Vulnerabilities > Gitlab > Gitlab > 11.10.5

DATE CVE VULNERABILITY TITLE RISK
2020-01-03 CVE-2019-19259 Authorization Bypass Through User-Controlled Key vulnerability in Gitlab
GitLab Enterprise Edition (EE) 11.3 and later through 12.5 allows an Insecure Direct Object Reference (IDOR).
network
low complexity
gitlab CWE-639
4.0
2020-01-03 CVE-2019-19258 Information Exposure vulnerability in Gitlab
GitLab Enterprise Edition (EE) 10.8 and later through 12.5 has Incorrect Access Control.
network
low complexity
gitlab CWE-200
5.0
2020-01-03 CVE-2019-19257 Information Exposure vulnerability in Gitlab
GitLab Community Edition (CE) and Enterprise Edition (EE) through 12.5 has Incorrect Access Control (issue 1 of 2).
network
low complexity
gitlab CWE-200
5.0
2020-01-03 CVE-2019-19311 Cross-site Scripting vulnerability in Gitlab
GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 allows XSS in group and profile fields.
network
gitlab CWE-79
3.5
2020-01-03 CVE-2019-19254 Information Exposure vulnerability in Gitlab
GitLab Community Edition (CE) and Enterprise Edition (EE).
network
low complexity
gitlab CWE-200
5.0
2020-01-03 CVE-2019-19088 Path Traversal vulnerability in Gitlab
Gitlab Enterprise Edition (EE) 11.3 through 12.4.2 allows Directory Traversal.
network
low complexity
gitlab CWE-22
7.5
2020-01-03 CVE-2019-19087 Incorrect Permission Assignment for Critical Resource vulnerability in Gitlab
Gitlab Enterprise Edition (EE) before 12.5.1 has Insecure Permissions (issue 2 of 2).
network
low complexity
gitlab CWE-732
4.0
2020-01-03 CVE-2019-19086 Incorrect Permission Assignment for Critical Resource vulnerability in Gitlab
Gitlab Enterprise Edition (EE) before 12.5.1 has Insecure Permissions (issue 1 of 2).
network
low complexity
gitlab CWE-732
4.0
2019-12-20 CVE-2019-15584 Resource Exhaustion vulnerability in Gitlab
A denial of service exists in gitlab <v12.3.2, <v12.2.6, and <v12.1.10 that would let an attacker bypass input validation in markdown fields take down the affected page.
network
low complexity
gitlab CWE-400
4.0
2019-12-18 CVE-2019-5487 Unspecified vulnerability in Gitlab
An improper access control vulnerability exists in Gitlab EE <v12.3.3, <v12.2.7, & <v12.1.13 that allowed the group search feature with Elasticsearch to return private code, merge requests and commits.
network
low complexity
gitlab
5.0