Vulnerabilities > Gitlab

DATE CVE VULNERABILITY TITLE RISK
2019-09-09 CVE-2019-11605 Information Exposure vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition 11.8.x before 11.8.10, 11.9.x before 11.9.11, and 11.10.x before 11.10.3.
network
low complexity
gitlab CWE-200
7.5
2019-09-09 CVE-2019-11549 Information Exposure Through Log Files vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2.
network
low complexity
gitlab CWE-532
6.5
2019-09-09 CVE-2019-11548 Cross-site Scripting vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9.
network
low complexity
gitlab CWE-79
5.4
2019-09-09 CVE-2019-11547 Improper Encoding or Escaping of Output vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2.
network
low complexity
gitlab CWE-116
6.1
2019-09-09 CVE-2019-11546 Race Condition vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2.
network
high complexity
gitlab CWE-362
5.3
2019-09-09 CVE-2019-11545 Information Exposure vulnerability in Gitlab
An issue was discovered in GitLab Community Edition 11.9.x before 11.9.10 and 11.10.x before 11.10.2.
network
low complexity
gitlab CWE-200
4.3
2019-09-09 CVE-2019-11544 Unspecified vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition 8.x, 9.x, 10.x, and 11.x before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2.
network
low complexity
gitlab
4.3
2019-09-09 CVE-2019-5473 Improper Authentication vulnerability in Gitlab 12.0.4/12.1.2
An authentication issue was discovered in GitLab that allowed a bypass of email verification.
network
low complexity
gitlab CWE-287
7.2
2019-09-09 CVE-2019-5471 Cross-site Scripting vulnerability in Gitlab
An input validation and output encoding issue was discovered in the GitLab email notification feature which could result in a persistent XSS.
network
low complexity
gitlab CWE-79
5.4
2019-09-09 CVE-2019-5467 Cross-site Scripting vulnerability in Gitlab
An input validation and output encoding issue was discovered in the GitLab CE/EE wiki pages feature which could result in a persistent XSS.
network
low complexity
gitlab CWE-79
5.4