gitlab

1,383 tracked vulnerabilities.

CVE-2019-6793 HIGH NUCLEI
GitLab 10.0.0-11.5.7, 11.6.0-11.6.5, 11.7.0 - Unauthenticated Server-Side Request Forgery via Jira Integration
Sep 09, 2019
CVSS 7.0
EPSS 0.05
CVE-2019-6792 MEDIUM
GitLab 8.9.0-11.5.7, 11.6.0-11.6.5, 11.7.0 - Path Disclosure via Project Import Error Message
Sep 09, 2019
CVSS 5.3
EPSS 0.00
CVE-2019-6789 MEDIUM
GitLab < 11.5.8, 11.6.x < 11.6.6, 11.7.x < 11.7.1 - Information Disclosure via Project Move Notification
Sep 09, 2019
CVSS 4.3
EPSS 0.00
CVE-2019-6788 HIGH
GitLab 8.4.0-11.5.7, 11.6.0-11.6.5, 11.7.0 - Information Disclosure via OAuth Token Covert Redirect
Sep 09, 2019
CVSS 7.5
EPSS 0.20
CVE-2019-6786 MEDIUM
GitLab <11.5.8-11.7.1 - Info Disclosure
Sep 09, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-6785 MEDIUM
GitLab 7.4.0-11.5.7, 11.6.0-11.6.5, 11.7.0 - Denial of Service via Markdown Field Input
Sep 09, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-6784 MEDIUM
GitLab < 11.5.8, 11.6.x < 11.6.6, 11.7.x < 11.7.1 - Stored Cross-Site Scripting via KaTeX Markdown Processing
Sep 09, 2019
CVSS 6.1
EPSS 0.00
CVE-2019-6783 HIGH
GitLab < 11.5.8, 11.6.x < 11.6.6, 11.7.x < 11.7.1 - Path Traversal and Remote Code Execution via GitLab Pages
Sep 09, 2019
CVSS 8.8
EPSS 0.02
CVE-2019-6782 HIGH
GitLab 11.3.0-11.5.7, 11.6.0-11.6.5, 11.7.0 - Information Disclosure via Private Profile Contribution Data
Sep 09, 2019
CVSS 7.5
EPSS 0.00
CVE-2019-11605 HIGH
GitLab <11.8.10-11.10.3 - Info Disclosure
Sep 09, 2019
CVSS 7.5
EPSS 0.00
CVE-2019-11549 MEDIUM
GitLab <11.8.9-11.10.2 - Info Disclosure
Sep 09, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-11548 MEDIUM
GitLab 5.4.0-11.8.9 - Unauthenticated Incorrect Access Control in Note Endpoint
Sep 09, 2019
CVSS 5.4
EPSS 0.00
CVE-2019-11547 MEDIUM
GitLab < 11.8.9, 11.9.x < 11.9.10, 11.10.x < 11.10.2 - Cross-Site Scripting via Merge Request Notification Email
Sep 09, 2019
CVSS 6.1
EPSS 0.00
CVE-2019-11546 MEDIUM
GitLab <11.8.9-11.10.2 - Info Disclosure
Sep 09, 2019
CVSS 5.3
EPSS 0.00
CVE-2019-11545 MEDIUM
GitLab CE <11.9.10, <11.10.2 - Info Disclosure
Sep 09, 2019
CVSS 4.3
EPSS 0.00
CVE-2019-11544 MEDIUM
GitLab <11.8.9-11.10.2 - Info Disclosure
Sep 09, 2019
CVSS 4.3
EPSS 0.00
CVE-2019-5473 HIGH
GitLab - Authentication Bypass via Email Verification
Sep 09, 2019
CVSS 7.2
EPSS 0.00
CVE-2019-5471 MEDIUM
GitLab 11.11.0-11.11.6 - Stored Cross-Site Scripting in Email Notification Feature
Sep 09, 2019
CVSS 5.4
EPSS 0.00
CVE-2019-5467 MEDIUM
GitLab 11.11.2-11.11.6 - Stored Cross-Site Scripting in Wiki Pages
Sep 09, 2019
CVSS 5.4
EPSS 0.00
CVE-2019-5463 MEDIUM
GitLab 11.11.0-11.11.6 - Missing Authorization in CI Badge Images Endpoint
Sep 09, 2019
CVSS 5.3
EPSS 0.00
CVE-2019-5461 LOW
GitLab 11.11.0-11.11.6 - Server-Side Request Forgery via GitHub Integration
Sep 09, 2019
CVSS 3.5
EPSS 0.00
CVE-2019-14943 CRITICAL
GitLab 12.0-12.1.4 - Use of Hard-coded Credentials
Aug 29, 2019
CVSS 9.8
EPSS 0.00
CVE-2019-9866 MEDIUM
GitLab <11.7.7, <11.8.3 - Info Disclosure
May 29, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-9732 CRITICAL
GitLab <11.6.10-11.8.1 - Incorrect Access Control
May 29, 2019
CVSS 9.8
EPSS 0.00
CVE-2019-9485 CRITICAL
GitLab <11.6.10-11.8.1 - Info Disclosure
May 29, 2019
CVSS 9.8
EPSS 0.00