab 2020-03-10
CVE-2019-12446
HIGH

An issue was discovered in GitLab Community and Enterprise Edition 8.3 through 11.11. It allows Information Exposure through an Error Message.

CVSS 7.5 Gitlab gitlab 2020-03-10
CVE-2019-13003
HIGH

An issue was discovered in GitLab Community and Enterprise Edition before 12.0.3. One of the parsers used by Gilab CI was vulnerable to a resource exhaustion attack. It allows Unco...

CVSS 7.5 Gitlab gitlab 2020-03-10
CVE-2019-12444
MEDIUM

An issue was discovered in GitLab Community and Enterprise Edition 8.9 through 11.11. Wiki Pages contained a lack of input validation which resulted in a persistent XSS vulnerabili...

CVSS 6.1 Gitlab gitlab 2020-03-10
CVE-2019-12445
MEDIUM

An issue was discovered in GitLab Community and Enterprise Edition 8.4 through 11.11. A malicious user could execute JavaScript code on notes by importing a specially crafted proje...

CVSS 5.4 Gitlab gitlab 2020-03-10
CVE-2019-13004
MEDIUM

An issue was discovered in GitLab Community and Enterprise Edition 11.10 through 12.0.2. When specific encoded characters were added to comments, the comments section would become ...

CVSS 5.3 Gitlab gitlab 2020-03-10
CVE-2019-12443
CRITICAL

An issue was discovered in GitLab Community and Enterprise Edition 10.2 through 11.11. Multiple features contained Server-Side Request Forgery (SSRF) vulnerabilities caused by an i...

CVSS 9.8 Gitlab gitlab 2020-03-10
CVE-2019-12441
HIGH

An issue was discovered in GitLab Community and Enterprise Edition 8.4 through 11.11. The protected branches feature contained a access control issue which resulted in a bypass of ...

CVSS 7.5 Gitlab gitlab 2020-03-10
CVE-2019-12442
MEDIUM

An issue was discovered in GitLab Enterprise Edition 11.7 through 11.11. The epic details page contained a lack of input validation and output encoding issue which resulted in a pe...

CVSS 6.1 Gitlab gitlab 2020-03-10
CVE-2019-12428
CRITICAL

An issue was discovered in GitLab Community and Enterprise Edition 6.8 through 11.11. Users could bypass the mandatory external authentication provider sign-in restrictions by send...

CVSS 9.8 Gitlab gitlab 2020-03-10
CVE-2019-12430
HIGH

An issue was discovered in GitLab Community and Enterprise Edition 11.11. A specially crafted payload would allow an authenticated malicious user to execute commands remotely throu...

CVSS 8.8 Gitlab gitlab 2020-03-10
1 38 39 40 41 42 53
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.