Vulnerabilities > Gitlab > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-01-03 | CVE-2019-19261 | Server-Side Request Forgery (SSRF) vulnerability in Gitlab GitLab Enterprise Edition (EE) 6.7 and later through 12.5 allows SSRF. | 8.8 |
2019-12-30 | CVE-2018-20499 | Server-Side Request Forgery (SSRF) vulnerability in Gitlab An issue was discovered in GitLab Community and Enterprise Edition before 11.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. | 7.2 |
2019-12-30 | CVE-2018-20494 | Incorrect Authorization vulnerability in Gitlab An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. | 7.5 |
2019-12-18 | CVE-2019-5486 | Improper Authentication vulnerability in Gitlab A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.10 in the Salesforce login integration that could be used by an attacker to create an account that bypassed domain restrictions and email verification requirements. | 8.8 |
2019-12-18 | CVE-2019-15589 | Unspecified vulnerability in Gitlab An improper access control vulnerability exists in Gitlab <v12.3.2, <v12.2.6, <v12.1.12 which would allow a blocked user would be able to use GIT clone and pull if he had obtained a CI/CD token before. | 8.8 |
2019-12-18 | CVE-2019-15576 | Missing Authorization vulnerability in Gitlab An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to view private system notes from a GraphQL endpoint. | 7.5 |
2019-12-18 | CVE-2019-15575 | Command Injection vulnerability in Gitlab A command injection exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to inject commands via the API through the blobs scope. | 7.5 |
2019-11-26 | CVE-2019-18455 | Infinite Loop vulnerability in Gitlab An issue was discovered in GitLab Community and Enterprise Edition 11 through 12.4 when building Nested GraphQL queries. | 7.5 |
2019-11-26 | CVE-2019-18457 | Improper Preservation of Permissions vulnerability in Gitlab An issue was discovered in GitLab Community and Enterprise Edition 11.8 through 12.4 when handling Security tokens.. | 8.8 |
2019-11-26 | CVE-2019-18460 | Information Exposure vulnerability in Gitlab An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.4 in the Comments Search feature provided by the Elasticsearch integration. | 7.5 |