Vulnerabilities > Gitlab

DATE CVE VULNERABILITY TITLE RISK
2019-12-26 CVE-2018-20492 Incorrect Authorization vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1.
network
low complexity
gitlab CWE-863
5.0
2019-12-20 CVE-2019-15584 Resource Exhaustion vulnerability in Gitlab
A denial of service exists in gitlab <v12.3.2, <v12.2.6, and <v12.1.10 that would let an attacker bypass input validation in markdown fields take down the affected page.
network
low complexity
gitlab CWE-400
4.0
2019-12-18 CVE-2019-5487 Unspecified vulnerability in Gitlab
An improper access control vulnerability exists in Gitlab EE <v12.3.3, <v12.2.7, & <v12.1.13 that allowed the group search feature with Elasticsearch to return private code, merge requests and commits.
network
low complexity
gitlab
5.0
2019-12-18 CVE-2019-5486 Improper Authentication vulnerability in Gitlab
A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.10 in the Salesforce login integration that could be used by an attacker to create an account that bypassed domain restrictions and email verification requirements.
network
low complexity
gitlab CWE-287
6.5
2019-12-18 CVE-2019-5469 Authorization Bypass Through User-Controlled Key vulnerability in Gitlab
An IDOR vulnerability exists in GitLab <v12.1.2, <v12.0.4, and <v11.11.6 that allowed uploading files from project archive to replace other users files potentially allowing an attacker to replace project binaries or other uploaded assets.
network
low complexity
gitlab CWE-639
5.5
2019-12-18 CVE-2019-15591 Unspecified vulnerability in Gitlab
An improper access control vulnerability exists in GitLab <12.3.3 that allows an attacker to obtain container and dependency scanning reports through the merge request widget even though public pipelines were disabled.
network
low complexity
gitlab
4.0
2019-12-18 CVE-2019-15589 Unspecified vulnerability in Gitlab
An improper access control vulnerability exists in Gitlab <v12.3.2, <v12.2.6, <v12.1.12 which would allow a blocked user would be able to use GIT clone and pull if he had obtained a CI/CD token before.
network
low complexity
gitlab
6.5
2019-12-18 CVE-2019-15580 Information Exposure vulnerability in Gitlab
An information exposure vulnerability exists in gitlab.com <v12.3.2, <v12.2.6, and <v12.1.10 when using the blocking merge request feature, it was possible for an unauthenticated user to see the head pipeline data of a public project even though pipeline visibility was restricted.
network
low complexity
gitlab CWE-200
4.0
2019-12-18 CVE-2019-15577 Improper Restriction of Excessive Authentication Attempts vulnerability in Gitlab
An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed project milestones to be disclosed via groups browsing.
network
low complexity
gitlab CWE-307
4.0
2019-12-18 CVE-2019-15576 Missing Authorization vulnerability in Gitlab
An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to view private system notes from a GraphQL endpoint.
network
low complexity
gitlab CWE-862
5.0