Vulnerability index

Browse CVEs

1,035 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

GitLab CRITICAL 9.8
CVE-2019-19088

Gitlab Enterprise Edition (EE) 11.3 through 12.4.2 allows Directory Traversal.

Fix: 12.5.1+
Fix from $2,300 2020-01-03
GitLab MEDIUM 5.3
CVE-2019-19254

GitLab Community Edition (CE) and Enterprise Edition (EE). 9.6 and later through 12.5 has Incorrect Access Control.

Fix: 12.5.1+
Fix from $1,600 2020-01-03
GitLab HIGH 7.2
CVE-2018-20499

An issue was discovered in GitLab Community and Enterprise Edition before 11.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It all…

Fix: 11.4.13 / 11.5.6+
Fix from $1,950 2019-12-30
GitLab MEDIUM 6.3
CVE-2018-20501

An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect A…

Fix: 11.4.13 / 11.5.6+
Fix from $1,600 2019-12-30
GitLab MEDIUM 5.3
CVE-2018-20507

An issue was discovered in GitLab Enterprise Edition 11.2.x through 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Inc…

Fix: 11.4.13 / 11.5.6+
Fix from $1,600 2019-12-30
GitLab MEDIUM 5.0
CVE-2018-20497

An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows SSRF.

Fix: 11.4.13 / 11.5.6+
Fix from $1,600 2019-12-30
GitLab HIGH 7.5
CVE-2018-20494

An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect A…

Fix: 11.4.13 / 11.5.6+
Fix from $1,950 2019-12-30
GitLab MEDIUM 5.4
CVE-2018-20490

An issue was discovered in GitLab Community and Enterprise Edition 11.2.x through 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6…

Fix: 11.4.13 / 11.5.6+
Fix from $1,600 2019-12-30
GitLab MEDIUM 5.4
CVE-2018-20491

An issue was discovered in GitLab Enterprise Edition 11.3.x and 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows XSS.

Fix: 11.4.13 / 11.5.6+
Fix from $1,600 2019-12-30
GitLab MEDIUM 5.4
CVE-2018-20496

An issue was discovered in GitLab Community and Enterprise Edition 11.2.x through 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6…

Fix: 11.4.13 / 11.5.6+
Fix from $1,600 2019-12-30
GitLab MEDIUM 5.3
CVE-2018-20489

An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect A…

Fix: 11.4.13 / 11.5.6+
Fix from $1,600 2019-12-30
GitLab MEDIUM 5.3
CVE-2018-20495

An issue was discovered in GitLab Community and Enterprise Edition 11.3.x and 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. …

Fix: 11.4.13 / 11.5.6+
Fix from $1,600 2019-12-30
GitLab MEDIUM 5.3
CVE-2018-20492

An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect A…

Fix: 11.4.13 / 11.5.6+
Fix from $1,600 2019-12-26
GitLab MEDIUM 6.5
CVE-2019-15584

A denial of service exists in gitlab <v12.3.2, <v12.2.6, and <v12.1.10 that would let an attacker bypass input validation in markdown fields take dow…

Fix: 12.1.10 / 12.2.6+
Fix from $1,600 2019-12-20
GitLab HIGH 8.8
CVE-2019-5486

A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.10 in the Salesforce login integration that could be used…

Fix: 12.1.10 / 12.2.6+
Fix from $1,950 2019-12-18
GitLab MEDIUM 6.5
CVE-2019-5469

An IDOR vulnerability exists in GitLab <v12.1.2, <v12.0.4, and <v11.11.6 that allowed uploading files from project archive to replace other users fil…

Fix: 11.11.6 / 12.0.4+
Fix from $1,600 2019-12-18
GitLab MEDIUM 5.3
CVE-2019-5487

An improper access control vulnerability exists in Gitlab EE <v12.3.3, <v12.2.7, & <v12.1.13 that allowed the group search feature with Elasticsearch…

Fix: 12.1.13 / 12.2.7+
Fix from $1,600 2019-12-18
GitLab HIGH 8.8
CVE-2019-15589

An improper access control vulnerability exists in Gitlab <v12.3.2, <v12.2.6, <v12.1.12 which would allow a blocked user would be able to use GIT clo…

Fix: 12.1.12 / 12.2.6+
Fix from $1,950 2019-12-18
GitLab MEDIUM 6.5
CVE-2019-15591

An improper access control vulnerability exists in GitLab <12.3.3 that allows an attacker to obtain container and dependency scanning reports through…

Fix: 12.3.3+
Fix from $1,600 2019-12-18
GitLab HIGH 7.5
CVE-2019-15575

A command injection exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to inject commands via the API through the blob…

Fix: 12.1.12 / 12.2.6+
Fix from $1,950 2019-12-18
GitLab HIGH 7.5
CVE-2019-15576

An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to view private system note…

Fix: 12.1.12 / 12.2.6+
Fix from $1,950 2019-12-18
GitLab MEDIUM 6.5
CVE-2019-15580

An information exposure vulnerability exists in gitlab.com <v12.3.2, <v12.2.6, and <v12.1.10 when using the blocking merge request feature, it was po…

Fix: 12.1.10 / 12.2.6+
Fix from $1,600 2019-12-18
GitLab HIGH 7.5
CVE-2019-18455

An issue was discovered in GitLab Community and Enterprise Edition 11 through 12.4 when building Nested GraphQL queries. It has a large or infinite l…

Fix: after 12.4.0
Fix from $1,950 2019-11-26
GitLab MEDIUM 6.5
CVE-2019-18448

An issue was discovered in GitLab Community and Enterprise Edition before 12.4. It has Incorrect Access Control.

Fix: after 12.4.0
Fix from $1,600 2019-11-26
GitLab MEDIUM 6.1
CVE-2019-18451

An issue was discovered in GitLab Community and Enterprise Edition 10.7.4 through 12.4 in the InternalRedirect filtering feature. It has an Open Redi…

Fix: after 12.4.0
Fix from $1,600 2019-11-26
GitLab MEDIUM 6.1
CVE-2019-18454

An issue was discovered in GitLab Community and Enterprise Edition 10.5 through 12.4 in link validation for RDoc wiki pages feature. It has XSS.

Fix: after 12.4.0
Fix from $1,600 2019-11-26
GitLab MEDIUM 5.3
CVE-2019-18452

An issue was discovered in GitLab Community and Enterprise Edition 11.3 through 12.4 when moving an issue to a public project from a private one. It …

Fix: after 12.4.0
Fix from $1,600 2019-11-26
GitLab MEDIUM 5.3
CVE-2019-18456

An issue was discovered in GitLab Community and Enterprise Edition 8.17 through 12.4 in the Search feature provided by Elasticsearch integration.. It…

Fix: after 12.4.0
Fix from $1,600 2019-11-26
GitLab HIGH 8.8
CVE-2019-18457

An issue was discovered in GitLab Community and Enterprise Edition 11.8 through 12.4 when handling Security tokens.. It has Insecure Permissions.

Fix: after 12.4.0
Fix from $1,950 2019-11-26
GitLab MEDIUM 5.3
CVE-2019-18459

An issue was discovered in GitLab Community and Enterprise Edition 11.3 to 12.3 in the protected environments feature. It has Insecure Permissions (i…

Fix: after 12.3.0
Fix from $1,600 2019-11-26