Filtered by vendor Gitlab Subscriptions
Total 1068 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2018-8971 2 Debian, Gitlab 2 Debian Linux, Gitlab 2024-08-05 N/A
The Auth0 integration in GitLab before 10.3.9, 10.4.x before 10.4.6, and 10.5.x before 10.5.6 has an incorrect omniauth-auth0 configuration, leading to signing in unintended users.
CVE-2018-8801 1 Gitlab 1 Gitlab 2024-08-05 N/A
GitLab Community and Enterprise Editions version 8.3 up to 10.x before 10.3 are vulnerable to SSRF in the Services and webhooks component.
CVE-2018-3710 2 Debian, Gitlab 2 Debian Linux, Gitlab 2024-08-05 7.8 High
Gitlab Community and Enterprise Editions version 10.3.3 is vulnerable to an Insecure Temporary File in the project import component resulting remote code execution.
CVE-2019-20146 1 Gitlab 1 Gitlab 2024-08-05 5.3 Medium
An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 11.0 through 12.6. It allows Uncontrolled Resource Consumption.
CVE-2019-20148 1 Gitlab 1 Gitlab 2024-08-05 5.3 Medium
An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 8.13 through 12.6.1. It has Incorrect Access Control.
CVE-2019-20143 1 Gitlab 1 Gitlab 2024-08-05 5.3 Medium
An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 12.6. It has Incorrect Access Control.
CVE-2019-20147 1 Gitlab 1 Gitlab 2024-08-05 5.3 Medium
An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 9.1 through 12.6.1. It has Incorrect Access Control.
CVE-2019-20145 1 Gitlab 1 Gitlab 2024-08-05 4.3 Medium
An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 11.4 through 12.6.1. It has Incorrect Access Control.
CVE-2019-20144 1 Gitlab 1 Gitlab 2024-08-05 4.3 Medium
An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 10.8 through 12.6.1. It has Incorrect Access Control.
CVE-2019-20142 1 Gitlab 1 Gitlab 2024-08-05 4.3 Medium
An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 12.3 through 12.6.1. It allows Denial of Service.
CVE-2019-19629 1 Gitlab 1 Gitlab 2024-08-05 7.5 High
In GitLab EE 10.5 through 12.5.3, 12.4.5, and 12.3.8, when transferring a public project to a private group, private code would be disclosed via the Group Search API provided by the Elasticsearch integration.
CVE-2019-19628 1 Gitlab 1 Gitlab 2024-08-05 9.8 Critical
In GitLab EE 11.3 through 12.5.3, 12.4.5, and 12.3.8, insufficient parameter sanitization for the Maven package registry could lead to privilege escalation and remote code execution vulnerabilities under certain conditions.
CVE-2019-19311 1 Gitlab 1 Gitlab 2024-08-05 5.4 Medium
GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 allows XSS in group and profile fields.
CVE-2019-19312 1 Gitlab 1 Gitlab 2024-08-05 5.8 Medium
GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 has Incorrect Access Control. After a project changed to private, previously forked repositories were still able to get information about the private project through the API.
CVE-2019-19309 1 Gitlab 1 Gitlab 2024-08-05 4.3 Medium
GitLab Enterprise Edition (EE) 8.90 and later through 12.5 has Incorrect Access Control.
CVE-2019-19313 1 Gitlab 1 Gitlab 2024-08-05 7.5 High
GitLab EE 12.3 through 12.5, 12.4.3, and 12.3.6 allows Denial of Service. Certain characters were making it impossible to create, edit, or view issues and commits.
CVE-2019-19314 1 Gitlab 1 Gitlab 2024-08-05 7.5 High
GitLab EE 8.4 through 12.5, 12.4.3, and 12.3.6 stored several tokens in plaintext.
CVE-2019-19310 1 Gitlab 1 Gitlab 2024-08-05 4.9 Medium
GitLab Enterprise Edition (EE) 9.0 and later through 12.5 allows Information Disclosure.
CVE-2019-19258 1 Gitlab 1 Gitlab 2024-08-05 5.3 Medium
GitLab Enterprise Edition (EE) 10.8 and later through 12.5 has Incorrect Access Control.
CVE-2019-19262 1 Gitlab 1 Gitlab 2024-08-05 4.3 Medium
GitLab Enterprise Edition (EE) 11.9 and later through 12.5 has Insecure Permissions.