Vulnerabilities
Vulnerable Software
Gitlab:  >> Gitlab  >> 10.5.4  Security Vulnerabilities
GitLab 10.1 through 12.8.1 has Incorrect Access Control. A scenario was discovered in which a GitLab account could be taken over through an expired link.
CVSS Score
9.8
EPSS Score
0.001
Published
2020-03-13
GitLab 10.4 through 12.8.1 allows Directory Traversal. A particular endpoint was vulnerable to a directory traversal vulnerability, leading to arbitrary file read.
CVSS Score
5.3
EPSS Score
0.0
Published
2020-03-13
GitLab before 12.8.2 allows Information Disclosure. Badge images were not being proxied, causing mixed content warnings as well as leaking the IP address of the user.
CVSS Score
7.5
EPSS Score
0.001
Published
2020-03-13
GitLab 8.11 through 12.8.1 allows a Denial of Service when using several features to recursively request eachother,
CVSS Score
7.5
EPSS Score
0.001
Published
2020-03-13
GitLab 9.3 through 12.8.1 allows XSS. A cross-site scripting vulnerability was found when viewing particular file types.
CVSS Score
6.1
EPSS Score
0.001
Published
2020-03-13
GitLab 7.10 through 12.8.1 has Incorrect Access Control. Under certain conditions where users should have been required to configure two-factor authentication, it was not being required.
CVSS Score
5.3
EPSS Score
0.001
Published
2020-03-13
GitLab 8.3 through 12.8.1 allows Information Disclosure. It was possible for certain non-members to access the Contribution Analytics page of a private group.
CVSS Score
5.3
EPSS Score
0.001
Published
2020-03-13
GitLab before 12.8.2 has Incorrect Access Control. It was internally discovered that the LFS import process could potentially be used to incorrectly access LFS objects not owned by the user.
CVSS Score
6.5
EPSS Score
0.001
Published
2020-03-13
An issue was discovered in GitLab Community and Enterprise Edition 9.2 through 12.0.2. Uploaded files associated with unsaved personal snippets were accessible to unauthorized users due to improper permission settings. It has Incorrect Access Control.
CVSS Score
6.5
EPSS Score
0.001
Published
2020-03-10
An issue was discovered in GitLab Enterprise Edition 8.3 through 12.0.2. The color codes decoder was vulnerable to a resource depletion attack if specific formats were used. It allows Uncontrolled Resource Consumption.
CVSS Score
5.9
EPSS Score
0.001
Published
2020-03-10


Contact Us

Shodan ® - All rights reserved