Vulnerabilities
Vulnerable Software
Gitlab:  >> Gitlab  >> 12.10.4  Security Vulnerabilities
Missing permission check on fork relation creation in GitLab CE/EE 11.3 and later through 13.0.1 allows guest users to create a fork relation on restricted public projects via API
CVSS Score
7.5
EPSS Score
0.004
Published
2020-06-10
A Stored Cross-Site Scripting vulnerability allowed the execution of arbitrary Javascript code in the blobs API in all previous GitLab CE/EE versions through 13.0.1
CVSS Score
6.1
EPSS Score
0.003
Published
2020-06-10
Insecure authorization in Project Deploy Keys in GitLab CE/EE 12.8 and later through 13.0.1 allows users to update permissions of other users' deploy keys under certain conditions
CVSS Score
4.3
EPSS Score
0.001
Published
2020-06-09


Contact Us

Shodan ® - All rights reserved