Vulnerabilities
Vulnerable Software
Gitlab:  >> Gitlab  >> 12.0.12  Security Vulnerabilities
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Under certain conditions GitLab was not properly revoking user sessions and allowed a malicious user to access a user account with an old password.
CVSS Score
3.8
EPSS Score
0.002
Published
2020-09-14
For GitLab before 13.0.12, 13.1.6, 13.2.3 a denial of service exists in the project import feature
CVSS Score
6.5
EPSS Score
0.001
Published
2020-08-13
For GitLab before 13.0.12, 13.1.6, 13.2.3 a memory exhaustion flaw exists due to excessive logging of an invite email error message.
CVSS Score
6.5
EPSS Score
0.001
Published
2020-08-13
For GitLab before 13.0.12, 13.1.6, 13.2.3 after a group transfer occurs, members from a parent group keep their access level on the subgroup leading to improper access.
CVSS Score
3.1
EPSS Score
0.001
Published
2020-08-13
For GitLab before 13.0.12, 13.1.6, 13.2.3 a cross-site scripting vulnerability exists in the issues list via milestone title.
CVSS Score
7.3
EPSS Score
0.001
Published
2020-08-13
In GitLab before 13.0.12, 13.1.6, and 13.2.3, improper access control was used on the Applications page
CVSS Score
7.5
EPSS Score
0.002
Published
2020-08-12
In GitLab before 13.0.12, 13.1.6 and 13.2.3 using a branch with a hexadecimal name could override an existing hash.
CVSS Score
6.3
EPSS Score
0.001
Published
2020-08-10
In GitLab before 13.0.12, 13.1.6 and 13.2.3, access grants were not revoked when a user revoked access to an application.
CVSS Score
4.2
EPSS Score
0.003
Published
2020-08-10
GitLab EE 11.3 through 13.1.2 has Incorrect Access Control because of the Maven package upload endpoint.
CVSS Score
5.3
EPSS Score
0.001
Published
2020-07-07
An authorization issue relating to project maintainer impersonation was identified in GitLab EE 9.5 and later through 13.0.1 that could allow unauthorized users to impersonate as a maintainer to perform limited actions.
CVSS Score
7.5
EPSS Score
0.002
Published
2020-06-19


Contact Us

Shodan ® - All rights reserved