Vulnerabilities > Gitlab
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-01-13 | CVE-2019-20148 | Unspecified vulnerability in Gitlab An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 8.13 through 12.6.1. | 5.3 |
2020-01-13 | CVE-2019-20147 | Unspecified vulnerability in Gitlab An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 9.1 through 12.6.1. | 5.3 |
2020-01-13 | CVE-2019-20146 | Resource Exhaustion vulnerability in Gitlab An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 11.0 through 12.6. | 5.3 |
2020-01-13 | CVE-2019-20145 | Unspecified vulnerability in Gitlab An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 11.4 through 12.6.1. | 4.3 |
2020-01-05 | CVE-2019-19629 | Unspecified vulnerability in Gitlab In GitLab EE 10.5 through 12.5.3, 12.4.5, and 12.3.8, when transferring a public project to a private group, private code would be disclosed via the Group Search API provided by the Elasticsearch integration. | 7.5 |
2020-01-05 | CVE-2019-19628 | Path Traversal vulnerability in Gitlab In GitLab EE 11.3 through 12.5.3, 12.4.5, and 12.3.8, insufficient parameter sanitization for the Maven package registry could lead to privilege escalation and remote code execution vulnerabilities under certain conditions. | 9.8 |
2020-01-05 | CVE-2019-19314 | Cleartext Storage of Sensitive Information vulnerability in Gitlab GitLab EE 8.4 through 12.5, 12.4.3, and 12.3.6 stored several tokens in plaintext. | 7.5 |
2020-01-05 | CVE-2019-19313 | Improper Handling of Exceptional Conditions vulnerability in Gitlab GitLab EE 12.3 through 12.5, 12.4.3, and 12.3.6 allows Denial of Service. | 7.5 |
2020-01-05 | CVE-2019-19312 | Unspecified vulnerability in Gitlab GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 has Incorrect Access Control. | 5.8 |
2020-01-03 | CVE-2019-19310 | Insufficiently Protected Credentials vulnerability in Gitlab GitLab Enterprise Edition (EE) 9.0 and later through 12.5 allows Information Disclosure. | 4.9 |