Filtered by vendor Gitlab Subscriptions
Total 981 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2019-15589 1 Gitlab 1 Gitlab 2019-12-27 8.8 High
An improper access control vulnerability exists in Gitlab <v12.3.2, <v12.2.6, <v12.1.12 which would allow a blocked user would be able to use GIT clone and pull if he had obtained a CI/CD token before.
CVE-2019-15733 1 Gitlab 1 Gitlab 2019-12-17 4.3 Medium
An issue was discovered in GitLab Community and Enterprise Edition 7.12 through 12.2.1. The specified default branch name could be exposed to unauthorized users.
CVE-2019-18461 1 Gitlab 1 Gitlab 2019-12-03 4.3 Medium
An issue was discovered in GitLab Community and Enterprise Edition 11.3 through 12.3 when a sub group epic is added to a public group. It has Incorrect Access Control.
CVE-2019-18463 1 Gitlab 1 Gitlab 2019-12-03 4.3 Medium
An issue was discovered in GitLab Community and Enterprise Edition through 12.4. It has Insecure Permissions (issue 4 of 4).
CVE-2019-18459 1 Gitlab 1 Gitlab 2019-12-03 5.3 Medium
An issue was discovered in GitLab Community and Enterprise Edition 11.3 to 12.3 in the protected environments feature. It has Insecure Permissions (issue 3 of 4).
CVE-2019-18460 1 Gitlab 1 Gitlab 2019-11-27 7.5 High
An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.4 in the Comments Search feature provided by the Elasticsearch integration. It has Incorrect Access Control.
CVE-2019-18450 1 Gitlab 1 Gitlab 2019-11-27 4.3 Medium
An issue was discovered in GitLab Community and Enterprise Edition before 12.4 in the Project labels feature. It has Insecure Permissions.
CVE-2019-18451 1 Gitlab 1 Gitlab 2019-11-27 6.1 Medium
An issue was discovered in GitLab Community and Enterprise Edition 10.7.4 through 12.4 in the InternalRedirect filtering feature. It has an Open Redirect.
CVE-2019-18452 1 Gitlab 1 Gitlab 2019-11-27 5.3 Medium
An issue was discovered in GitLab Community and Enterprise Edition 11.3 through 12.4 when moving an issue to a public project from a private one. It has Insecure Permissions.
CVE-2019-18453 1 Gitlab 1 Gitlab 2019-11-27 4.3 Medium
An issue was discovered in GitLab Community and Enterprise Edition 11.6 through 12.4 in the add comments via email feature. It has Insecure Permissions.
CVE-2019-18457 1 Gitlab 1 Gitlab 2019-11-27 8.8 High
An issue was discovered in GitLab Community and Enterprise Edition 11.8 through 12.4 when handling Security tokens.. It has Insecure Permissions.
CVE-2019-18458 1 Gitlab 1 Gitlab 2019-11-27 2.7 Low
An issue was discovered in GitLab Community and Enterprise Edition through 12.4. It has Insecure Permissions (issue 2 of 4).
CVE-2019-18447 1 Gitlab 1 Gitlab 2019-11-27 4.3 Medium
An issue was discovered in GitLab Community and Enterprise Edition before 12.4. It has Insecure Permissions.
CVE-2019-18454 1 Gitlab 1 Gitlab 2019-11-27 6.1 Medium
An issue was discovered in GitLab Community and Enterprise Edition 10.5 through 12.4 in link validation for RDoc wiki pages feature. It has XSS.
CVE-2019-18455 1 Gitlab 1 Gitlab 2019-11-27 7.5 High
An issue was discovered in GitLab Community and Enterprise Edition 11 through 12.4 when building Nested GraphQL queries. It has a large or infinite loop.
CVE-2019-18446 1 Gitlab 1 Gitlab 2019-11-27 4.3 Medium
An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.4. It has Insecure Permissions (issue 1 of 2).
CVE-2017-0927 1 Gitlab 1 Gitlab 2019-10-09 N/A
Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the deployment keys component resulting in unauthorized use of deployment keys by guest users.
CVE-2017-0926 2 Debian, Gitlab 2 Debian Linux, Gitlab 2019-10-09 N/A
Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the Oauth sign-in component resulting in unauthorized user login.
CVE-2017-0925 2 Debian, Gitlab 2 Debian Linux, Gitlab 2019-10-09 N/A
Gitlab Enterprise Edition version 10.1.0 is vulnerable to an insufficiently protected credential issue in the project service integration API endpoint resulting in an information disclosure of plaintext password.
CVE-2017-0924 1 Gitlab 1 Gitlab 2019-10-09 N/A
Gitlab Community Edition version 10.2.4 is vulnerable to lack of input validation in the labels component resulting in persistent cross site scripting.