Vulnerabilities > Gitlab > Gitlab > 13.0.0

DATE CVE VULNERABILITY TITLE RISK
2020-08-12 CVE-2020-13290 Improper Authentication vulnerability in Gitlab
In GitLab before 13.0.12, 13.1.6, and 13.2.3, improper access control was used on the Applications page
network
low complexity
gitlab CWE-287
6.5
2020-08-12 CVE-2020-13288 Cross-site Scripting vulnerability in Gitlab
In GitLab before 13.0.12, 13.1.6, and 13.2.3, a stored XSS vulnerability exists in the CI/CD Jobs page
network
gitlab CWE-79
3.5
2020-08-10 CVE-2020-13294 Unspecified vulnerability in Gitlab
In GitLab before 13.0.12, 13.1.6 and 13.2.3, access grants were not revoked when a user revoked access to an application.
network
low complexity
gitlab
5.4
2020-08-10 CVE-2020-13293 Incorrect Type Conversion or Cast vulnerability in Gitlab
In GitLab before 13.0.12, 13.1.6 and 13.2.3 using a branch with a hexadecimal name could override an existing hash.
network
low complexity
gitlab CWE-704
5.5
2020-08-10 CVE-2020-13292 Improper Authentication vulnerability in Gitlab
In GitLab before 13.0.12, 13.1.6 and 13.2.3, it is possible to bypass E-mail verification which is required for OAuth Flow.
network
low complexity
gitlab CWE-287
5.5
2020-07-07 CVE-2020-15525 Improper Privilege Management vulnerability in Gitlab
GitLab EE 11.3 through 13.1.2 has Incorrect Access Control because of the Maven package upload endpoint.
network
low complexity
gitlab CWE-269
5.0
2020-06-19 CVE-2020-13264 Information Exposure vulnerability in Gitlab
Kubernetes cluster token disclosure in GitLab CE/EE 10.3 and later through 13.0.1 allows other group maintainers to view Kubernetes cluster token
network
low complexity
gitlab CWE-200
5.0
2020-06-19 CVE-2020-13263 Incorrect Authorization vulnerability in Gitlab
An authorization issue relating to project maintainer impersonation was identified in GitLab EE 9.5 and later through 13.0.1 that could allow unauthorized users to impersonate as a maintainer to perform limited actions.
network
low complexity
gitlab CWE-863
6.5
2020-06-19 CVE-2020-13261 Insufficiently Protected Credentials vulnerability in Gitlab
Amazon EKS credentials disclosure in GitLab CE/EE 12.6 and later through 13.0.1 allows other administrators to view Amazon EKS credentials via HTML source code
network
low complexity
gitlab CWE-522
4.0
2020-06-19 CVE-2020-13276 Incorrect Authorization vulnerability in Gitlab
User is allowed to set an email as a notification email even without verifying the new email in all previous GitLab CE/EE versions through 13.0.1
network
low complexity
gitlab CWE-863
4.0