Vulnerabilities
Vulnerable Software
Gitlab:  >> Gitlab  >> 12.0.1  Security Vulnerabilities
An issue was discovered in GitLab Community and Enterprise Edition through 12.2.1. Certain account actions needed improved authentication and session management.
CVSS Score
6.5
EPSS Score
0.014
Published
2019-09-16
An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1. Under certain conditions, merge request IDs were being disclosed via email.
CVSS Score
5.3
EPSS Score
0.015
Published
2019-09-16
An issue was discovered in GitLab Community and Enterprise Edition 8.1 through 12.2.1. Certain areas displaying Markdown were not properly sanitizing some XSS payloads.
CVSS Score
6.1
EPSS Score
0.012
Published
2019-09-16
An issue was discovered in GitLab Community and Enterprise Edition 7.9 through 12.2.1. EXIF Geolocation data was not being removed from certain image uploads.
CVSS Score
5.3
EPSS Score
0.016
Published
2019-09-16
An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1. Non-members were able to comment on merge requests despite the repository being set to allow only project members to do so.
CVSS Score
5.3
EPSS Score
0.012
Published
2019-09-16
An issue was discovered in GitLab Community and Enterprise Edition 7.12 through 12.2.1. The specified default branch name could be exposed to unauthorized users.
CVSS Score
4.3
EPSS Score
0.01
Published
2019-09-16
An issue was discovered in GitLab Community and Enterprise Edition 10.8 through 12.2.1. An internal endpoint unintentionally allowed group maintainers to view and edit group runner settings.
CVSS Score
5.4
EPSS Score
0.008
Published
2019-09-16
An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.2.1. Particular mathematical expressions in GitLab Markdown can exhaust client resources.
CVSS Score
7.5
EPSS Score
0.019
Published
2019-09-16
An issue was discovered in GitLab Community and Enterprise Edition 11.10 through 12.2.1. Label descriptions are vulnerable to HTML injection.
CVSS Score
6.1
EPSS Score
0.012
Published
2019-09-16
An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1. An IDOR in the epic notes API that could result in disclosure of private milestones, labels, and other information.
CVSS Score
7.5
EPSS Score
0.018
Published
2019-09-16


Contact Us

Shodan ® - All rights reserved