CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Vendor: gitlab
1,044 result(s) · page 43 of 53
CVE-2019-19314
HIGH

GitLab EE 8.4 through 12.5, 12.4.3, and 12.3.6 stored several tokens in plaintext.

CVSS 7.5 Gitlab gitlab 2020-01-05
CVE-2019-19629
HIGH

In GitLab EE 10.5 through 12.5.3, 12.4.5, and 12.3.8, when transferring a public project to a private group, private code would be disclosed via the Group Search API provided by th...

CVSS 7.5 Gitlab gitlab 2020-01-05
CVE-2019-19312
MEDIUM

GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 has Incorrect Access Control. After a project changed to private, previously forked repositories were still able to get information ...

CVSS 5.8 Gitlab gitlab 2020-01-05
CVE-2019-19261
HIGH

GitLab Enterprise Edition (EE) 6.7 and later through 12.5 allows SSRF.

CVSS 8.8 Gitlab gitlab 2020-01-03
CVE-2019-19260
MEDIUM

GitLab Community Edition (CE) and Enterprise Edition (EE) through 12.5 has Incorrect Access Control (issue 2 of 2).

CVSS 5.4 Gitlab gitlab 2020-01-03
CVE-2019-19256
MEDIUM

GitLab Enterprise Edition (EE) 12.2 and later through 12.5 has Incorrect Access Control.

CVSS 5.3 Gitlab gitlab 2020-01-03
CVE-2019-19257
MEDIUM

GitLab Community Edition (CE) and Enterprise Edition (EE) through 12.5 has Incorrect Access Control (issue 1 of 2).

CVSS 5.3 Gitlab gitlab 2020-01-03
CVE-2019-19258
MEDIUM

GitLab Enterprise Edition (EE) 10.8 and later through 12.5 has Incorrect Access Control.

CVSS 5.3 Gitlab gitlab 2020-01-03
CVE-2019-19311
MEDIUM

GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 allows XSS in group and profile fields.

CVSS 5.4 Gitlab gitlab 2020-01-03
CVE-2019-19088
CRITICAL

Gitlab Enterprise Edition (EE) 11.3 through 12.4.2 allows Directory Traversal.

CVSS 9.8 Gitlab gitlab 2020-01-03
CVE-2019-19254
MEDIUM

GitLab Community Edition (CE) and Enterprise Edition (EE). 9.6 and later through 12.5 has Incorrect Access Control.

CVSS 5.3 Gitlab gitlab 2020-01-03
CVE-2018-20499
HIGH

An issue was discovered in GitLab Community and Enterprise Edition before 11.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows SSRF.

CVSS 7.2 Gitlab gitlab 2019-12-30
CVE-2018-20501
MEDIUM

An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.

CVSS 6.3 Gitlab gitlab 2019-12-30
CVE-2018-20507
MEDIUM

An issue was discovered in GitLab Enterprise Edition 11.2.x through 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.

CVSS 5.3 Gitlab gitlab 2019-12-30
CVE-2018-20497
MEDIUM

An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows SSRF.

CVSS 5 Gitlab gitlab 2019-12-30
CVE-2018-20494
HIGH

An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.

CVSS 7.5 Gitlab gitlab 2019-12-30
CVE-2018-20490
MEDIUM

An issue was discovered in GitLab Community and Enterprise Edition 11.2.x through 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows XSS.

CVSS 5.4 Gitlab gitlab 2019-12-30
CVE-2018-20491
MEDIUM

An issue was discovered in GitLab Enterprise Edition 11.3.x and 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows XSS.

CVSS 5.4 Gitlab gitlab 2019-12-30
CVE-2018-20496
MEDIUM

An issue was discovered in GitLab Community and Enterprise Edition 11.2.x through 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows XSS.

CVSS 5.4 Gitlab gitlab 2019-12-30
CVE-2018-20489
MEDIUM

An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.

CVSS 5.3 Gitlab gitlab 2019-12-30
1 41 42 43 44 45 53
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.