Vulnerabilities > Gitlab > Gitlab > 12.1.17

DATE CVE VULNERABILITY TITLE RISK
2020-01-13 CVE-2019-20147 Information Exposure vulnerability in Gitlab
An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 9.1 through 12.6.1.
network
low complexity
gitlab CWE-200
5.0
2020-01-13 CVE-2019-20146 Resource Exhaustion vulnerability in Gitlab
An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 11.0 through 12.6.
network
low complexity
gitlab CWE-400
5.0
2020-01-13 CVE-2019-20145 Unspecified vulnerability in Gitlab
An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 11.4 through 12.6.1.
network
low complexity
gitlab
4.0
2020-01-03 CVE-2019-19260 Unspecified vulnerability in Gitlab
GitLab Community Edition (CE) and Enterprise Edition (EE) through 12.5 has Incorrect Access Control (issue 2 of 2).
network
low complexity
gitlab
5.5
2020-01-03 CVE-2019-19257 Information Exposure vulnerability in Gitlab
GitLab Community Edition (CE) and Enterprise Edition (EE) through 12.5 has Incorrect Access Control (issue 1 of 2).
network
low complexity
gitlab CWE-200
5.0
2020-01-03 CVE-2019-19254 Information Exposure vulnerability in Gitlab
GitLab Community Edition (CE) and Enterprise Edition (EE).
network
low complexity
gitlab CWE-200
5.0
2019-12-18 CVE-2019-15591 Unspecified vulnerability in Gitlab
An improper access control vulnerability exists in GitLab <12.3.3 that allows an attacker to obtain container and dependency scanning reports through the merge request widget even though public pipelines were disabled.
network
low complexity
gitlab
4.0
2019-11-26 CVE-2019-18456 Incorrect Permission Assignment for Critical Resource vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition 8.17 through 12.4 in the Search feature provided by Elasticsearch integration..
network
low complexity
gitlab CWE-732
5.0
2019-11-26 CVE-2019-18455 Infinite Loop vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition 11 through 12.4 when building Nested GraphQL queries.
network
low complexity
gitlab CWE-835
5.0
2019-11-26 CVE-2019-18454 Cross-site Scripting vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition 10.5 through 12.4 in link validation for RDoc wiki pages feature.
network
gitlab CWE-79
4.3