Vulnerabilities > Gitlab > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-01-03 | CVE-2019-19260 | Unspecified vulnerability in Gitlab GitLab Community Edition (CE) and Enterprise Edition (EE) through 12.5 has Incorrect Access Control (issue 2 of 2). | 5.4 |
2020-01-03 | CVE-2019-19259 | Authorization Bypass Through User-Controlled Key vulnerability in Gitlab GitLab Enterprise Edition (EE) 11.3 and later through 12.5 allows an Insecure Direct Object Reference (IDOR). | 4.3 |
2020-01-03 | CVE-2019-19258 | Unspecified vulnerability in Gitlab GitLab Enterprise Edition (EE) 10.8 and later through 12.5 has Incorrect Access Control. | 5.3 |
2020-01-03 | CVE-2019-19257 | Unspecified vulnerability in Gitlab GitLab Community Edition (CE) and Enterprise Edition (EE) through 12.5 has Incorrect Access Control (issue 1 of 2). | 5.3 |
2020-01-03 | CVE-2019-19256 | Information Exposure vulnerability in Gitlab GitLab Enterprise Edition (EE) 12.2 and later through 12.5 has Incorrect Access Control. | 5.3 |
2020-01-03 | CVE-2019-19255 | Unspecified vulnerability in Gitlab GitLab Enterprise Edition (EE) 12.3 and later through 12.5 has Incorrect Access Control. | 4.3 |
2020-01-03 | CVE-2019-19311 | Cross-site Scripting vulnerability in Gitlab GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 allows XSS in group and profile fields. | 5.4 |
2020-01-03 | CVE-2019-19254 | Information Exposure vulnerability in Gitlab GitLab Community Edition (CE) and Enterprise Edition (EE). | 5.3 |
2020-01-03 | CVE-2019-19087 | Incorrect Permission Assignment for Critical Resource vulnerability in Gitlab Gitlab Enterprise Edition (EE) before 12.5.1 has Insecure Permissions (issue 2 of 2). | 4.3 |
2020-01-03 | CVE-2019-19086 | Incorrect Permission Assignment for Critical Resource vulnerability in Gitlab Gitlab Enterprise Edition (EE) before 12.5.1 has Insecure Permissions (issue 1 of 2). | 4.3 |