Vulnerabilities > Gitlab

DATE CVE VULNERABILITY TITLE RISK
2020-01-28 CVE-2019-5472 Improper Privilege Management vulnerability in Gitlab
An authorization issue was discovered in Gitlab versions < 12.1.2, < 12.0.4, and < 11.11.6 that prevented owners and maintainer to delete epic comments.
network
low complexity
gitlab CWE-269
7.5
2020-01-28 CVE-2019-5470 Missing Authorization vulnerability in Gitlab
An information disclosure issue was discovered GitLab versions < 12.1.2, < 12.0.4, and < 11.11.6 in the security dashboard which could result in disclosure of vulnerability feedback information.
network
low complexity
gitlab CWE-862
7.5
2020-01-28 CVE-2019-5468 Improper Privilege Management vulnerability in Gitlab
An privilege escalation issue was discovered in Gitlab versions < 12.1.2, < 12.0.4, and < 11.11.6 when Mattermost slash commands are used with a blocked account.
network
low complexity
gitlab CWE-269
8.8
2020-01-28 CVE-2019-5466 Authorization Bypass Through User-Controlled Key vulnerability in Gitlab
An IDOR was discovered in GitLab CE/EE 11.5 and later that allowed new merge requests endpoint to disclose label names.
network
low complexity
gitlab CWE-639
4.3
2020-01-28 CVE-2019-5465 Unspecified vulnerability in Gitlab
An information disclosure issue was discovered in GitLab CE/EE 8.14 and later, by using the move issue feature which could result in disclosure of the newly created issue ID.
network
low complexity
gitlab
4.3
2020-01-28 CVE-2019-5464 Server-Side Request Forgery (SSRF) vulnerability in Gitlab
A flawed DNS rebinding protection issue was discovered in GitLab CE/EE 10.2 and later in the `url_blocker.rb` which could result in SSRF where the library is utilized.
network
low complexity
gitlab CWE-918
critical
9.8
2020-01-28 CVE-2019-5462 Insufficient Session Expiration vulnerability in Gitlab
A privilege escalation issue was discovered in GitLab CE/EE 9.0 and later when trigger tokens are not rotated once ownership of them has changed.
network
low complexity
gitlab CWE-613
8.8
2020-01-28 CVE-2019-15590 Unspecified vulnerability in Gitlab
An access control issue exists in < 12.3.5, < 12.2.8, and < 12.1.14 for GitLab Community Edition (CE) and Enterprise Edition (EE) where private merge requests and issues would be disclosed with the Group Search feature provided by Elasticsearch integration
network
low complexity
gitlab
7.5
2020-01-28 CVE-2019-15586 Cross-site Scripting vulnerability in Gitlab
A XSS exists in Gitlab CE/EE < 12.1.10 in the Mermaid plugin.
network
low complexity
gitlab CWE-79
6.1
2020-01-28 CVE-2019-15585 Improper Authentication vulnerability in Gitlab
Improper authentication exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) in the GitLab SAML integration had a validation issue that permitted an attacker to takeover another user's account.
network
low complexity
gitlab CWE-287
critical
9.8