Vulnerabilities > Gitlab

DATE CVE VULNERABILITY TITLE RISK
2020-01-05 CVE-2019-19312 Information Exposure vulnerability in Gitlab
GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 has Incorrect Access Control.
network
low complexity
gitlab CWE-200
5.0
2020-01-03 CVE-2019-19310 Insufficiently Protected Credentials vulnerability in Gitlab
GitLab Enterprise Edition (EE) 9.0 and later through 12.5 allows Information Disclosure.
network
low complexity
gitlab CWE-522
4.0
2020-01-03 CVE-2019-19309 Information Exposure vulnerability in Gitlab
GitLab Enterprise Edition (EE) 8.90 and later through 12.5 has Incorrect Access Control.
network
low complexity
gitlab CWE-200
4.0
2020-01-03 CVE-2019-19263 Incorrect Permission Assignment for Critical Resource vulnerability in Gitlab
GitLab Enterprise Edition (EE) 8.2 and later through 12.5 has Insecure Permissions.
network
low complexity
gitlab CWE-732
4.0
2020-01-03 CVE-2019-19262 Incorrect Permission Assignment for Critical Resource vulnerability in Gitlab
GitLab Enterprise Edition (EE) 11.9 and later through 12.5 has Insecure Permissions.
network
low complexity
gitlab CWE-732
4.0
2020-01-03 CVE-2019-19261 Server-Side Request Forgery (SSRF) vulnerability in Gitlab
GitLab Enterprise Edition (EE) 6.7 and later through 12.5 allows SSRF.
network
gitlab CWE-918
6.8
2020-01-03 CVE-2019-19260 Unspecified vulnerability in Gitlab
GitLab Community Edition (CE) and Enterprise Edition (EE) through 12.5 has Incorrect Access Control (issue 2 of 2).
network
low complexity
gitlab
5.5
2020-01-03 CVE-2019-19259 Authorization Bypass Through User-Controlled Key vulnerability in Gitlab
GitLab Enterprise Edition (EE) 11.3 and later through 12.5 allows an Insecure Direct Object Reference (IDOR).
network
low complexity
gitlab CWE-639
4.0
2020-01-03 CVE-2019-19258 Information Exposure vulnerability in Gitlab
GitLab Enterprise Edition (EE) 10.8 and later through 12.5 has Incorrect Access Control.
network
low complexity
gitlab CWE-200
5.0
2020-01-03 CVE-2019-19257 Information Exposure vulnerability in Gitlab
GitLab Community Edition (CE) and Enterprise Edition (EE) through 12.5 has Incorrect Access Control (issue 1 of 2).
network
low complexity
gitlab CWE-200
5.0