Vulnerabilities > Gitlab > Gitlab > 10.2.8
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2018-07-27 | CVE-2018-14606 | Cross-site Scripting vulnerability in Gitlab An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2. | 3.5 |
2018-07-27 | CVE-2018-14605 | Cross-site Scripting vulnerability in Gitlab An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2. | 3.5 |
2018-07-27 | CVE-2018-14604 | Cross-site Scripting vulnerability in Gitlab An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2. | 4.3 |
2018-07-27 | CVE-2018-14603 | Cross-Site Request Forgery (CSRF) vulnerability in Gitlab An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2. | 6.8 |
2018-07-27 | CVE-2018-14602 | Information Exposure vulnerability in Gitlab An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2. | 5.0 |
2018-07-18 | CVE-2018-14364 | Path Traversal vulnerability in Gitlab GitLab Community and Enterprise Edition before 10.7.7, 10.8.x before 10.8.6, and 11.x before 11.0.4 allows Directory Traversal with write access and resultant remote code execution via the GitLab projects import component. | 7.5 |
2018-05-31 | CVE-2018-10379 | Cross-site Scripting vulnerability in Gitlab An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) before 10.5.8, 10.6.x before 10.6.5, and 10.7.x before 10.7.2. | 4.3 |
2018-04-25 | CVE-2018-8801 | Server-Side Request Forgery (SSRF) vulnerability in Gitlab GitLab Community and Enterprise Editions version 8.3 up to 10.x before 10.3 are vulnerable to SSRF in the Services and webhooks component. | 4.0 |
2018-04-05 | CVE-2018-9244 | Cross-site Scripting vulnerability in Gitlab GitLab Community and Enterprise Editions version 9.2 up to 10.4 are vulnerable to XSS because a lack of input validation in the milestones component leads to cross site scripting (specifically, data-milestone-id in the milestone dropdown feature). | 4.3 |
2018-04-05 | CVE-2018-9243 | Cross-site Scripting vulnerability in Gitlab GitLab Community and Enterprise Editions version 8.4 up to 10.4 are vulnerable to XSS because a lack of input validation in the merge request component leads to cross site scripting (specifically, filenames in changes tabs of merge requests). | 4.3 |