Vulnerabilities
Vulnerable Software
Gitlab:  >> Gitlab  Security Vulnerabilities
GitLab EE/CE 8.11 to 12.9 is leaking information on Issues opened in a public project and then moved to a private project through Web-UI and GraphQL API.
CVSS Score
5.3
EPSS Score
0.001
Published
2020-04-08
GitLab EE/CE 11.10 to 12.9 is leaking information on restricted CI pipelines metrics to unauthorized users.
CVSS Score
4.3
EPSS Score
0.001
Published
2020-04-08
GitLab EE/CE 8.0.rc1 to 12.9 is vulnerable to a blind SSRF in the FogBugz integration.
CVSS Score
9.8
EPSS Score
0.002
Published
2020-04-08
GitLab EE/CE 9.0 to 12.9 allows a maintainer to modify other maintainers' pipeline trigger descriptions within the same project.
CVSS Score
4.3
EPSS Score
0.001
Published
2020-04-08
GitLab EE/CE 10.8 to 12.9 is leaking metadata and comments on vulnerabilities to unauthorized users on the vulnerability feedback page.
CVSS Score
4.3
EPSS Score
0.001
Published
2020-04-08
GitLab EE/CE 8.17 to 12.9 is vulnerable to information leakage when querying a merge request widget.
CVSS Score
7.5
EPSS Score
0.001
Published
2020-04-08
GitLab EE/CE 8.5 to 12.9 is vulnerable to a an path traversal when moving an issue between projects.
CVSS Score
5.5
EPSS Score
0.059
Published
2020-04-08
GitLab EE/CE 8.11 through 12.9.1 allows blocked users to pull/push docker images.
CVSS Score
6.5
EPSS Score
0.001
Published
2020-03-27
In GitLab EE 11.7 through 12.9, the NPM feature is vulnerable to a path traversal issue.
CVSS Score
7.5
EPSS Score
0.001
Published
2020-03-27
GitLab through 12.9 is affected by a potential DoS in repository archive download.
CVSS Score
7.5
EPSS Score
0.001
Published
2020-03-27


Contact Us

Shodan ® - All rights reserved