Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Gitlab Subscribe
Total 821 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-13327 1 Gitlab 1 Runner 2020-11-02 6.0 MEDIUM 7.5 HIGH
An issue has been discovered in GitLab Runner affecting all versions starting from 13.4.0 before 13.4.2, all versions starting from 13.3.0 before 13.3.7, all versions starting from 13.2.0 before 13.2.10. Insecure Runner Configuration in Kubernetes Environments
CVE-2020-13333 1 Gitlab 1 Gitlab 2020-10-29 4.0 MEDIUM 4.3 MEDIUM
A potential DOS vulnerability was discovered in GitLab versions 13.1, 13.2 and 13.3. The api to update an asset as a link from a release had a regex check which caused exponential number of backtracks for certain user supplied values resulting in high CPU usage.
CVE-2019-5487 1 Gitlab 1 Gitlab 2020-10-22 5.0 MEDIUM 5.3 MEDIUM
An improper access control vulnerability exists in Gitlab EE <v12.3.3, <v12.2.7, & <v12.1.13 that allowed the group search feature with Elasticsearch to return private code, merge requests and commits.
CVE-2019-5470 1 Gitlab 1 Gitlab 2020-10-21 5.0 MEDIUM 7.5 HIGH
An information disclosure issue was discovered GitLab versions < 12.1.2, < 12.0.4, and < 11.11.6 in the security dashboard which could result in disclosure of vulnerability feedback information.
CVE-2019-5466 1 Gitlab 1 Gitlab 2020-10-20 4.0 MEDIUM 4.3 MEDIUM
An IDOR was discovered in GitLab CE/EE 11.5 and later that allowed new merge requests endpoint to disclose label names.
CVE-2019-5465 1 Gitlab 1 Gitlab 2020-10-20 4.0 MEDIUM 4.3 MEDIUM
An information disclosure issue was discovered in GitLab CE/EE 8.14 and later, by using the move issue feature which could result in disclosure of the newly created issue ID.
CVE-2019-5474 1 Gitlab 1 Gitlab 2020-10-19 4.0 MEDIUM 6.5 MEDIUM
An authorization issue was discovered in GitLab EE < 12.1.2, < 12.0.4, and < 11.11.6 allowing the merge request approval rules to be overridden without appropriate permissions.
CVE-2020-13334 1 Gitlab 1 Gitlab 2020-10-15 5.0 MEDIUM 7.5 HIGH
In GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, improper authorization checks allow a non-member of a project/group to change the confidentiality attribute of issue via mutation GraphQL query
CVE-2020-13345 1 Gitlab 1 Gitlab 2020-10-15 3.5 LOW 5.4 MEDIUM
An issue has been discovered in GitLab affecting all versions starting from 10.8. Reflected XSS on Multiple Routes
CVE-2020-13343 1 Gitlab 1 Gitlab 2020-10-14 4.0 MEDIUM 8.8 HIGH
An issue has been discovered in GitLab affecting all versions starting from 11.2. Unauthorized Users Can View Custom Project Template
CVE-2020-13340 1 Gitlab 1 Gitlab 2020-10-13 3.5 LOW 8.7 HIGH
An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2: Stored XSS in CI Job Log
CVE-2019-15591 1 Gitlab 1 Gitlab 2020-10-09 4.0 MEDIUM 6.5 MEDIUM
An improper access control vulnerability exists in GitLab <12.3.3 that allows an attacker to obtain container and dependency scanning reports through the merge request widget even though public pipelines were disabled.
CVE-2019-15575 1 Gitlab 1 Gitlab 2020-10-09 5.0 MEDIUM 7.5 HIGH
A command injection exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to inject commands via the API through the blobs scope.
CVE-2019-15593 1 Gitlab 1 Gitlab 2020-10-09 4.0 MEDIUM 6.5 MEDIUM
GitLab 12.2.3 contains a security vulnerability that allows a user to affect the availability of the service through a Denial of Service attack in Issue Comments.
CVE-2020-13339 1 Gitlab 1 Gitlab 2020-10-08 6.0 MEDIUM 6.5 MEDIUM
An issue has been discovered in GitLab affecting all versions before 13.2.10, 13.3.7 and 13.4.2: XSS in SVG File Preview. Overall impact is limited due to the current user only being impacted.
CVE-2020-13337 1 Gitlab 1 Gitlab 2020-10-08 3.5 LOW 4.8 MEDIUM
An issue has been discovered in GitLab affecting versions from 12.10 to 12.10.12 that allowed for a stored XSS payload to be added as a group name.
CVE-2020-13338 1 Gitlab 1 Gitlab 2020-10-08 3.5 LOW 5.4 MEDIUM
An issue has been discovered in GitLab affecting versions prior to 12.10.13, 13.0.8, 13.1.2. A stored cross-site scripting vulnerability was discovered when editing references.
CVE-2020-13324 1 Gitlab 1 Gitlab 2020-10-08 3.5 LOW 6.5 MEDIUM
A vulnerability was discovered in GitLab versions prior to 13.1. Under certain conditions the private activity of a user could be exposed via the API.
CVE-2020-13336 1 Gitlab 1 Gitlab 2020-10-07 3.5 LOW 4.8 MEDIUM
An issue has been discovered in GitLab affecting versions from 11.8 before 12.10.13. GitLab was vulnerable to a stored XSS by in the error tracking feature.
CVE-2020-13296 1 Gitlab 1 Gitlab 2020-10-02 7.5 HIGH 8.8 HIGH
An issue has been discovered in GitLab affecting versions >=10.7 <13.0.14, >=13.1.0 <13.1.8, >=13.2.0 <13.2.6. Improper Access Control for Deploy Tokens