Vulnerabilities > Gitlab > Gitlab > 12.0.4

DATE CVE VULNERABILITY TITLE RISK
2019-09-16 CVE-2019-15730 Server-Side Request Forgery (SSRF) vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition 8.14 through 12.2.1.
network
low complexity
gitlab CWE-918
5.0
2019-09-16 CVE-2019-15728 Server-Side Request Forgery (SSRF) vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition 10.1 through 12.2.1.
network
low complexity
gitlab CWE-918
5.0
2019-09-16 CVE-2019-15727 Information Exposure vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition 11.2 through 12.2.1.
network
low complexity
gitlab CWE-200
5.0
2019-09-16 CVE-2019-15726 Information Exposure vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition through 12.2.1.
network
low complexity
gitlab CWE-200
5.0
2019-09-16 CVE-2019-15725 Authorization Bypass Through User-Controlled Key vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1.
network
low complexity
gitlab CWE-639
5.0
2019-09-16 CVE-2019-15724 Cross-site Scripting vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition 11.10 through 12.2.1.
network
gitlab CWE-79
4.3
2019-09-16 CVE-2019-15722 Allocation of Resources Without Limits or Throttling vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.2.1.
network
low complexity
gitlab CWE-770
5.0
2019-09-16 CVE-2019-15721 Incorrect Permission Assignment for Critical Resource vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition 10.8 through 12.2.1.
network
low complexity
gitlab CWE-732
5.5
2019-09-16 CVE-2019-16170 Unspecified vulnerability in Gitlab
An issue was discovered in GitLab Enterprise Edition 11.x and 12.x before 12.0.9, 12.1.x before 12.1.9, and 12.2.x before 12.2.5.
network
low complexity
gitlab
5.5
2019-09-09 CVE-2019-5473 Improper Authentication vulnerability in Gitlab 12.0.4/12.1.2
An authentication issue was discovered in GitLab that allowed a bypass of email verification.
network
low complexity
gitlab CWE-287
7.2