Vulnerabilities > Gitlab > Gitlab > 7.3.2
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-02-05 | CVE-2020-7973 | Cross-site Scripting vulnerability in Gitlab GitLab through 12.7.2 allows XSS. | 4.3 |
2020-02-05 | CVE-2020-7968 | Improper Authentication vulnerability in Gitlab GitLab EE 8.0 through 12.7.2 has Incorrect Access Control. | 5.0 |
2020-01-13 | CVE-2020-5197 | Incorrect Authorization vulnerability in Gitlab An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 5.1 through 12.6.1. | 3.5 |
2020-01-03 | CVE-2019-19260 | Unspecified vulnerability in Gitlab GitLab Community Edition (CE) and Enterprise Edition (EE) through 12.5 has Incorrect Access Control (issue 2 of 2). | 5.5 |
2020-01-03 | CVE-2019-19257 | Information Exposure vulnerability in Gitlab GitLab Community Edition (CE) and Enterprise Edition (EE) through 12.5 has Incorrect Access Control (issue 1 of 2). | 5.0 |
2019-12-20 | CVE-2019-15584 | Resource Exhaustion vulnerability in Gitlab A denial of service exists in gitlab <v12.3.2, <v12.2.6, and <v12.1.10 that would let an attacker bypass input validation in markdown fields take down the affected page. | 4.0 |
2019-12-18 | CVE-2019-5486 | Improper Authentication vulnerability in Gitlab A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.10 in the Salesforce login integration that could be used by an attacker to create an account that bypassed domain restrictions and email verification requirements. | 6.5 |
2019-12-18 | CVE-2019-15591 | Unspecified vulnerability in Gitlab An improper access control vulnerability exists in GitLab <12.3.3 that allows an attacker to obtain container and dependency scanning reports through the merge request widget even though public pipelines were disabled. | 4.0 |
2019-12-18 | CVE-2019-15589 | Unspecified vulnerability in Gitlab An improper access control vulnerability exists in Gitlab <v12.3.2, <v12.2.6, <v12.1.12 which would allow a blocked user would be able to use GIT clone and pull if he had obtained a CI/CD token before. | 6.5 |
2019-12-18 | CVE-2019-15580 | Information Exposure vulnerability in Gitlab An information exposure vulnerability exists in gitlab.com <v12.3.2, <v12.2.6, and <v12.1.10 when using the blocking merge request feature, it was possible for an unauthenticated user to see the head pipeline data of a public project even though pipeline visibility was restricted. | 4.0 |