Vulnerability index

Browse CVEs

1,035 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

GitLab HIGH 8.8
CVE-2019-5468

An privilege escalation issue was discovered in Gitlab versions < 12.1.2, < 12.0.4, and < 11.11.6 when Mattermost slash commands are used with a bloc…

Fix: 11.11.6 / 12.0.4+
Fix from $1,950 2020-01-28
GitLab HIGH 7.5
CVE-2019-5470

An information disclosure issue was discovered GitLab versions < 12.1.2, < 12.0.4, and < 11.11.6 in the security dashboard which could result in disc…

Fix: 11.11.6 / 12.0.4+
Fix from $1,950 2020-01-28
GitLab HIGH 7.5
CVE-2019-5472

An authorization issue was discovered in Gitlab versions < 12.1.2, < 12.0.4, and < 11.11.6 that prevented owners and maintainer to delete epic commen…

Fix: 11.11.6 / 12.0.4+
Fix from $1,950 2020-01-28
GitLab MEDIUM 6.5
CVE-2019-5474

An authorization issue was discovered in GitLab EE < 12.1.2, < 12.0.4, and < 11.11.6 allowing the merge request approval rules to be overridden witho…

Fix: 11.11.6 / 12.0.4+
Fix from $1,600 2020-01-28
GitLab CRITICAL 9.8
CVE-2019-15585

Improper authentication exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) in the GitLab SAML …

Fix: 12.1.12 / 12.2.6+
Fix from $2,300 2020-01-28
GitLab CRITICAL 9.8
CVE-2019-5464

A flawed DNS rebinding protection issue was discovered in GitLab CE/EE 10.2 and later in the `url_blocker.rb` which could result in SSRF where the li…

Fix: 11.11.7+
Fix from $2,300 2020-01-28
GitLab HIGH 8.8
CVE-2019-5462

A privilege escalation issue was discovered in GitLab CE/EE 9.0 and later when trigger tokens are not rotated once ownership of them has changed.

Fix: 11.11.7+
Fix from $1,950 2020-01-28
GitLab HIGH 7.5
CVE-2019-15583

An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE). When an issue wa…

Fix: 12.1.12 / 12.2.6+
Fix from $1,950 2020-01-28
GitLab HIGH 7.5
CVE-2019-15590

An access control issue exists in < 12.3.5, < 12.2.8, and < 12.1.14 for GitLab Community Edition (CE) and Enterprise Edition (EE) where private merge…

Fix: 12.1.14 / 12.2.8+
Fix from $1,950 2020-01-28
GitLab MEDIUM 6.1
CVE-2019-15586

A XSS exists in Gitlab CE/EE < 12.1.10 in the Mermaid plugin.

Fix: 12.1.10+
Fix from $1,600 2020-01-28
GitLab MEDIUM 5.3
CVE-2019-15578

An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE). The path of a pr…

Fix: 12.1.12 / 12.2.6+
Fix from $1,600 2020-01-28
GitLab MEDIUM 5.3
CVE-2019-15579

An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) where the assigne…

Fix: 12.1.12 / 12.2.6+
Fix from $1,600 2020-01-28
GitLab MEDIUM 5.3
CVE-2019-15581

An IDOR exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) that allowed a project owner or mai…

Fix: 12.1.12 / 12.2.6+
Fix from $1,600 2020-01-28
GitLab MEDIUM 5.3
CVE-2019-15582

An IDOR was discovered in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) that allowed a maintainer t…

Fix: 12.1.12 / 12.2.6+
Fix from $1,600 2020-01-28
GitLab MEDIUM 5.3
CVE-2019-20143

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 12.6. It has Incorrect Access Control.

No fix yet
Fix from $1,600 2020-01-13
GitLab MEDIUM 5.3
CVE-2020-6832

An issue was discovered in GitLab Enterprise Edition (EE) 8.9.0 through 12.6.1. Using the project import feature, it was possible for someone to obta…

Fix: after 12.6.1
Fix from $1,600 2020-01-13
GitLab MEDIUM 5.3
CVE-2019-20146

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 11.0 through 12.6. It allows Uncontrolled Resource Consumption.

Fix: after 12.6.0
Fix from $1,600 2020-01-13
GitLab MEDIUM 5.3
CVE-2019-20147

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 9.1 through 12.6.1. It has Incorrect Access Control.

Fix: after 12.6.1
Fix from $1,600 2020-01-13
GitLab MEDIUM 5.3
CVE-2019-20148

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 8.13 through 12.6.1. It has Incorrect Access Control.

Fix: after 12.6.1
Fix from $1,600 2020-01-13
GitLab CRITICAL 9.8
CVE-2019-19628

In GitLab EE 11.3 through 12.5.3, 12.4.5, and 12.3.8, insufficient parameter sanitization for the Maven package registry could lead to privilege esca…

Fix: after 12.5.3
Fix from $2,300 2020-01-05
GitLab HIGH 7.5
CVE-2019-19313

GitLab EE 12.3 through 12.5, 12.4.3, and 12.3.6 allows Denial of Service. Certain characters were making it impossible to create, edit, or view issue…

Fix: 12.3.8 / 12.4.5+
Fix from $1,950 2020-01-05
GitLab HIGH 7.5
CVE-2019-19314

GitLab EE 8.4 through 12.5, 12.4.3, and 12.3.6 stored several tokens in plaintext.

Fix: 12.3.8 / 12.4.5+
Fix from $1,950 2020-01-05
GitLab HIGH 7.5
CVE-2019-19629

In GitLab EE 10.5 through 12.5.3, 12.4.5, and 12.3.8, when transferring a public project to a private group, private code would be disclosed via the …

Fix: after 12.5.3
Fix from $1,950 2020-01-05
GitLab MEDIUM 5.8
CVE-2019-19312

GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 has Incorrect Access Control. After a project changed to private, previously forked repositories were…

Fix: 12.3.8 / 12.4.5+
Fix from $1,600 2020-01-05
GitLab HIGH 8.8
CVE-2019-19261

GitLab Enterprise Edition (EE) 6.7 and later through 12.5 allows SSRF.

Fix: 12.5.1+
Fix from $1,950 2020-01-03
GitLab MEDIUM 5.4
CVE-2019-19260

GitLab Community Edition (CE) and Enterprise Edition (EE) through 12.5 has Incorrect Access Control (issue 2 of 2).

Fix: 12.5.1+
Fix from $1,600 2020-01-03
GitLab MEDIUM 5.3
CVE-2019-19256

GitLab Enterprise Edition (EE) 12.2 and later through 12.5 has Incorrect Access Control.

Fix: 12.5.1+
Fix from $1,600 2020-01-03
GitLab MEDIUM 5.3
CVE-2019-19257

GitLab Community Edition (CE) and Enterprise Edition (EE) through 12.5 has Incorrect Access Control (issue 1 of 2).

Fix: 12.5.1+
Fix from $1,600 2020-01-03
GitLab MEDIUM 5.3
CVE-2019-19258

GitLab Enterprise Edition (EE) 10.8 and later through 12.5 has Incorrect Access Control.

Fix: 12.5.1+
Fix from $1,600 2020-01-03
GitLab MEDIUM 5.4
CVE-2019-19311

GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 allows XSS in group and profile fields.

Fix: 12.3.7 / 12.4.4+
Fix from $1,600 2020-01-03