Filtered by vendor Gitlab Subscriptions
Total 1068 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2020-10079 1 Gitlab 1 Gitlab 2024-08-04 5.3 Medium
GitLab 7.10 through 12.8.1 has Incorrect Access Control. Under certain conditions where users should have been required to configure two-factor authentication, it was not being required.
CVE-2020-10091 1 Gitlab 1 Gitlab 2024-08-04 6.1 Medium
GitLab 9.3 through 12.8.1 allows XSS. A cross-site scripting vulnerability was found when viewing particular file types.
CVE-2020-10092 1 Gitlab 1 Gitlab 2024-08-04 6.1 Medium
GitLab 12.1 through 12.8.1 allows XSS. A cross-site scripting vulnerability was present in a particular view relating to the Grafana integration.
CVE-2020-10089 1 Gitlab 1 Gitlab 2024-08-04 7.5 High
GitLab 8.11 through 12.8.1 allows a Denial of Service when using several features to recursively request eachother,
CVE-2020-10073 1 Gitlab 1 Gitlab 2024-08-04 7.5 High
GitLab EE 12.4.2 through 12.8.1 allows Denial of Service. It was internally discovered that a potential denial of service involving permissions checks could impact a project home page.
CVE-2020-10090 1 Gitlab 1 Gitlab 2024-08-04 5.3 Medium
GitLab 11.7 through 12.8.1 allows Information Disclosure. Under certain group conditions, group epic information was unintentionally being disclosed.
CVE-2020-10084 1 Gitlab 1 Gitlab 2024-08-04 5.3 Medium
GitLab EE 11.6 through 12.8.1 allows Information Disclosure. Sending a specially crafted request to the vulnerability_feedback endpoint could result in the exposure of a private project namespace
CVE-2020-10074 1 Gitlab 1 Gitlab 2024-08-04 9.8 Critical
GitLab 10.1 through 12.8.1 has Incorrect Access Control. A scenario was discovered in which a GitLab account could be taken over through an expired link.
CVE-2020-10083 1 Gitlab 1 Gitlab 2024-08-04 9.1 Critical
GitLab 12.7 through 12.8.1 has Insecure Permissions. Under certain conditions involving groups, project authorization changes were not being applied.
CVE-2020-10078 1 Gitlab 1 Gitlab 2024-08-04 6.1 Medium
GitLab 12.1 through 12.8.1 allows XSS. The merge request submission form was determined to have a stored cross-site scripting vulnerability.
CVE-2020-8795 1 Gitlab 1 Gitlab 2024-08-04 7.5 High
In GitLab Enterprise Edition (EE) 12.5.0 through 12.7.5, sharing a group with a group could grant project access to unauthorized users.
CVE-2020-8114 1 Gitlab 1 Gitlab 2024-08-04 9.8 Critical
GitLab EE 8.9 and later through 12.7.2 has Insecure Permission
CVE-2020-8113 1 Gitlab 1 Gitlab 2024-08-04 9.8 Critical
GitLab 10.7 and later through 12.7.2 has Incorrect Access Control.
CVE-2020-7979 1 Gitlab 1 Gitlab 2024-08-04 5.3 Medium
GitLab EE 8.9 and later through 12.7.2 has Insecure Permission
CVE-2020-7968 1 Gitlab 1 Gitlab 2024-08-04 7.5 High
GitLab EE 8.0 through 12.7.2 has Incorrect Access Control.
CVE-2020-7973 1 Gitlab 1 Gitlab 2024-08-04 6.1 Medium
GitLab through 12.7.2 allows XSS.
CVE-2020-7969 1 Gitlab 1 Gitlab 2024-08-04 7.5 High
GitLab EE 8.0 and later through 12.7.2 allows Information Disclosure.
CVE-2020-7976 1 Gitlab 1 Gitlab 2024-08-04 5.3 Medium
GitLab EE 12.4 and later through 12.7.2 has Incorrect Access Control.
CVE-2020-7967 1 Gitlab 1 Gitlab 2024-08-04 4.3 Medium
GitLab EE 8.0 through 12.7.2 has Insecure Permissions (issue 1 of 2).
CVE-2020-7974 1 Gitlab 1 Gitlab 2024-08-04 5.3 Medium
GitLab EE 10.1 through 12.7.2 allows Information Disclosure.