CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Vendor: gitlab
1,044 result(s) · page 51 of 53
CVE-2018-12605
MEDIUM

An issue was discovered in GitLab Community Edition and Enterprise Edition 10.7.x before 10.7.6. The usage of 'url_for' contained a XSS issue due to it allowing arbitrary protocols...

CVSS 5.4 Gitlab gitlab 2018-08-03
CVE-2018-12606
MEDIUM

An issue was discovered in GitLab Community Edition and Enterprise Edition before 10.7.6, 10.8.x before 10.8.5, and 11.x before 11.0.1. The wiki contains a persistent XSS issue due...

CVSS 5.4 Gitlab gitlab 2018-08-03
CVE-2018-12607
MEDIUM

An issue was discovered in GitLab Community Edition and Enterprise Edition before 10.7.6, 10.8.x before 10.8.5, and 11.x before 11.0.1. The charts feature contained a persistent XS...

CVSS 5.4 Gitlab gitlab 2018-08-03
CVE-2018-14603
HIGH

An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2. CSRF can occur in the Test feature of the System H...

CVSS 8.8 Gitlab gitlab 2018-07-27
CVE-2018-14601
HIGH

An issue was discovered in GitLab Community and Enterprise Edition 11.1.x before 11.1.2. A Denial of Service can occur because Markdown rendering times are slow.

CVSS 7.5 Gitlab gitlab 2018-07-27
CVE-2018-14602
HIGH

An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2. Information Disclosure can occur because the Prome...

CVSS 7.5 Gitlab gitlab 2018-07-27
CVE-2018-14604
MEDIUM

An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2. XSS can occur in the tooltip of the job inside the...

CVSS 6.1 Gitlab gitlab 2018-07-27
CVE-2018-14605
MEDIUM

An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2. XSS can occur in the branch name during a Web IDE ...

CVSS 5.4 Gitlab gitlab 2018-07-27
CVE-2018-14606
MEDIUM

An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2. XSS can occur via a Milestone name during a promot...

CVSS 5.4 Gitlab gitlab 2018-07-27
CVE-2018-14364
CRITICAL

GitLab Community and Enterprise Edition before 10.7.7, 10.8.x before 10.8.6, and 11.x before 11.0.4 allows Directory Traversal with write access and resultant remote code execution...

CVSS 9.8 Gitlab gitlab 2018-07-18
CVE-2017-0921
HIGH

GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an unverified password change issue in the PasswordsController component resulting in p...

CVSS 8.1 Gitlab gitlab 2018-07-03
CVE-2017-0919
HIGH

GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the GitLab import component resulting in an attacker b...

CVSS 7.5 Gitlab gitlab 2018-07-03
CVE-2018-10379
MEDIUM

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) before 10.5.8, 10.6.x before 10.6.5, and 10.7.x before 10.7.2. The Move Issue feature contained...

CVSS 6.1 Gitlab gitlab 2018-05-31
CVE-2018-8801
MEDIUM

GitLab Community and Enterprise Editions version 8.3 up to 10.x before 10.3 are vulnerable to SSRF in the Services and webhooks component.

CVSS 6.5 Gitlab gitlab 2018-04-25
CVE-2018-9243
MEDIUM

GitLab Community and Enterprise Editions version 8.4 up to 10.4 are vulnerable to XSS because a lack of input validation in the merge request component leads to cross site scriptin...

CVSS 6.1 Gitlab gitlab 2018-04-05
CVE-2018-9244
MEDIUM

GitLab Community and Enterprise Editions version 9.2 up to 10.4 are vulnerable to XSS because a lack of input validation in the milestones component leads to cross site scripting (...

CVSS 6.1 Gitlab gitlab 2018-04-05
CVE-2018-8971
CRITICAL

The Auth0 integration in GitLab before 10.3.9, 10.4.x before 10.4.6, and 10.5.x before 10.5.6 has an incorrect omniauth-auth0 configuration, leading to signing in unintended users.

CVSS 9.8 Gitlab gitlab 2018-03-24
CVE-2018-3710
HIGH

Gitlab Community and Enterprise Editions version 10.3.3 is vulnerable to an Insecure Temporary File in the project import component resulting remote code execution.

CVSS 7.8 Gitlab gitlab 2018-03-21
CVE-2017-0915
CRITICAL

Gitlab Community Edition version 10.2.4 is vulnerable to a lack of input validation in the GitlabProjectsImportService resulting in remote code execution.

CVSS 9.8 Gitlab gitlab 2018-03-21
CVE-2017-0916
CRITICAL

Gitlab Community Edition version 10.3 is vulnerable to a lack of input validation in the system_hook_push queue through web hook component resulting in remote code execution.

CVSS 9.8 Gitlab gitlab 2018-03-21
1 49 50 51 52 53
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.