Vulnerabilities > Gitlab > Gitlab > 12.9.6

DATE CVE VULNERABILITY TITLE RISK
2020-07-07 CVE-2020-15525 Improper Privilege Management vulnerability in Gitlab
GitLab EE 11.3 through 13.1.2 has Incorrect Access Control because of the Maven package upload endpoint.
network
low complexity
gitlab CWE-269
5.0
2020-06-19 CVE-2020-13264 Information Exposure vulnerability in Gitlab
Kubernetes cluster token disclosure in GitLab CE/EE 10.3 and later through 13.0.1 allows other group maintainers to view Kubernetes cluster token
network
low complexity
gitlab CWE-200
5.0
2020-06-19 CVE-2020-13263 Incorrect Authorization vulnerability in Gitlab
An authorization issue relating to project maintainer impersonation was identified in GitLab EE 9.5 and later through 13.0.1 that could allow unauthorized users to impersonate as a maintainer to perform limited actions.
network
low complexity
gitlab CWE-863
6.5
2020-06-19 CVE-2020-13261 Insufficiently Protected Credentials vulnerability in Gitlab
Amazon EKS credentials disclosure in GitLab CE/EE 12.6 and later through 13.0.1 allows other administrators to view Amazon EKS credentials via HTML source code
network
low complexity
gitlab CWE-522
4.0
2020-06-19 CVE-2020-13276 Incorrect Authorization vulnerability in Gitlab
User is allowed to set an email as a notification email even without verifying the new email in all previous GitLab CE/EE versions through 13.0.1
network
low complexity
gitlab CWE-863
4.0
2020-06-19 CVE-2020-13275 Incorrect Authorization vulnerability in Gitlab
A user with an unverified email address could request an access to domain restricted groups in GitLab EE 12.2 and later through 13.0.1
network
low complexity
gitlab CWE-863
5.5
2020-06-19 CVE-2020-13274 Resource Exhaustion vulnerability in Gitlab
A security issue allowed achieving Denial of Service attacks through memory exhaustion by uploading malicious artifacts in all previous GitLab versions through 13.0.1
network
low complexity
gitlab CWE-400
5.0
2020-06-19 CVE-2020-13273 Resource Exhaustion vulnerability in Gitlab
A Denial of Service vulnerability allowed exhausting the system resources in GitLab CE/EE 12.0 and later through 13.0.1
network
low complexity
gitlab CWE-400
7.8
2020-06-19 CVE-2020-13272 Incorrect Authorization vulnerability in Gitlab
OAuth flow missing verification checks CE/EE 12.3 and later through 13.0.1 allows unverified user to use OAuth authorization code flow
network
low complexity
gitlab CWE-863
6.5
2020-06-19 CVE-2020-13265 Insufficient Verification of Data Authenticity vulnerability in Gitlab
User email verification bypass in GitLab CE/EE 12.5 and later through 13.0.1 allows user to bypass email verification
network
low complexity
gitlab CWE-345
5.0