Vulnerabilities > Gitlab > Gitlab > 12.10.5

DATE CVE VULNERABILITY TITLE RISK
2020-09-14 CVE-2020-13309 Server-Side Request Forgery (SSRF) vulnerability in Gitlab
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4.
network
low complexity
gitlab CWE-918
6.5
2020-09-14 CVE-2020-13306 Allocation of Resources Without Limits or Throttling vulnerability in Gitlab
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4.
network
low complexity
gitlab CWE-770
5.0
2020-09-14 CVE-2020-13305 Insufficient Session Expiration vulnerability in Gitlab
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4.
network
low complexity
gitlab CWE-613
4.0
2020-09-14 CVE-2020-13304 Improper Authentication vulnerability in Gitlab
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4.
network
low complexity
gitlab CWE-287
6.5
2020-09-14 CVE-2020-13302 Insufficient Session Expiration vulnerability in Gitlab
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4.
network
low complexity
gitlab CWE-613
6.5
2020-09-14 CVE-2020-13301 Cross-site Scripting vulnerability in Gitlab
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4.
network
gitlab CWE-79
3.5
2020-09-14 CVE-2020-13298 Improper Input Validation vulnerability in Gitlab
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4.
network
low complexity
gitlab CWE-20
5.0
2020-09-14 CVE-2020-13297 Improper Authentication vulnerability in Gitlab
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4.
network
gitlab CWE-287
4.9
2020-08-13 CVE-2020-13286 Server-Side Request Forgery (SSRF) vulnerability in Gitlab
For GitLab before 13.0.12, 13.1.6, 13.2.3 user controlled git configuration settings can be modified to result in Server Side Request Forgery.
network
low complexity
gitlab CWE-918
4.0
2020-08-13 CVE-2020-13281 Improper Input Validation vulnerability in Gitlab
For GitLab before 13.0.12, 13.1.6, 13.2.3 a denial of service exists in the project import feature
network
low complexity
gitlab CWE-20
4.0