RSS   Vulnerabilities for 'Gitlab'   RSS

2019-09-17
 
CVE-2019-15729

CWE-200
 

 
An issue was discovered in GitLab Community and Enterprise Edition 8.18 through 12.2.1. An internal endpoint unintentionally disclosed information about the last pipeline that ran for a merge request.

 
2019-09-16
 
CVE-2019-15740

CWE-200
 

 
An issue was discovered in GitLab Community and Enterprise Edition 7.9 through 12.2.1. EXIF Geolocation data was not being removed from certain image uploads.

 
 
CVE-2019-15739

CWE-79
 

 
An issue was discovered in GitLab Community and Enterprise Edition 8.1 through 12.2.1. Certain areas displaying Markdown were not properly sanitizing some XSS payloads.

 
 
CVE-2019-15738

CWE-200
 

 
An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1. Under certain conditions, merge request IDs were being disclosed via email.

 
 
CVE-2019-15737

CWE-287
 

 
An issue was discovered in GitLab Community and Enterprise Edition through 12.2.1. Certain account actions needed improved authentication and session management.

 
 
CVE-2019-15736

CWE-400
 

 
An issue was discovered in GitLab Community and Enterprise Edition through 12.2.1. Under certain circumstances, CI pipelines could potentially be used in a denial of service attack.

 
 
CVE-2019-15734

CWE-200
 

 
An issue was discovered in GitLab Community and Enterprise Edition 8.6 through 12.2.1. Under very specific conditions, commit titles and team member comments could become viewable to users who did not have permission to access these.

 
 
CVE-2019-15733

CWE-200
 

 
An issue was discovered in GitLab Community and Enterprise Edition 7.12 through 12.2.1. The specified default branch name could be exposed to unauthorized users.

 
 
CVE-2019-15732

CWE-200
 

 
An issue was discovered in GitLab Community and Enterprise Edition 12.2 through 12.2.1. The project import API could be used to bypass project visibility restrictions.

 
 
CVE-2019-15731

CWE-732
 

 
An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1. Non-members were able to comment on merge requests despite the repository being set to allow only project members to do so.

 


Copyright 2019, cxsecurity.com

 

Back to Top