CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Vendor: gitlab
1,044 result(s) · page 47 of 53
CVE-2019-5463
MEDIUM

An authorization issue was discovered in the GitLab CE/EE CI badge images endpoint which could result in disclosure of the build status. This vulnerability was addressed in 12.1.2,...

CVSS 5.3 Gitlab gitlab 2019-09-09
CVE-2019-14943
CRITICAL

An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.1.4. It uses Hard-coded Credentials.

CVSS 9.8 Gitlab gitlab 2019-08-29
CVE-2018-19584
HIGH

GitLab EE, versions 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, is vulnerable to an insecure direct object reference vulnerability that allows authenticated, b...

CVSS 7.5 Gitlab gitlab 2019-07-10
CVE-2018-19571
HIGH

GitLab CE/EE, versions 8.18 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an SSRF vulnerability in webhooks.

CVSS 7.7 Gitlab gitlab 2019-07-10
CVE-2018-19581
HIGH

GitLab EE, versions 8.3 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, is vulnerable to an insecure object reference vulnerability that allows a Guest user ...

CVSS 7.5 Gitlab gitlab 2019-07-10
CVE-2018-19578
MEDIUM

GitLab EE, version 11.5 before 11.5.1, is vulnerable to an insecure object reference issue that permits a user with Reporter privileges to view the Jaeger Tracing Operations page.

CVSS 6.5 Gitlab gitlab 2019-07-10
CVE-2018-19583
MEDIUM

GitLab CE/EE, versions 8.0 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, would log access tokens in the Workhorse logs, permitting administrators with acce...

CVSS 6.5 Gitlab gitlab 2019-07-10
CVE-2018-19579
MEDIUM

GitLab EE version 11.5 is vulnerable to a persistent XSS vulnerability in the Operations page. This is fixed in 11.5.1.

CVSS 5.4 Gitlab gitlab 2019-07-10
CVE-2018-19580
MEDIUM

All versions of GitLab prior to 11.5.1, 11.4.8, and 11.3.11 do not send an email to the old email address when an email address change is made.

CVSS 5.3 Gitlab gitlab 2019-07-10
CVE-2018-19576
HIGH

GitLab CE/EE, versions 8.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an access control issue that allows a Guest user to make changes...

CVSS 8.1 Gitlab gitlab 2019-07-10
CVE-2018-19569
HIGH

GitLab CE/EE, versions 8.8 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an authorization vulnerability that allows access to the web-UI ...

CVSS 8.8 Gitlab gitlab 2019-07-10
CVE-2018-19572
MEDIUM

GitLab CE 8.17 and later and EE 8.3 and later have a symlink time-of-check-to-time-of-use race condition that would allow unauthorized access to files in the GitLab Pages chroot en...

CVSS 5.9 Gitlab gitlab 2019-07-10
CVE-2018-19570
MEDIUM

GitLab CE/EE, versions 11.3 before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an XSS vulnerability in Markdown fields via unrecognized HTML tags.

CVSS 5.4 Gitlab gitlab 2019-07-10
CVE-2018-19573
MEDIUM

GitLab CE/EE, versions 10.3 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an XSS vulnerability in Markdown fields via Mermaid.

CVSS 5.4 Gitlab gitlab 2019-07-10
CVE-2018-19574
MEDIUM

GitLab CE/EE, versions 7.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an XSS vulnerability in the OAuth authorization page.

CVSS 5.4 Gitlab gitlab 2019-07-10
CVE-2018-19496
MEDIUM

An issue was discovered in GitLab Community and Enterprise Edition 10.x and 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an incorrect access contro...

CVSS 6.5 Gitlab gitlab 2019-07-10
CVE-2018-19577
MEDIUM

Gitlab CE/EE, versions 8.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an incorrect access control vulnerability that displays to an un...

CVSS 5.3 Gitlab gitlab 2019-07-10
CVE-2018-19495
MEDIUM

An issue was discovered in GitLab Community and Enterprise Edition before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an SSRF vulnerability in the Prometheus ...

CVSS 6.5 Gitlab gitlab 2019-07-10
CVE-2018-19493
MEDIUM

An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is a persistent XSS vulnerability in t...

CVSS 6.1 Gitlab gitlab 2019-07-10
CVE-2019-9485
CRITICAL

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Insecure Permissions.

CVSS 9.8 Gitlab gitlab 2019-05-29
1 45 46 47 48 49 53
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.