Vulnerabilities > Gitlab > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-04-08 CVE-2020-10979 Unspecified vulnerability in Gitlab
GitLab EE/CE 11.10 to 12.9 is leaking information on restricted CI pipelines metrics to unauthorized users.
network
low complexity
gitlab
4.3
2020-04-08 CVE-2020-10978 Unspecified vulnerability in Gitlab
GitLab EE/CE 8.11 to 12.9 is leaking information on Issues opened in a public project and then moved to a private project through Web-UI and GraphQL API.
network
low complexity
gitlab
5.3
2020-04-08 CVE-2020-10977 Path Traversal vulnerability in Gitlab
GitLab EE/CE 8.5 to 12.9 is vulnerable to a an path traversal when moving an issue between projects.
local
low complexity
gitlab CWE-22
5.5
2020-04-08 CVE-2020-10975 Unspecified vulnerability in Gitlab
GitLab EE/CE 10.8 to 12.9 is leaking metadata and comments on vulnerabilities to unauthorized users on the vulnerability feedback page.
network
low complexity
gitlab
4.3
2020-03-27 CVE-2020-10955 Missing Authorization vulnerability in multiple products
GitLab EE/CE 11.1 through 12.9 is vulnerable to parameter tampering on an upload feature that allows an unauthorized user to read content available under specific folders.
network
low complexity
gitlab debian CWE-862
6.5
2020-03-27 CVE-2020-10952 Unspecified vulnerability in Gitlab
GitLab EE/CE 8.11 through 12.9.1 allows blocked users to pull/push docker images.
network
low complexity
gitlab
6.5
2020-03-13 CVE-2020-10076 Cross-site Scripting vulnerability in Gitlab
GitLab 12.1 through 12.8.1 allows XSS.
network
low complexity
gitlab CWE-79
6.1
2020-03-13 CVE-2020-10075 Cross-site Scripting vulnerability in Gitlab
GitLab 12.5 through 12.8.1 allows HTML Injection.
network
low complexity
gitlab CWE-79
6.1
2020-03-13 CVE-2020-10092 Cross-site Scripting vulnerability in Gitlab
GitLab 12.1 through 12.8.1 allows XSS.
network
low complexity
gitlab CWE-79
6.1
2020-03-13 CVE-2020-10091 Cross-site Scripting vulnerability in Gitlab
GitLab 9.3 through 12.8.1 allows XSS.
network
low complexity
gitlab CWE-79
6.1