CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Vendor: gitlab
1,044 result(s) · page 44 of 53
CVE-2018-20495
MEDIUM

An issue was discovered in GitLab Community and Enterprise Edition 11.3.x and 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows Information Exposure.

CVSS 5.3 Gitlab gitlab 2019-12-30
CVE-2018-20492
MEDIUM

An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control (issue 2 of 6).

CVSS 5.3 Gitlab gitlab 2019-12-26
CVE-2019-15584
MEDIUM

A denial of service exists in gitlab <v12.3.2, <v12.2.6, and <v12.1.10 that would let an attacker bypass input validation in markdown fields take down the affected page.

CVSS 6.5 Gitlab gitlab 2019-12-20
CVE-2019-5486
HIGH

A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.10 in the Salesforce login integration that could be used by an attacker to create an ac...

CVSS 8.8 Gitlab gitlab 2019-12-18
CVE-2019-5469
MEDIUM

An IDOR vulnerability exists in GitLab <v12.1.2, <v12.0.4, and <v11.11.6 that allowed uploading files from project archive to replace other users files potentially allowing an atta...

CVSS 6.5 Gitlab gitlab 2019-12-18
CVE-2019-5487
MEDIUM

An improper access control vulnerability exists in Gitlab EE <v12.3.3, <v12.2.7, & <v12.1.13 that allowed the group search feature with Elasticsearch to return private code, merge ...

CVSS 5.3 Gitlab gitlab 2019-12-18
CVE-2019-15589
HIGH

An improper access control vulnerability exists in Gitlab <v12.3.2, <v12.2.6, <v12.1.12 which would allow a blocked user would be able to use GIT clone and pull if he had obtained ...

CVSS 8.8 Gitlab gitlab 2019-12-18
CVE-2019-15591
MEDIUM

An improper access control vulnerability exists in GitLab <12.3.3 that allows an attacker to obtain container and dependency scanning reports through the merge request widget even ...

CVSS 6.5 Gitlab gitlab 2019-12-18
CVE-2019-15575
HIGH

A command injection exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to inject commands via the API through the blobs scope.

CVSS 7.5 Gitlab gitlab 2019-12-18
CVE-2019-15576
HIGH

An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to view private system notes from a GraphQL endpoint.

CVSS 7.5 Gitlab gitlab 2019-12-18
CVE-2019-15580
MEDIUM

An information exposure vulnerability exists in gitlab.com <v12.3.2, <v12.2.6, and <v12.1.10 when using the blocking merge request feature, it was possible for an unauthenticated u...

CVSS 6.5 Gitlab gitlab 2019-12-18
CVE-2019-18455
HIGH

An issue was discovered in GitLab Community and Enterprise Edition 11 through 12.4 when building Nested GraphQL queries. It has a large or infinite loop.

CVSS 7.5 Gitlab gitlab 2019-11-26
CVE-2019-18448
MEDIUM

An issue was discovered in GitLab Community and Enterprise Edition before 12.4. It has Incorrect Access Control.

CVSS 6.5 Gitlab gitlab 2019-11-26
CVE-2019-18451
MEDIUM

An issue was discovered in GitLab Community and Enterprise Edition 10.7.4 through 12.4 in the InternalRedirect filtering feature. It has an Open Redirect.

CVSS 6.1 Gitlab gitlab 2019-11-26
CVE-2019-18454
MEDIUM

An issue was discovered in GitLab Community and Enterprise Edition 10.5 through 12.4 in link validation for RDoc wiki pages feature. It has XSS.

CVSS 6.1 Gitlab gitlab 2019-11-26
CVE-2019-18452
MEDIUM

An issue was discovered in GitLab Community and Enterprise Edition 11.3 through 12.4 when moving an issue to a public project from a private one. It has Insecure Permissions.

CVSS 5.3 Gitlab gitlab 2019-11-26
CVE-2019-18456
MEDIUM

An issue was discovered in GitLab Community and Enterprise Edition 8.17 through 12.4 in the Search feature provided by Elasticsearch integration.. It has Insecure Permissions (issu...

CVSS 5.3 Gitlab gitlab 2019-11-26
CVE-2019-18457
HIGH

An issue was discovered in GitLab Community and Enterprise Edition 11.8 through 12.4 when handling Security tokens.. It has Insecure Permissions.

CVSS 8.8 Gitlab gitlab 2019-11-26
CVE-2019-18459
MEDIUM

An issue was discovered in GitLab Community and Enterprise Edition 11.3 to 12.3 in the protected environments feature. It has Insecure Permissions (issue 3 of 4).

CVSS 5.3 Gitlab gitlab 2019-11-26
CVE-2019-18460
HIGH

An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.4 in the Comments Search feature provided by the Elasticsearch integration. It has Incorrect Acce...

CVSS 7.5 Gitlab gitlab 2019-11-26
1 42 43 44 45 46 53
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.