Vulnerabilities > Gitlab > High

DATE CVE VULNERABILITY TITLE RISK
2020-01-03 CVE-2019-19261 Server-Side Request Forgery (SSRF) vulnerability in Gitlab
GitLab Enterprise Edition (EE) 6.7 and later through 12.5 allows SSRF.
network
low complexity
gitlab CWE-918
8.8
2019-12-30 CVE-2018-20499 Server-Side Request Forgery (SSRF) vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition before 11.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1.
network
low complexity
gitlab CWE-918
7.2
2019-12-30 CVE-2018-20494 Incorrect Authorization vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1.
network
low complexity
gitlab CWE-863
7.5
2019-12-18 CVE-2019-5486 Improper Authentication vulnerability in Gitlab
A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.10 in the Salesforce login integration that could be used by an attacker to create an account that bypassed domain restrictions and email verification requirements.
network
low complexity
gitlab CWE-287
8.8
2019-12-18 CVE-2019-15589 Unspecified vulnerability in Gitlab
An improper access control vulnerability exists in Gitlab <v12.3.2, <v12.2.6, <v12.1.12 which would allow a blocked user would be able to use GIT clone and pull if he had obtained a CI/CD token before.
network
low complexity
gitlab
8.8
2019-12-18 CVE-2019-15576 Missing Authorization vulnerability in Gitlab
An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to view private system notes from a GraphQL endpoint.
network
low complexity
gitlab CWE-862
7.5
2019-12-18 CVE-2019-15575 Command Injection vulnerability in Gitlab
A command injection exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to inject commands via the API through the blobs scope.
network
low complexity
gitlab CWE-77
7.5
2019-11-26 CVE-2019-18455 Infinite Loop vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition 11 through 12.4 when building Nested GraphQL queries.
network
low complexity
gitlab CWE-835
7.5
2019-11-26 CVE-2019-18457 Improper Preservation of Permissions vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition 11.8 through 12.4 when handling Security tokens..
network
low complexity
gitlab CWE-281
8.8
2019-11-26 CVE-2019-18460 Information Exposure vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.4 in the Comments Search feature provided by the Elasticsearch integration.
network
low complexity
gitlab CWE-200
7.5