Vulnerabilities > Gitlab > Gitlab > 11.10.3
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-01-03 | CVE-2019-19258 | Information Exposure vulnerability in Gitlab GitLab Enterprise Edition (EE) 10.8 and later through 12.5 has Incorrect Access Control. | 5.0 |
2020-01-03 | CVE-2019-19257 | Information Exposure vulnerability in Gitlab GitLab Community Edition (CE) and Enterprise Edition (EE) through 12.5 has Incorrect Access Control (issue 1 of 2). | 5.0 |
2020-01-03 | CVE-2019-19311 | Cross-site Scripting vulnerability in Gitlab GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 allows XSS in group and profile fields. | 3.5 |
2020-01-03 | CVE-2019-19254 | Information Exposure vulnerability in Gitlab GitLab Community Edition (CE) and Enterprise Edition (EE). | 5.0 |
2020-01-03 | CVE-2019-19088 | Path Traversal vulnerability in Gitlab Gitlab Enterprise Edition (EE) 11.3 through 12.4.2 allows Directory Traversal. | 7.5 |
2020-01-03 | CVE-2019-19087 | Incorrect Permission Assignment for Critical Resource vulnerability in Gitlab Gitlab Enterprise Edition (EE) before 12.5.1 has Insecure Permissions (issue 2 of 2). | 4.0 |
2020-01-03 | CVE-2019-19086 | Incorrect Permission Assignment for Critical Resource vulnerability in Gitlab Gitlab Enterprise Edition (EE) before 12.5.1 has Insecure Permissions (issue 1 of 2). | 4.0 |
2019-12-20 | CVE-2019-15584 | Resource Exhaustion vulnerability in Gitlab A denial of service exists in gitlab <v12.3.2, <v12.2.6, and <v12.1.10 that would let an attacker bypass input validation in markdown fields take down the affected page. | 4.0 |
2019-12-18 | CVE-2019-5487 | Unspecified vulnerability in Gitlab An improper access control vulnerability exists in Gitlab EE <v12.3.3, <v12.2.7, & <v12.1.13 that allowed the group search feature with Elasticsearch to return private code, merge requests and commits. | 5.0 |
2019-12-18 | CVE-2019-5486 | Improper Authentication vulnerability in Gitlab A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.10 in the Salesforce login integration that could be used by an attacker to create an account that bypassed domain restrictions and email verification requirements. | 6.5 |