Vulnerabilities > Gitlab > Gitlab > 12.3.2

DATE CVE VULNERABILITY TITLE RISK
2020-02-05 CVE-2020-7973 Cross-site Scripting vulnerability in Gitlab
GitLab through 12.7.2 allows XSS.
network
gitlab CWE-79
4.3
2020-02-05 CVE-2020-7972 Incorrect Default Permissions vulnerability in Gitlab
GitLab EE 12.2 has Insecure Permissions (issue 2 of 2).
network
low complexity
gitlab CWE-276
5.0
2020-02-05 CVE-2020-7971 Cross-site Scripting vulnerability in Gitlab
GitLab EE 11.0 and later through 12.7.2 allows XSS.
network
gitlab CWE-79
4.3
2020-02-05 CVE-2020-7969 Information Exposure vulnerability in Gitlab
GitLab EE 8.0 and later through 12.7.2 allows Information Disclosure.
network
low complexity
gitlab CWE-200
5.0
2020-02-05 CVE-2020-7968 Improper Authentication vulnerability in Gitlab
GitLab EE 8.0 through 12.7.2 has Incorrect Access Control.
network
low complexity
gitlab CWE-287
5.0
2020-02-05 CVE-2020-7967 Incorrect Default Permissions vulnerability in Gitlab
GitLab EE 8.0 through 12.7.2 has Insecure Permissions (issue 1 of 2).
network
low complexity
gitlab CWE-276
4.0
2020-02-05 CVE-2020-7966 Path Traversal vulnerability in Gitlab
GitLab EE 11.11 and later through 12.7.2 allows Directory Traversal.
network
low complexity
gitlab CWE-22
5.0
2020-02-05 CVE-2020-8114 Incorrect Default Permissions vulnerability in Gitlab
GitLab EE 8.9 and later through 12.7.2 has Insecure Permission
network
low complexity
gitlab CWE-276
7.5
2020-02-05 CVE-2020-7979 Incorrect Default Permissions vulnerability in Gitlab
GitLab EE 8.9 and later through 12.7.2 has Insecure Permission
network
gitlab CWE-276
4.3
2020-01-28 CVE-2019-15590 Unspecified vulnerability in Gitlab
An access control issue exists in < 12.3.5, < 12.2.8, and < 12.1.14 for GitLab Community Edition (CE) and Enterprise Edition (EE) where private merge requests and issues would be disclosed with the Group Search feature provided by Elasticsearch integration
network
low complexity
gitlab
5.0