Vulnerabilities > Gitlab > Gitlab > 12.10.13

DATE CVE VULNERABILITY TITLE RISK
2020-11-19 CVE-2020-13359 Information Exposure vulnerability in Gitlab
The Terraform API in GitLab CE/EE 12.10+ exposed the object storage signed URL on the delete operation allowing a malicious project maintainer to overwrite the Terraform state, bypassing audit and other business controls.
network
low complexity
gitlab CWE-200
5.5
2020-11-19 CVE-2020-13356 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.8.9.
network
low complexity
gitlab
6.4
2020-11-19 CVE-2020-13355 Path Traversal vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.14.
network
low complexity
gitlab CWE-22
5.5
2020-11-17 CVE-2020-26405 Path Traversal vulnerability in Gitlab
Path traversal vulnerability in package upload functionality in GitLab CE/EE starting from 12.8 allows an attacker to save packages in arbitrary locations.
network
low complexity
gitlab CWE-22
5.5
2020-11-17 CVE-2020-13349 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab EE affecting all versions starting from 8.12.
network
low complexity
gitlab
4.0
2020-11-17 CVE-2020-13348 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab EE affecting all versions starting from 10.2.
network
low complexity
gitlab
4.0
2020-11-17 CVE-2020-13350 Cross-Site Request Forgery (CSRF) vulnerability in Gitlab
CSRF in runner administration page in all versions of GitLab CE/EE allows an attacker who's able to target GitLab instance administrators to pause/resume runners.
network
gitlab CWE-352
4.3
2020-11-17 CVE-2020-13354 Resource Exhaustion vulnerability in Gitlab
A potential DOS vulnerability was discovered in GitLab CE/EE starting with version 12.6.
network
low complexity
gitlab CWE-400
4.0
2020-11-17 CVE-2020-13352 Unspecified vulnerability in Gitlab
Private group info is leaked leaked in GitLab CE/EE version 10.2 and above, when the project is moved from private to public group.
network
low complexity
gitlab
5.0
2020-10-08 CVE-2020-13340 Cross-site Scripting vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2: Stored XSS in CI Job Log
network
gitlab CWE-79
3.5