Vulnerabilities > Gitlab > Gitlab > 12.9.1

DATE CVE VULNERABILITY TITLE RISK
2020-06-19 CVE-2020-13262 Cross-site Scripting vulnerability in Gitlab
Client-Side code injection through Mermaid markup in GitLab CE/EE 12.9 and later through 13.0.1 allows a specially crafted Mermaid payload to PUT requests on behalf of other users via clicking on a link
network
gitlab CWE-79
4.3
2020-06-19 CVE-2020-13277 Incorrect Authorization vulnerability in Gitlab
An authorization issue in the mirroring logic allowed read access to private repositories in GitLab CE/EE 10.6 and later through 13.0.5
network
low complexity
gitlab CWE-863
4.0
2020-06-15 CVE-2020-14155 Integer Overflow or Wraparound vulnerability in multiple products
libpcre in PCRE before 8.44 allows an integer overflow via a large number after a (?C substring.
network
low complexity
pcre apple gitlab oracle netapp splunk CWE-190
5.3
2020-06-10 CVE-2020-13271 Cross-site Scripting vulnerability in Gitlab
A Stored Cross-Site Scripting vulnerability allowed the execution of arbitrary Javascript code in the blobs API in all previous GitLab CE/EE versions through 13.0.1
network
gitlab CWE-79
4.3
2020-06-10 CVE-2020-13270 Missing Authorization vulnerability in Gitlab
Missing permission check on fork relation creation in GitLab CE/EE 11.3 and later through 13.0.1 allows guest users to create a fork relation on restricted public projects via API
network
low complexity
gitlab CWE-862
6.5
2020-06-10 CVE-2020-13267 Cross-site Scripting vulnerability in Gitlab
A Stored Cross-Site Scripting vulnerability allowed the execution on Javascript payloads on the Metrics Dashboard in GitLab CE/EE 12.8 and later through 13.0.1
network
gitlab CWE-79
4.3
2020-06-09 CVE-2020-13266 Missing Authorization vulnerability in Gitlab
Insecure authorization in Project Deploy Keys in GitLab CE/EE 12.8 and later through 13.0.1 allows users to update permissions of other users' deploy keys under certain conditions
network
low complexity
gitlab CWE-862
4.0
2020-04-22 CVE-2020-11649 Missing Authentication for Critical Function vulnerability in Gitlab
An issue was discovered in GitLab CE and EE 8.15 through 12.9.2.
network
low complexity
gitlab CWE-306
4.0
2020-04-22 CVE-2020-11506 Information Exposure vulnerability in Gitlab
An issue was discovered in GitLab 10.7.0 and later through 12.9.2.
network
low complexity
gitlab CWE-200
5.0
2020-04-22 CVE-2020-11505 Information Exposure vulnerability in Gitlab
An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) before 12.7.9, 12.8.x before 12.8.9, and 12.9.x before 12.9.3.
network
low complexity
gitlab CWE-200
5.0