apk package
chainguard/gitlab-operator-fips
pkg:apk/chainguard/gitlab-operator-fips
Vulnerabilities (178)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2020-10081 | Med | 6.5 | < 0 | 0 | Mar 13, 2020 | GitLab before 12.8.2 has Incorrect Access Control. It was internally discovered that the LFS import process could potentially be used to incorrectly access LFS objects not owned by the user. | |
| CVE-2019-13003 | Hig | 7.5 | < 0 | 0 | Mar 10, 2020 | An issue was discovered in GitLab Community and Enterprise Edition before 12.0.3. One of the parsers used by Gilab CI was vulnerable to a resource exhaustion attack. It allows Uncontrolled Resource Consumption. | |
| CVE-2020-7973 | Med | 6.1 | < 0 | 0 | Feb 5, 2020 | GitLab through 12.7.2 allows XSS. | |
| CVE-2020-7968 | Hig | 7.5 | < 0 | 0 | Feb 5, 2020 | GitLab EE 8.0 through 12.7.2 has Incorrect Access Control. | |
| CVE-2019-19260 | Med | 5.4 | < 0 | 0 | Jan 3, 2020 | GitLab Community Edition (CE) and Enterprise Edition (EE) through 12.5 has Incorrect Access Control (issue 2 of 2). | |
| CVE-2019-19257 | Med | 5.3 | < 0 | 0 | Jan 3, 2020 | GitLab Community Edition (CE) and Enterprise Edition (EE) through 12.5 has Incorrect Access Control (issue 1 of 2). | |
| CVE-2019-15584 | Med | 6.5 | < 0 | 0 | Dec 20, 2019 | A denial of service exists in gitlab <v12.3.2, <v12.2.6, and <v12.1.10 that would let an attacker bypass input validation in markdown fields take down the affected page. | |
| CVE-2019-5486 | Hig | 8.8 | < 0 | 0 | Dec 18, 2019 | A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.10 in the Salesforce login integration that could be used by an attacker to create an account that bypassed domain restrictions and email verification requirements. | |
| CVE-2019-15591 | Med | 6.5 | < 0 | 0 | Dec 18, 2019 | An improper access control vulnerability exists in GitLab <12.3.3 that allows an attacker to obtain container and dependency scanning reports through the merge request widget even though public pipelines were disabled. | |
| CVE-2019-15589 | Hig | 8.8 | < 0 | 0 | Dec 18, 2019 | An improper access control vulnerability exists in Gitlab <v12.3.2, <v12.2.6, <v12.1.12 which would allow a blocked user would be able to use GIT clone and pull if he had obtained a CI/CD token before. | |
| CVE-2019-15580 | Med | 6.5 | < 0 | 0 | Dec 18, 2019 | An information exposure vulnerability exists in gitlab.com <v12.3.2, <v12.2.6, and <v12.1.10 when using the blocking merge request feature, it was possible for an unauthenticated user to see the head pipeline data of a public project even though pipeline visibility was restricted | |
| CVE-2019-15577 | Med | 4.3 | < 0 | 0 | Dec 18, 2019 | An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed project milestones to be disclosed via groups browsing. | |
| CVE-2019-15576 | Hig | 7.5 | < 0 | 0 | Dec 18, 2019 | An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to view private system notes from a GraphQL endpoint. | |
| CVE-2019-15575 | Hig | 7.5 | < 0 | 0 | Dec 18, 2019 | A command injection exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to inject commands via the API through the blobs scope. | |
| CVE-2019-18450 | Med | 4.3 | < 0 | 0 | Nov 26, 2019 | An issue was discovered in GitLab Community and Enterprise Edition before 12.4 in the Project labels feature. It has Insecure Permissions. | |
| CVE-2019-18449 | Med | 4.3 | < 0 | 0 | Nov 26, 2019 | An issue was discovered in GitLab Community and Enterprise Edition before 12.4 in the autocomplete feature. It has Insecure Permissions (issue 2 of 2). | |
| CVE-2019-18448 | Med | 6.5 | < 0 | 0 | Nov 26, 2019 | An issue was discovered in GitLab Community and Enterprise Edition before 12.4. It has Incorrect Access Control. | |
| CVE-2019-18447 | Med | 4.3 | < 0 | 0 | Nov 26, 2019 | An issue was discovered in GitLab Community and Enterprise Edition before 12.4. It has Insecure Permissions. | |
| CVE-2019-18463 | Med | 4.3 | < 0 | 0 | Nov 26, 2019 | An issue was discovered in GitLab Community and Enterprise Edition through 12.4. It has Insecure Permissions (issue 4 of 4). | |
| CVE-2019-15737 | Med | 6.5 | < 0 | 0 | Sep 16, 2019 | An issue was discovered in GitLab Community and Enterprise Edition through 12.2.1. Certain account actions needed improved authentication and session management. |
- affected < 0fixed 0
GitLab before 12.8.2 has Incorrect Access Control. It was internally discovered that the LFS import process could potentially be used to incorrectly access LFS objects not owned by the user.
- affected < 0fixed 0
An issue was discovered in GitLab Community and Enterprise Edition before 12.0.3. One of the parsers used by Gilab CI was vulnerable to a resource exhaustion attack. It allows Uncontrolled Resource Consumption.
- affected < 0fixed 0
GitLab through 12.7.2 allows XSS.
- affected < 0fixed 0
GitLab EE 8.0 through 12.7.2 has Incorrect Access Control.
- affected < 0fixed 0
GitLab Community Edition (CE) and Enterprise Edition (EE) through 12.5 has Incorrect Access Control (issue 2 of 2).
- affected < 0fixed 0
GitLab Community Edition (CE) and Enterprise Edition (EE) through 12.5 has Incorrect Access Control (issue 1 of 2).
- affected < 0fixed 0
A denial of service exists in gitlab <v12.3.2, <v12.2.6, and <v12.1.10 that would let an attacker bypass input validation in markdown fields take down the affected page.
- affected < 0fixed 0
A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.10 in the Salesforce login integration that could be used by an attacker to create an account that bypassed domain restrictions and email verification requirements.
- affected < 0fixed 0
An improper access control vulnerability exists in GitLab <12.3.3 that allows an attacker to obtain container and dependency scanning reports through the merge request widget even though public pipelines were disabled.
- affected < 0fixed 0
An improper access control vulnerability exists in Gitlab <v12.3.2, <v12.2.6, <v12.1.12 which would allow a blocked user would be able to use GIT clone and pull if he had obtained a CI/CD token before.
- affected < 0fixed 0
An information exposure vulnerability exists in gitlab.com <v12.3.2, <v12.2.6, and <v12.1.10 when using the blocking merge request feature, it was possible for an unauthenticated user to see the head pipeline data of a public project even though pipeline visibility was restricted
- affected < 0fixed 0
An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed project milestones to be disclosed via groups browsing.
- affected < 0fixed 0
An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to view private system notes from a GraphQL endpoint.
- affected < 0fixed 0
A command injection exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to inject commands via the API through the blobs scope.
- affected < 0fixed 0
An issue was discovered in GitLab Community and Enterprise Edition before 12.4 in the Project labels feature. It has Insecure Permissions.
- affected < 0fixed 0
An issue was discovered in GitLab Community and Enterprise Edition before 12.4 in the autocomplete feature. It has Insecure Permissions (issue 2 of 2).
- affected < 0fixed 0
An issue was discovered in GitLab Community and Enterprise Edition before 12.4. It has Incorrect Access Control.
- affected < 0fixed 0
An issue was discovered in GitLab Community and Enterprise Edition before 12.4. It has Insecure Permissions.
- affected < 0fixed 0
An issue was discovered in GitLab Community and Enterprise Edition through 12.4. It has Insecure Permissions (issue 4 of 4).
- affected < 0fixed 0
An issue was discovered in GitLab Community and Enterprise Edition through 12.2.1. Certain account actions needed improved authentication and session management.
Page 6 of 9