Количество 5 336
Количество 5 336
CVE-2019-12430
An issue was discovered in GitLab Community and Enterprise Edition 11. ...
CVE-2019-12429
An issue was discovered in GitLab Community and Enterprise Edition 11.9 through 11.11. Unprivileged users were able to access labels, status and merge request counts of confidential issues via the milestone details page. It has Improper Access Control.
CVE-2019-12429
An issue was discovered in GitLab Community and Enterprise Edition 11.9 through 11.11. Unprivileged users were able to access labels, status and merge request counts of confidential issues via the milestone details page. It has Improper Access Control.
CVE-2019-12429
An issue was discovered in GitLab Community and Enterprise Edition 11. ...
CVE-2019-12428
An issue was discovered in GitLab Community and Enterprise Edition 6.8 through 11.11. Users could bypass the mandatory external authentication provider sign-in restrictions by sending a specially crafted request. It has Improper Authorization.
CVE-2019-12428
An issue was discovered in GitLab Community and Enterprise Edition 6.8 through 11.11. Users could bypass the mandatory external authentication provider sign-in restrictions by sending a specially crafted request. It has Improper Authorization.
CVE-2019-12428
An issue was discovered in GitLab Community and Enterprise Edition 6.8 ...
CVE-2019-11605
An issue was discovered in GitLab Community and Enterprise Edition 11.8.x before 11.8.10, 11.9.x before 11.9.11, and 11.10.x before 11.10.3. It allows Information Disclosure. A small number of GitLab API endpoints would disclose project information when using a read_user scoped token.
CVE-2019-11605
An issue was discovered in GitLab Community and Enterprise Edition 11.8.x before 11.8.10, 11.9.x before 11.9.11, and 11.10.x before 11.10.3. It allows Information Disclosure. A small number of GitLab API endpoints would disclose project information when using a read_user scoped token.
CVE-2019-11605
An issue was discovered in GitLab Community and Enterprise Edition 11. ...
CVE-2019-11549
An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. Gitaly has allows an information disclosure issue where HTTP/GIT credentials are included in logs on connection errors.
CVE-2019-11549
An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. Gitaly has allows an information disclosure issue where HTTP/GIT credentials are included in logs on connection errors.
CVE-2019-11549
An issue was discovered in GitLab Community and Enterprise Edition 9.x ...
CVE-2019-11548
An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9. It has Incorrect Access Control. Unprivileged members of a project are able to post comments on confidential issues through an authorization issue in the note endpoint.
CVE-2019-11548
An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9. It has Incorrect Access Control. Unprivileged members of a project are able to post comments on confidential issues through an authorization issue in the note endpoint.
CVE-2019-11548
An issue was discovered in GitLab Community and Enterprise Edition bef ...
CVE-2019-11547
An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. It has Improper Encoding or Escaping of Output. The branch name on new merge request notification emails isn't escaped, which could potentially lead to XSS issues.
CVE-2019-11547
An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. It has Improper Encoding or Escaping of Output. The branch name on new merge request notification emails isn't escaped, which could potentially lead to XSS issues.
CVE-2019-11547
An issue was discovered in GitLab Community and Enterprise Edition bef ...
CVE-2019-11546
An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. It has a Race Condition which could allow users to approve a merge request multiple times and potentially reach the approval count required to merge.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2019-12430 An issue was discovered in GitLab Community and Enterprise Edition 11. ... | CVSS3: 8.8 | 4% Низкий | почти 6 лет назад | |
CVE-2019-12429 An issue was discovered in GitLab Community and Enterprise Edition 11.9 through 11.11. Unprivileged users were able to access labels, status and merge request counts of confidential issues via the milestone details page. It has Improper Access Control. | CVSS3: 6.5 | 0% Низкий | почти 6 лет назад | |
CVE-2019-12429 An issue was discovered in GitLab Community and Enterprise Edition 11.9 through 11.11. Unprivileged users were able to access labels, status and merge request counts of confidential issues via the milestone details page. It has Improper Access Control. | CVSS3: 6.5 | 0% Низкий | почти 6 лет назад | |
CVE-2019-12429 An issue was discovered in GitLab Community and Enterprise Edition 11. ... | CVSS3: 6.5 | 0% Низкий | почти 6 лет назад | |
CVE-2019-12428 An issue was discovered in GitLab Community and Enterprise Edition 6.8 through 11.11. Users could bypass the mandatory external authentication provider sign-in restrictions by sending a specially crafted request. It has Improper Authorization. | CVSS3: 9.8 | 0% Низкий | почти 6 лет назад | |
CVE-2019-12428 An issue was discovered in GitLab Community and Enterprise Edition 6.8 through 11.11. Users could bypass the mandatory external authentication provider sign-in restrictions by sending a specially crafted request. It has Improper Authorization. | CVSS3: 9.8 | 0% Низкий | почти 6 лет назад | |
CVE-2019-12428 An issue was discovered in GitLab Community and Enterprise Edition 6.8 ... | CVSS3: 9.8 | 0% Низкий | почти 6 лет назад | |
CVE-2019-11605 An issue was discovered in GitLab Community and Enterprise Edition 11.8.x before 11.8.10, 11.9.x before 11.9.11, and 11.10.x before 11.10.3. It allows Information Disclosure. A small number of GitLab API endpoints would disclose project information when using a read_user scoped token. | CVSS3: 7.5 | 0% Низкий | больше 6 лет назад | |
CVE-2019-11605 An issue was discovered in GitLab Community and Enterprise Edition 11.8.x before 11.8.10, 11.9.x before 11.9.11, and 11.10.x before 11.10.3. It allows Information Disclosure. A small number of GitLab API endpoints would disclose project information when using a read_user scoped token. | CVSS3: 7.5 | 0% Низкий | больше 6 лет назад | |
CVE-2019-11605 An issue was discovered in GitLab Community and Enterprise Edition 11. ... | CVSS3: 7.5 | 0% Низкий | больше 6 лет назад | |
CVE-2019-11549 An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. Gitaly has allows an information disclosure issue where HTTP/GIT credentials are included in logs on connection errors. | CVSS3: 6.5 | 0% Низкий | больше 6 лет назад | |
CVE-2019-11549 An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. Gitaly has allows an information disclosure issue where HTTP/GIT credentials are included in logs on connection errors. | CVSS3: 6.5 | 0% Низкий | больше 6 лет назад | |
CVE-2019-11549 An issue was discovered in GitLab Community and Enterprise Edition 9.x ... | CVSS3: 6.5 | 0% Низкий | больше 6 лет назад | |
CVE-2019-11548 An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9. It has Incorrect Access Control. Unprivileged members of a project are able to post comments on confidential issues through an authorization issue in the note endpoint. | CVSS3: 5.4 | 0% Низкий | больше 6 лет назад | |
CVE-2019-11548 An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9. It has Incorrect Access Control. Unprivileged members of a project are able to post comments on confidential issues through an authorization issue in the note endpoint. | CVSS3: 5.4 | 0% Низкий | больше 6 лет назад | |
CVE-2019-11548 An issue was discovered in GitLab Community and Enterprise Edition bef ... | CVSS3: 5.4 | 0% Низкий | больше 6 лет назад | |
CVE-2019-11547 An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. It has Improper Encoding or Escaping of Output. The branch name on new merge request notification emails isn't escaped, which could potentially lead to XSS issues. | CVSS3: 6.1 | 0% Низкий | больше 6 лет назад | |
CVE-2019-11547 An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. It has Improper Encoding or Escaping of Output. The branch name on new merge request notification emails isn't escaped, which could potentially lead to XSS issues. | CVSS3: 6.1 | 0% Низкий | больше 6 лет назад | |
CVE-2019-11547 An issue was discovered in GitLab Community and Enterprise Edition bef ... | CVSS3: 6.1 | 0% Низкий | больше 6 лет назад | |
CVE-2019-11546 An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. It has a Race Condition which could allow users to approve a merge request multiple times and potentially reach the approval count required to merge. | CVSS3: 5.3 | 0% Низкий | больше 6 лет назад |
Уязвимостей на страницу