Vulnerabilities > Gitlab > Gitlab > 11.10.5

DATE CVE VULNERABILITY TITLE RISK
2019-12-18 CVE-2019-5486 Improper Authentication vulnerability in Gitlab
A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.10 in the Salesforce login integration that could be used by an attacker to create an account that bypassed domain restrictions and email verification requirements.
network
low complexity
gitlab CWE-287
6.5
2019-12-18 CVE-2019-15591 Unspecified vulnerability in Gitlab
An improper access control vulnerability exists in GitLab <12.3.3 that allows an attacker to obtain container and dependency scanning reports through the merge request widget even though public pipelines were disabled.
network
low complexity
gitlab
4.0
2019-12-18 CVE-2019-15589 Unspecified vulnerability in Gitlab
An improper access control vulnerability exists in Gitlab <v12.3.2, <v12.2.6, <v12.1.12 which would allow a blocked user would be able to use GIT clone and pull if he had obtained a CI/CD token before.
network
low complexity
gitlab
6.5
2019-12-18 CVE-2019-15580 Information Exposure vulnerability in Gitlab
An information exposure vulnerability exists in gitlab.com <v12.3.2, <v12.2.6, and <v12.1.10 when using the blocking merge request feature, it was possible for an unauthenticated user to see the head pipeline data of a public project even though pipeline visibility was restricted.
network
low complexity
gitlab CWE-200
4.0
2019-12-18 CVE-2019-15577 Improper Restriction of Excessive Authentication Attempts vulnerability in Gitlab
An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed project milestones to be disclosed via groups browsing.
network
low complexity
gitlab CWE-307
4.0
2019-12-18 CVE-2019-15576 Missing Authorization vulnerability in Gitlab
An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to view private system notes from a GraphQL endpoint.
network
low complexity
gitlab CWE-862
5.0
2019-12-18 CVE-2019-15575 Command Injection vulnerability in Gitlab
A command injection exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to inject commands via the API through the blobs scope.
network
low complexity
gitlab CWE-77
5.0
2019-11-26 CVE-2019-18456 Incorrect Permission Assignment for Critical Resource vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition 8.17 through 12.4 in the Search feature provided by Elasticsearch integration..
network
low complexity
gitlab CWE-732
5.0
2019-11-26 CVE-2019-18455 Infinite Loop vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition 11 through 12.4 when building Nested GraphQL queries.
network
low complexity
gitlab CWE-835
5.0
2019-11-26 CVE-2019-18454 Cross-site Scripting vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition 10.5 through 12.4 in link validation for RDoc wiki pages feature.
network
gitlab CWE-79
4.3