Vulnerabilities > Gitlab > Gitlab > 12.4.8

DATE CVE VULNERABILITY TITLE RISK
2020-01-03 CVE-2019-19261 Server-Side Request Forgery (SSRF) vulnerability in Gitlab
GitLab Enterprise Edition (EE) 6.7 and later through 12.5 allows SSRF.
network
gitlab CWE-918
6.8
2020-01-03 CVE-2019-19260 Unspecified vulnerability in Gitlab
GitLab Community Edition (CE) and Enterprise Edition (EE) through 12.5 has Incorrect Access Control (issue 2 of 2).
network
low complexity
gitlab
5.5
2020-01-03 CVE-2019-19259 Authorization Bypass Through User-Controlled Key vulnerability in Gitlab
GitLab Enterprise Edition (EE) 11.3 and later through 12.5 allows an Insecure Direct Object Reference (IDOR).
network
low complexity
gitlab CWE-639
4.0
2020-01-03 CVE-2019-19258 Information Exposure vulnerability in Gitlab
GitLab Enterprise Edition (EE) 10.8 and later through 12.5 has Incorrect Access Control.
network
low complexity
gitlab CWE-200
5.0
2020-01-03 CVE-2019-19257 Information Exposure vulnerability in Gitlab
GitLab Community Edition (CE) and Enterprise Edition (EE) through 12.5 has Incorrect Access Control (issue 1 of 2).
network
low complexity
gitlab CWE-200
5.0
2020-01-03 CVE-2019-19256 Information Exposure vulnerability in Gitlab
GitLab Enterprise Edition (EE) 12.2 and later through 12.5 has Incorrect Access Control.
network
low complexity
gitlab CWE-200
5.0
2020-01-03 CVE-2019-19255 Unspecified vulnerability in Gitlab
GitLab Enterprise Edition (EE) 12.3 and later through 12.5 has Incorrect Access Control.
network
low complexity
gitlab
4.0
2020-01-03 CVE-2019-19254 Information Exposure vulnerability in Gitlab
GitLab Community Edition (CE) and Enterprise Edition (EE).
network
low complexity
gitlab CWE-200
5.0
2020-01-03 CVE-2019-19088 Path Traversal vulnerability in Gitlab
Gitlab Enterprise Edition (EE) 11.3 through 12.4.2 allows Directory Traversal.
network
low complexity
gitlab CWE-22
7.5
2020-01-03 CVE-2019-19087 Incorrect Permission Assignment for Critical Resource vulnerability in Gitlab
Gitlab Enterprise Edition (EE) before 12.5.1 has Insecure Permissions (issue 2 of 2).
network
low complexity
gitlab CWE-732
4.0