Vulnerabilities
Vulnerable Software
Gitlab:  >> Gitlab  >> 1.0.1  Security Vulnerabilities
An improper access control vulnerability exists in Gitlab <v12.3.2, <v12.2.6, <v12.1.12 which would allow a blocked user would be able to use GIT clone and pull if he had obtained a CI/CD token before.
CVSS Score
8.8
EPSS Score
0.001
Published
2019-12-18
An improper access control vulnerability exists in GitLab <12.3.3 that allows an attacker to obtain container and dependency scanning reports through the merge request widget even though public pipelines were disabled.
CVSS Score
6.5
EPSS Score
0.002
Published
2019-12-18
A command injection exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to inject commands via the API through the blobs scope.
CVSS Score
7.5
EPSS Score
0.027
Published
2019-12-18
An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to view private system notes from a GraphQL endpoint.
CVSS Score
7.5
EPSS Score
0.004
Published
2019-12-18
An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed project milestones to be disclosed via groups browsing.
CVSS Score
4.3
EPSS Score
0.001
Published
2019-12-18
An information exposure vulnerability exists in gitlab.com <v12.3.2, <v12.2.6, and <v12.1.10 when using the blocking merge request feature, it was possible for an unauthenticated user to see the head pipeline data of a public project even though pipeline visibility was restricted.
CVSS Score
6.5
EPSS Score
0.003
Published
2019-12-18
An issue was discovered in GitLab Community and Enterprise Edition before 12.4. It has Insecure Permissions.
CVSS Score
4.3
EPSS Score
0.001
Published
2019-11-26
An issue was discovered in GitLab Community and Enterprise Edition before 12.4. It has Incorrect Access Control.
CVSS Score
6.5
EPSS Score
0.001
Published
2019-11-26
An issue was discovered in GitLab Community and Enterprise Edition before 12.4 in the autocomplete feature. It has Insecure Permissions (issue 2 of 2).
CVSS Score
4.3
EPSS Score
0.001
Published
2019-11-26
An issue was discovered in GitLab Community and Enterprise Edition before 12.4 in the Project labels feature. It has Insecure Permissions.
CVSS Score
4.3
EPSS Score
0.001
Published
2019-11-26


Contact Us

Shodan ® - All rights reserved