Vulnerabilities > Gitlab > Gitlab > 13.2.10

DATE CVE VULNERABILITY TITLE RISK
2020-12-11 CVE-2020-26408 Information Exposure vulnerability in Gitlab
A limited information disclosure vulnerability exists in Gitlab CE/EE from >= 12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2 that allows an attacker to view limited information in user's private profile
network
low complexity
gitlab CWE-200
5.0
2020-12-11 CVE-2020-13357 Authorization Bypass Through User-Controlled Key vulnerability in Gitlab
An issue was discovered in Gitlab CE/EE versions >= 13.1 to <13.4.7, >= 13.5 to <13.5.5, and >= 13.6 to <13.6.2 allowed an unauthorized user to access the user list corresponding to a feature flag in a project.
network
low complexity
gitlab CWE-639
4.0
2020-12-11 CVE-2020-26409 Improper Input Validation vulnerability in Gitlab
A DOS vulnerability exists in Gitlab CE/EE >=10.3, <13.4.7,>=13.5, <13.5.5,>=13.6, <13.6.2 that allows an attacker to trigger uncontrolled resource by bypassing input validation in markdown fields.
network
low complexity
gitlab CWE-20
4.0
2020-12-10 CVE-2020-26407 Cross-site Scripting vulnerability in Gitlab
A XSS vulnerability exists in Gitlab CE/EE from 12.4 before 13.4.7, 13.5 before 13.5.5, and 13.6 before 13.6.2 that allows an attacker to perform cross-site scripting to other users via importing a malicious project
network
gitlab CWE-79
3.5
2020-11-19 CVE-2020-13359 Information Exposure vulnerability in Gitlab
The Terraform API in GitLab CE/EE 12.10+ exposed the object storage signed URL on the delete operation allowing a malicious project maintainer to overwrite the Terraform state, bypassing audit and other business controls.
network
low complexity
gitlab CWE-200
5.5
2020-11-19 CVE-2020-13356 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.8.9.
network
low complexity
gitlab
6.4
2020-11-19 CVE-2020-13355 Path Traversal vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.14.
network
low complexity
gitlab CWE-22
5.5
2020-11-17 CVE-2020-26405 Path Traversal vulnerability in Gitlab
Path traversal vulnerability in package upload functionality in GitLab CE/EE starting from 12.8 allows an attacker to save packages in arbitrary locations.
network
low complexity
gitlab CWE-22
5.5
2020-11-17 CVE-2020-13349 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab EE affecting all versions starting from 8.12.
network
low complexity
gitlab
4.0
2020-11-17 CVE-2020-13348 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab EE affecting all versions starting from 10.2.
network
low complexity
gitlab
4.0