Vulnerabilities > Gitlab > Gitlab > 5.2.1
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-06-19 | CVE-2020-13276 | Incorrect Authorization vulnerability in Gitlab User is allowed to set an email as a notification email even without verifying the new email in all previous GitLab CE/EE versions through 13.0.1 | 4.0 |
2020-06-19 | CVE-2020-13274 | Resource Exhaustion vulnerability in Gitlab A security issue allowed achieving Denial of Service attacks through memory exhaustion by uploading malicious artifacts in all previous GitLab versions through 13.0.1 | 5.0 |
2020-06-15 | CVE-2020-14155 | Integer Overflow or Wraparound vulnerability in multiple products libpcre in PCRE before 8.44 allows an integer overflow via a large number after a (?C substring. | 5.3 |
2020-06-10 | CVE-2020-13271 | Cross-site Scripting vulnerability in Gitlab A Stored Cross-Site Scripting vulnerability allowed the execution of arbitrary Javascript code in the blobs API in all previous GitLab CE/EE versions through 13.0.1 | 4.3 |
2020-04-22 | CVE-2020-11505 | Information Exposure vulnerability in Gitlab An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) before 12.7.9, 12.8.x before 12.8.9, and 12.9.x before 12.9.3. | 5.0 |
2020-03-27 | CVE-2020-10954 | Resource Exhaustion vulnerability in Gitlab GitLab through 12.9 is affected by a potential DoS in repository archive download. | 5.0 |
2020-03-13 | CVE-2020-10087 | Unspecified vulnerability in Gitlab GitLab before 12.8.2 allows Information Disclosure. | 5.0 |
2020-03-13 | CVE-2020-10081 | Incorrect Authorization vulnerability in Gitlab GitLab before 12.8.2 has Incorrect Access Control. | 4.0 |
2020-03-10 | CVE-2019-13003 | Resource Exhaustion vulnerability in Gitlab An issue was discovered in GitLab Community and Enterprise Edition before 12.0.3. | 5.0 |
2020-02-05 | CVE-2020-7973 | Cross-site Scripting vulnerability in Gitlab GitLab through 12.7.2 allows XSS. | 4.3 |