Security Vulnerabilities
- CVEs Published In February 2020
An issue was discovered in GitLab EE 11.3 and later. A GitLab Workhorse bypass could lead to package and file disclosure via request smuggling.
GitLab EE 11.0 and later through 12.7.2 allows XSS.
GitLab EE 12.2 has Insecure Permissions (issue 2 of 2).
GitLab through 12.7.2 allows XSS.
GitLab EE 10.1 through 12.7.2 allows Information Disclosure.
GitLab EE 12.4 and later through 12.7.2 has Incorrect Access Control.
GitLab EE 8.8 and later through 12.7.2 has Insecure Permissions.
GitLab EE 12.6 and later through 12.7.2 allows Denial of Service.
The Global TV application 2.3.2 for Android and 4.7.5 for iOS sends Unencrypted Analytics.
The Citytv Video application 4.08.0 for Android and 3.35 for iOS sends Unencrypted Analytics.