Vulnerabilities
Vulnerable Software
Gitlab:  >> Gitlab  >> 12.7.3  Security Vulnerabilities
GitLab 7.10 through 12.8.1 has Incorrect Access Control. Under certain conditions where users should have been required to configure two-factor authentication, it was not being required.
CVSS Score
5.3
EPSS Score
0.001
Published
2020-03-13
GitLab 8.3 through 12.8.1 allows Information Disclosure. It was possible for certain non-members to access the Contribution Analytics page of a private group.
CVSS Score
5.3
EPSS Score
0.001
Published
2020-03-13
GitLab before 12.8.2 has Incorrect Access Control. It was internally discovered that the LFS import process could potentially be used to incorrectly access LFS objects not owned by the user.
CVSS Score
6.5
EPSS Score
0.001
Published
2020-03-13
In GitLab Enterprise Edition (EE) 12.5.0 through 12.7.5, sharing a group with a group could grant project access to unauthorized users.
CVSS Score
7.5
EPSS Score
0.001
Published
2020-02-17
An issue was discovered in GitLab EE 11.3 and later. A GitLab Workhorse bypass could lead to package and file disclosure via request smuggling.
CVSS Score
7.5
EPSS Score
0.001
Published
2020-02-05
GitLab EE 12.2 has Insecure Permissions (issue 2 of 2).
CVSS Score
7.5
EPSS Score
0.001
Published
2020-02-05
GitLab EE 8.0 through 12.7.2 has Incorrect Access Control.
CVSS Score
7.5
EPSS Score
0.001
Published
2020-02-05


Contact Us

Shodan ® - All rights reserved