gitlab
1,383 tracked vulnerabilities.
CVE-2019-9221
MEDIUM
GitLab < 11.6.10, 11.7.x < 11.7.6, 11.8.x < 11.8.1 - Incorrect Access Control
May 29, 2019
CVSS 5.5
EPSS 0.00
CVE-2019-9218
CRITICAL
GitLab <11.6.10-11.8.1 - Info Disclosure
May 29, 2019
CVSS 9.8
EPSS 0.00
CVE-2019-7549
MEDIUM
GitLab <11.5.10-11.7.3 - Auth Bypass
May 29, 2019
CVSS 4.3
EPSS 0.00
CVE-2019-7353
CRITICAL
GitLab CE/EE <11.7.4 - Info Disclosure
May 17, 2019
CVSS 9.1
EPSS 0.00
CVE-2019-6797
HIGH
GitLab < 11.5.8, 11.6.x < 11.6.6, 11.7.x < 11.7.1 - Information Disclosure via GitHub Token Leak in CI/CD UI
May 17, 2019
CVSS 7.5
EPSS 0.00
CVE-2019-6790
MEDIUM
GitLab 8.14.0-11.5.7, 11.6.0-11.6.5, 11.7.0 - Unauthenticated Merge Request List Exposure
May 17, 2019
CVSS 4.3
EPSS 0.00
CVE-2019-6787
MEDIUM
GitLab Community/E Enterprise <11.5.8-11.7.1 - Info Disclosure
May 17, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-6781
HIGH
GitLab 11.5.0-11.5.7, 11.6.0-11.6.5, 11.7.0 - Open Redirect via Profile Name in Notification Emails
May 17, 2019
CVSS 7.5
EPSS 0.00
CVE-2019-5883
CRITICAL
GitLab Community and Enterprise Edition <11.3.11 <11.4.8 <11.5.1 - Incorrect Access Control in Issue Comments
May 17, 2019
CVSS 9.1
EPSS 0.00
CVE-2019-10112
HIGH
GitLab <11.7.8-11.9.2 - Info Disclosure
May 16, 2019
CVSS 7.5
EPSS 0.00
CVE-2019-10117
MEDIUM
GitLab <11.7.8, <11.8.4, <11.9.2 - Open Redirect
May 16, 2019
CVSS 6.1
EPSS 0.00
CVE-2019-10116
MEDIUM
GitLab Community/E Enterprise <11.7.8-11.9.2 - Info Disclosure
May 16, 2019
CVSS 4.3
EPSS 0.00
CVE-2019-10115
MEDIUM
GitLab < 11.7.8, 11.8.x < 11.8.4, 11.9.x < 11.9.2 - Insecure Permissions in Releases Feature
May 16, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-10114
HIGH
GitLab <11.7.8, <11.8.x <11.8.4, <11.9.x <11.9.2 - Info Disclosure
May 16, 2019
CVSS 7.5
EPSS 0.00
CVE-2019-10113
HIGH
GitLab <11.7.8-11.9.2 - Uncontrolled Resource Consumption
May 16, 2019
CVSS 7.5
EPSS 0.00
CVE-2019-10111
MEDIUM
GitLab < 11.7.8, 11.8.x < 11.8.4, 11.9.x < 11.9.2 - Stored Cross-Site Scripting in Merge Request Conflicts Page
May 15, 2019
CVSS 5.4
EPSS 0.00
CVE-2019-10110
MEDIUM
GitLab <11.7.8, <11.8.4, <11.9.2 - Privilege Escalation
May 15, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-10109
MEDIUM
GitLab <11.7.8, <11.8.x <11.8.4, <11.9.x <11.9.2 - Info Disclosure
May 15, 2019
CVSS 5.3
EPSS 0.00
CVE-2019-10108
MEDIUM
GitLab < 11.7.8, 11.8.x < 11.8.4, 11.9.x < 11.9.2 - Incorrect Access Control for Private Project Labels
May 15, 2019
CVSS 5.4
EPSS 0.00
CVE-2019-10640
HIGH
GitLab < 11.7.10, 11.8.x < 11.8.6, 11.9.x < 11.9.4 - Resource Consumption via .gitlab-ci.yml
May 15, 2019
CVSS 7.5
EPSS 0.00
CVE-2019-11000
MEDIUM
GitLab < 11.7.11, 11.8.x < 11.8.7, 11.9.x < 11.9.7 - Information Disclosure
May 10, 2019
CVSS 6.5
EPSS 0.01
CVE-2019-9890
CRITICAL
GitLab <11.6.10-11.8.1 - Info Disclosure
Apr 17, 2019
CVSS 9.1
EPSS 0.00
CVE-2019-9756
CRITICAL
GitLab Community and Enterprise Edition <11.6.10/11.7.6 - Incorrect Access Control
Apr 17, 2019
CVSS 9.8
EPSS 0.00
CVE-2019-9225
MEDIUM
GitLab < 11.6.10, 11.7.x < 11.7.6, 11.8.x < 11.8.1 - Exposure of Sensitive Information via Incorrect Access Control
Apr 17, 2019
CVSS 5.3
EPSS 0.00
CVE-2019-9224
MEDIUM
GitLab < 11.6.10, 11.7.x < 11.7.6, 11.8.x < 11.8.1 - Missing Authorization
Apr 17, 2019
CVSS 5.3
EPSS 0.00