Vulnerabilities > Gitlab > High

DATE CVE VULNERABILITY TITLE RISK
2020-01-28 CVE-2013-4583 Improper Privilege Management vulnerability in Gitlab and Gitlab-Shell
The parse_cmd function in lib/gitlab_shell.rb in GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, and Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote authenticated users to gain privileges and clone arbitrary repositories.
network
low complexity
gitlab CWE-269
8.8
2020-01-28 CVE-2019-5472 Improper Privilege Management vulnerability in Gitlab
An authorization issue was discovered in Gitlab versions < 12.1.2, < 12.0.4, and < 11.11.6 that prevented owners and maintainer to delete epic comments.
network
low complexity
gitlab CWE-269
7.5
2020-01-28 CVE-2019-5470 Missing Authorization vulnerability in Gitlab
An information disclosure issue was discovered GitLab versions < 12.1.2, < 12.0.4, and < 11.11.6 in the security dashboard which could result in disclosure of vulnerability feedback information.
network
low complexity
gitlab CWE-862
7.5
2020-01-28 CVE-2019-5468 Improper Privilege Management vulnerability in Gitlab
An privilege escalation issue was discovered in Gitlab versions < 12.1.2, < 12.0.4, and < 11.11.6 when Mattermost slash commands are used with a blocked account.
network
low complexity
gitlab CWE-269
8.8
2020-01-28 CVE-2019-5462 Insufficient Session Expiration vulnerability in Gitlab
A privilege escalation issue was discovered in GitLab CE/EE 9.0 and later when trigger tokens are not rotated once ownership of them has changed.
network
low complexity
gitlab CWE-613
8.8
2020-01-28 CVE-2019-15590 Unspecified vulnerability in Gitlab
An access control issue exists in < 12.3.5, < 12.2.8, and < 12.1.14 for GitLab Community Edition (CE) and Enterprise Edition (EE) where private merge requests and issues would be disclosed with the Group Search feature provided by Elasticsearch integration
network
low complexity
gitlab
7.5
2020-01-28 CVE-2019-15583 Information Exposure vulnerability in Gitlab
An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE).
network
low complexity
gitlab CWE-200
7.5
2020-01-05 CVE-2019-19629 Unspecified vulnerability in Gitlab
In GitLab EE 10.5 through 12.5.3, 12.4.5, and 12.3.8, when transferring a public project to a private group, private code would be disclosed via the Group Search API provided by the Elasticsearch integration.
network
low complexity
gitlab
7.5
2020-01-05 CVE-2019-19314 Cleartext Storage of Sensitive Information vulnerability in Gitlab
GitLab EE 8.4 through 12.5, 12.4.3, and 12.3.6 stored several tokens in plaintext.
network
low complexity
gitlab CWE-312
7.5
2020-01-05 CVE-2019-19313 Improper Handling of Exceptional Conditions vulnerability in Gitlab
GitLab EE 12.3 through 12.5, 12.4.3, and 12.3.6 allows Denial of Service.
network
low complexity
gitlab CWE-755
7.5