Vulnerabilities > Gitlab > Gitlab > 12.5.1

DATE CVE VULNERABILITY TITLE RISK
2020-01-05 CVE-2019-19629 Information Exposure vulnerability in Gitlab
In GitLab EE 10.5 through 12.5.3, 12.4.5, and 12.3.8, when transferring a public project to a private group, private code would be disclosed via the Group Search API provided by the Elasticsearch integration.
network
low complexity
gitlab CWE-200
5.0
2020-01-05 CVE-2019-19628 Path Traversal vulnerability in Gitlab
In GitLab EE 11.3 through 12.5.3, 12.4.5, and 12.3.8, insufficient parameter sanitization for the Maven package registry could lead to privilege escalation and remote code execution vulnerabilities under certain conditions.
network
low complexity
gitlab CWE-22
7.5
2020-01-05 CVE-2019-19314 Cleartext Storage of Sensitive Information vulnerability in Gitlab
GitLab EE 8.4 through 12.5, 12.4.3, and 12.3.6 stored several tokens in plaintext.
network
low complexity
gitlab CWE-312
5.0
2020-01-05 CVE-2019-19313 Improper Input Validation vulnerability in Gitlab
GitLab EE 12.3 through 12.5, 12.4.3, and 12.3.6 allows Denial of Service.
network
low complexity
gitlab CWE-20
5.0
2020-01-05 CVE-2019-19312 Information Exposure vulnerability in Gitlab
GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 has Incorrect Access Control.
network
low complexity
gitlab CWE-200
5.0
2020-01-03 CVE-2019-19262 Incorrect Permission Assignment for Critical Resource vulnerability in Gitlab
GitLab Enterprise Edition (EE) 11.9 and later through 12.5 has Insecure Permissions.
network
low complexity
gitlab CWE-732
4.0