Vulnerabilities > Gitlab > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-12-18 CVE-2019-15577 Improper Restriction of Excessive Authentication Attempts vulnerability in Gitlab
An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed project milestones to be disclosed via groups browsing.
network
low complexity
gitlab CWE-307
4.3
2019-11-26 CVE-2019-18456 Incorrect Permission Assignment for Critical Resource vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition 8.17 through 12.4 in the Search feature provided by Elasticsearch integration..
network
low complexity
gitlab CWE-732
5.3
2019-11-26 CVE-2019-18454 Cross-site Scripting vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition 10.5 through 12.4 in link validation for RDoc wiki pages feature.
network
low complexity
gitlab CWE-79
6.1
2019-11-26 CVE-2019-18453 Incorrect Permission Assignment for Critical Resource vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition 11.6 through 12.4 in the add comments via email feature.
network
low complexity
gitlab CWE-732
4.3
2019-11-26 CVE-2019-18452 Incorrect Permission Assignment for Critical Resource vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition 11.3 through 12.4 when moving an issue to a public project from a private one.
network
low complexity
gitlab CWE-732
5.3
2019-11-26 CVE-2019-18451 Open Redirect vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition 10.7.4 through 12.4 in the InternalRedirect filtering feature.
network
low complexity
gitlab CWE-601
6.1
2019-11-26 CVE-2019-18450 Incorrect Permission Assignment for Critical Resource vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition before 12.4 in the Project labels feature.
network
low complexity
gitlab CWE-732
4.3
2019-11-26 CVE-2019-18449 Incorrect Permission Assignment for Critical Resource vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition before 12.4 in the autocomplete feature.
network
low complexity
gitlab CWE-732
4.3
2019-11-26 CVE-2019-18448 Unspecified vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition before 12.4.
network
low complexity
gitlab
6.5
2019-11-26 CVE-2019-18447 Incorrect Permission Assignment for Critical Resource vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition before 12.4.
network
low complexity
gitlab CWE-732
4.3