Vulnerabilities > Gitlab > Gitlab > 5.2.1

DATE CVE VULNERABILITY TITLE RISK
2020-02-05 CVE-2020-7968 Improper Authentication vulnerability in Gitlab
GitLab EE 8.0 through 12.7.2 has Incorrect Access Control.
network
low complexity
gitlab CWE-287
5.0
2020-01-28 CVE-2013-4583 Improper Privilege Management vulnerability in Gitlab and Gitlab-Shell
The parse_cmd function in lib/gitlab_shell.rb in GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, and Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote authenticated users to gain privileges and clone arbitrary repositories.
network
low complexity
gitlab CWE-269
6.5
2020-01-28 CVE-2013-4582 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Gitlab and Gitlab-Shell
The (1) create_branch, (2) create_tag, (3) import_project, and (4) fork_project functions in lib/gitlab_projects.rb in GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote authenticated users to include information from local files into the metadata of a Git repository via the web interface.
network
low complexity
gitlab CWE-829
4.0
2020-01-13 CVE-2020-5197 Incorrect Authorization vulnerability in Gitlab
An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 5.1 through 12.6.1.
network
gitlab CWE-863
3.5
2020-01-03 CVE-2019-19260 Unspecified vulnerability in Gitlab
GitLab Community Edition (CE) and Enterprise Edition (EE) through 12.5 has Incorrect Access Control (issue 2 of 2).
network
low complexity
gitlab
5.5
2020-01-03 CVE-2019-19257 Information Exposure vulnerability in Gitlab
GitLab Community Edition (CE) and Enterprise Edition (EE) through 12.5 has Incorrect Access Control (issue 1 of 2).
network
low complexity
gitlab CWE-200
5.0
2019-12-20 CVE-2019-15584 Resource Exhaustion vulnerability in Gitlab
A denial of service exists in gitlab <v12.3.2, <v12.2.6, and <v12.1.10 that would let an attacker bypass input validation in markdown fields take down the affected page.
network
low complexity
gitlab CWE-400
4.0
2019-12-18 CVE-2019-5486 Improper Authentication vulnerability in Gitlab
A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.10 in the Salesforce login integration that could be used by an attacker to create an account that bypassed domain restrictions and email verification requirements.
network
low complexity
gitlab CWE-287
6.5
2019-12-18 CVE-2019-15591 Unspecified vulnerability in Gitlab
An improper access control vulnerability exists in GitLab <12.3.3 that allows an attacker to obtain container and dependency scanning reports through the merge request widget even though public pipelines were disabled.
network
low complexity
gitlab
4.0
2019-12-18 CVE-2019-15589 Unspecified vulnerability in Gitlab
An improper access control vulnerability exists in Gitlab <v12.3.2, <v12.2.6, <v12.1.12 which would allow a blocked user would be able to use GIT clone and pull if he had obtained a CI/CD token before.
network
low complexity
gitlab
6.5