Vulnerability index

Browse CVEs

1,035 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

GitLab MEDIUM 5.9
CVE-2019-13010

An issue was discovered in GitLab Enterprise Edition 8.3 through 12.0.2. The color codes decoder was vulnerable to a resource depletion attack if spe…

Fix: after 12.0.2
Fix from $1,600 2020-03-10
GitLab HIGH 7.5
CVE-2019-12446

An issue was discovered in GitLab Community and Enterprise Edition 8.3 through 11.11. It allows Information Exposure through an Error Message.

Fix: after 11.11.0
Fix from $1,950 2020-03-10
GitLab HIGH 7.5
CVE-2019-13003

An issue was discovered in GitLab Community and Enterprise Edition before 12.0.3. One of the parsers used by Gilab CI was vulnerable to a resource ex…

Fix: 12.0.3+
Fix from $1,950 2020-03-10
GitLab MEDIUM 6.1
CVE-2019-12444

An issue was discovered in GitLab Community and Enterprise Edition 8.9 through 11.11. Wiki Pages contained a lack of input validation which resulted …

Fix: after 11.11.0
Fix from $1,600 2020-03-10
GitLab MEDIUM 5.4
CVE-2019-12445

An issue was discovered in GitLab Community and Enterprise Edition 8.4 through 11.11. A malicious user could execute JavaScript code on notes by impo…

Fix: after 11.11.0
Fix from $1,600 2020-03-10
GitLab MEDIUM 5.3
CVE-2019-13004

An issue was discovered in GitLab Community and Enterprise Edition 11.10 through 12.0.2. When specific encoded characters were added to comments, the…

Fix: after 12.0.2
Fix from $1,600 2020-03-10
GitLab CRITICAL 9.8
CVE-2019-12443

An issue was discovered in GitLab Community and Enterprise Edition 10.2 through 11.11. Multiple features contained Server-Side Request Forgery (SSRF)…

Fix: after 11.11.0
Fix from $2,300 2020-03-10
GitLab HIGH 7.5
CVE-2019-12441

An issue was discovered in GitLab Community and Enterprise Edition 8.4 through 11.11. The protected branches feature contained a access control issue…

Fix: after 11.11.0
Fix from $1,950 2020-03-10
GitLab MEDIUM 6.1
CVE-2019-12442

An issue was discovered in GitLab Enterprise Edition 11.7 through 11.11. The epic details page contained a lack of input validation and output encodi…

Fix: after 11.11.0
Fix from $1,600 2020-03-10
GitLab CRITICAL 9.8
CVE-2019-12428

An issue was discovered in GitLab Community and Enterprise Edition 6.8 through 11.11. Users could bypass the mandatory external authentication provid…

Fix: after 11.11.0
Fix from $2,300 2020-03-10
GitLab HIGH 8.8
CVE-2019-12430

An issue was discovered in GitLab Community and Enterprise Edition 11.11. A specially crafted payload would allow an authenticated malicious user to …

Mitigation only
Fix from $1,950 2020-03-10
GitLab MEDIUM 6.5
CVE-2019-12429

An issue was discovered in GitLab Community and Enterprise Edition 11.9 through 11.11. Unprivileged users were able to access labels, status and merg…

Fix: after 11.11.0
Fix from $1,600 2020-03-10
GitLab MEDIUM 5.3
CVE-2019-12433

An issue was discovered in GitLab Community and Enterprise Edition 11.7 through 11.11. It has Improper Input Validation. Restricted visibility settin…

Fix: after 11.11.0
Fix from $1,600 2020-03-10
GitLab CRITICAL 9.8
CVE-2020-8113

GitLab 10.7 and later through 12.7.2 has Incorrect Access Control.

Fix: 12.6.8+
Fix from $2,300 2020-03-06
GitLab HIGH 7.5
CVE-2020-8795

In GitLab Enterprise Edition (EE) 12.5.0 through 12.7.5, sharing a group with a group could grant project access to unauthorized users.

Fix: after 12.7.5
Fix from $1,950 2020-02-17
GitLab HIGH 7.5
CVE-2020-6833

An issue was discovered in GitLab EE 11.3 and later. A GitLab Workhorse bypass could lead to package and file disclosure via request smuggling.

Fix: 12.5.9 / 12.6.6+
Fix from $1,950 2020-02-05
GitLab HIGH 7.5
CVE-2020-7972

GitLab EE 12.2 has Insecure Permissions (issue 2 of 2).

Fix: 12.5.9 / 12.6.6+
Fix from $1,950 2020-02-05
GitLab HIGH 7.5
CVE-2020-7978

GitLab EE 12.6 and later through 12.7.2 allows Denial of Service.

Fix: 12.6.6+
Fix from $1,950 2020-02-05
GitLab MEDIUM 6.1
CVE-2020-7971

GitLab EE 11.0 and later through 12.7.2 allows XSS.

Fix: 12.5.9 / 12.6.6+
Fix from $1,600 2020-02-05
GitLab MEDIUM 6.1
CVE-2020-7973

GitLab through 12.7.2 allows XSS.

Fix: 12.5.9 / 12.6.6+
Fix from $1,600 2020-02-05
GitLab MEDIUM 5.3
CVE-2020-7974

GitLab EE 10.1 through 12.7.2 allows Information Disclosure.

Fix: 12.5.9 / 12.6.6+
Fix from $1,600 2020-02-05
GitLab MEDIUM 5.3
CVE-2020-7976

GitLab EE 12.4 and later through 12.7.2 has Incorrect Access Control.

Fix: 12.5.9 / 12.6.6+
Fix from $1,600 2020-02-05
GitLab MEDIUM 5.3
CVE-2020-7977

GitLab EE 8.8 and later through 12.7.2 has Insecure Permissions.

Fix: 12.5.9 / 12.6.6+
Fix from $1,600 2020-02-05
GitLab HIGH 7.5
CVE-2020-7966

GitLab EE 11.11 and later through 12.7.2 allows Directory Traversal.

Fix: 12.5.9 / 12.6.6+
Fix from $1,950 2020-02-05
GitLab HIGH 7.5
CVE-2020-7968

GitLab EE 8.0 through 12.7.2 has Incorrect Access Control.

Fix: 12.5.9 / 12.6.6+
Fix from $1,950 2020-02-05
GitLab HIGH 7.5
CVE-2020-7969

GitLab EE 8.0 and later through 12.7.2 allows Information Disclosure.

Fix: 12.5.9 / 12.6.6+
Fix from $1,950 2020-02-05
GitLab CRITICAL 9.8
CVE-2020-8114

GitLab EE 8.9 and later through 12.7.2 has Insecure Permission

Fix: 12.5.9 / 12.6.6+
Fix from $2,300 2020-02-05
GitLab MEDIUM 5.3
CVE-2020-7979

GitLab EE 8.9 and later through 12.7.2 has Insecure Permission

Fix: 12.5.9 / 12.6.6+
Fix from $1,600 2020-02-05
GitLab HIGH 8.8
CVE-2013-4583

The parse_cmd function in lib/gitlab_shell.rb in GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, and Enterprise Edition before 6.2.1 and git…

Fix: 1.7.8 / 5.4.2+
Fix from $1,950 2020-01-28
GitLab MEDIUM 6.5
CVE-2013-4582

The (1) create_branch, (2) create_tag, (3) import_project, and (4) fork_project functions in lib/gitlab_projects.rb in GitLab 5.0 before 5.4.2, Commu…

Fix: 1.7.8 / 5.4.2+
Fix from $1,600 2020-01-28