Bitnami package
gitlab
pkg:bitnami/gitlab
Vulnerabilities (1,054)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2020-10078 | — | >= 12.1.0, < 12.8.2 | 12.8.2 | Mar 13, 2020 | GitLab 12.1 through 12.8.1 allows XSS. The merge request submission form was determined to have a stored cross-site scripting vulnerability. | ||
| CVE-2020-10079 | — | >= 7.10.0, < 12.8.2 | 12.8.2 | Mar 13, 2020 | GitLab 7.10 through 12.8.1 has Incorrect Access Control. Under certain conditions where users should have been required to configure two-factor authentication, it was not being required. | ||
| CVE-2020-10080 | — | >= 8.3.0, < 12.8.2 | 12.8.2 | Mar 13, 2020 | GitLab 8.3 through 12.8.1 allows Information Disclosure. It was possible for certain non-members to access the Contribution Analytics page of a private group. | ||
| CVE-2020-10081 | — | < 12.8.2 | 12.8.2 | Mar 13, 2020 | GitLab before 12.8.2 has Incorrect Access Control. It was internally discovered that the LFS import process could potentially be used to incorrectly access LFS objects not owned by the user. | ||
| CVE-2020-10082 | — | >= 12.2.0, < 12.8.2 | 12.8.2 | Mar 13, 2020 | GitLab 12.2 through 12.8.1 allows Denial of Service. A denial of service vulnerability impacting the designs for public issues was discovered. | ||
| CVE-2020-10083 | — | >= 12.7.0, < 12.8.2 | 12.8.2 | Mar 13, 2020 | GitLab 12.7 through 12.8.1 has Insecure Permissions. Under certain conditions involving groups, project authorization changes were not being applied. | ||
| CVE-2020-10084 | — | >= 11.6.0, < 12.8.2 | 12.8.2 | Mar 13, 2020 | GitLab EE 11.6 through 12.8.1 allows Information Disclosure. Sending a specially crafted request to the vulnerability_feedback endpoint could result in the exposure of a private project namespace | ||
| CVE-2020-10085 | — | >= 12.3.5, < 12.8.2 | 12.8.2 | Mar 13, 2020 | GitLab 12.3.5 through 12.8.1 allows Information Disclosure. A particular view was exposing merge private merge request titles. | ||
| CVE-2020-10086 | — | >= 10.4.0, < 12.8.2 | 12.8.2 | Mar 13, 2020 | GitLab 10.4 through 12.8.1 allows Directory Traversal. A particular endpoint was vulnerable to a directory traversal vulnerability, leading to arbitrary file read. | ||
| CVE-2020-10087 | — | < 12.8.2 | 12.8.2 | Mar 13, 2020 | GitLab before 12.8.2 allows Information Disclosure. Badge images were not being proxied, causing mixed content warnings as well as leaking the IP address of the user. | ||
| CVE-2020-10088 | — | >= 12.5.0, < 12.8.2 | 12.8.2 | Mar 13, 2020 | GitLab 12.5 through 12.8.1 has Insecure Permissions. Depending on particular group settings, it was possible for invited groups to be given the incorrect permission level. | ||
| CVE-2020-10089 | — | >= 8.11.0, < 12.8.2 | 12.8.2 | Mar 13, 2020 | GitLab 8.11 through 12.8.1 allows a Denial of Service when using several features to recursively request eachother, | ||
| CVE-2020-10090 | — | >= 11.7.0, < 12.8.2 | 12.8.2 | Mar 13, 2020 | GitLab 11.7 through 12.8.1 allows Information Disclosure. Under certain group conditions, group epic information was unintentionally being disclosed. | ||
| CVE-2020-10091 | — | >= 9.3.0, < 12.8.2 | 12.8.2 | Mar 13, 2020 | GitLab 9.3 through 12.8.1 allows XSS. A cross-site scripting vulnerability was found when viewing particular file types. | ||
| CVE-2020-10092 | — | >= 12.1.0, < 12.8.2 | 12.8.2 | Mar 13, 2020 | GitLab 12.1 through 12.8.1 allows XSS. A cross-site scripting vulnerability was present in a particular view relating to the Grafana integration. | ||
| CVE-2020-10535 | — | >= 12.8.0, < 12.8.6 | 12.8.6 | Mar 12, 2020 | GitLab 12.8.x before 12.8.6, when sign-up is enabled, allows remote attackers to bypass email domain restrictions within the two-day grace period for an unconfirmed email address. | ||
| CVE-2020-8113 | — | >= 10.7.0, < 12.6.8 | 12.6.8 | Mar 6, 2020 | GitLab 10.7 and later through 12.7.2 has Incorrect Access Control. | ||
| CVE-2020-8795 | — | >= 12.5.0, < 12.7.6 | 12.7.6 | Feb 17, 2020 | In GitLab Enterprise Edition (EE) 12.5.0 through 12.7.5, sharing a group with a group could grant project access to unauthorized users. | ||
| CVE-2020-6833 | — | >= 11.3.0, < 12.5.9 | 12.5.9 | Feb 5, 2020 | An issue was discovered in GitLab EE 11.3 and later. A GitLab Workhorse bypass could lead to package and file disclosure via request smuggling. | ||
| CVE-2020-7966 | — | >= 11.11.0, < 12.5.9 | 12.5.9 | Feb 5, 2020 | GitLab EE 11.11 and later through 12.7.2 allows Directory Traversal. |
- CVE-2020-10078Mar 13, 2020affected >= 12.1.0, < 12.8.2fixed 12.8.2
GitLab 12.1 through 12.8.1 allows XSS. The merge request submission form was determined to have a stored cross-site scripting vulnerability.
- CVE-2020-10079Mar 13, 2020affected >= 7.10.0, < 12.8.2fixed 12.8.2
GitLab 7.10 through 12.8.1 has Incorrect Access Control. Under certain conditions where users should have been required to configure two-factor authentication, it was not being required.
- CVE-2020-10080Mar 13, 2020affected >= 8.3.0, < 12.8.2fixed 12.8.2
GitLab 8.3 through 12.8.1 allows Information Disclosure. It was possible for certain non-members to access the Contribution Analytics page of a private group.
- CVE-2020-10081Mar 13, 2020affected < 12.8.2fixed 12.8.2
GitLab before 12.8.2 has Incorrect Access Control. It was internally discovered that the LFS import process could potentially be used to incorrectly access LFS objects not owned by the user.
- CVE-2020-10082Mar 13, 2020affected >= 12.2.0, < 12.8.2fixed 12.8.2
GitLab 12.2 through 12.8.1 allows Denial of Service. A denial of service vulnerability impacting the designs for public issues was discovered.
- CVE-2020-10083Mar 13, 2020affected >= 12.7.0, < 12.8.2fixed 12.8.2
GitLab 12.7 through 12.8.1 has Insecure Permissions. Under certain conditions involving groups, project authorization changes were not being applied.
- CVE-2020-10084Mar 13, 2020affected >= 11.6.0, < 12.8.2fixed 12.8.2
GitLab EE 11.6 through 12.8.1 allows Information Disclosure. Sending a specially crafted request to the vulnerability_feedback endpoint could result in the exposure of a private project namespace
- CVE-2020-10085Mar 13, 2020affected >= 12.3.5, < 12.8.2fixed 12.8.2
GitLab 12.3.5 through 12.8.1 allows Information Disclosure. A particular view was exposing merge private merge request titles.
- CVE-2020-10086Mar 13, 2020affected >= 10.4.0, < 12.8.2fixed 12.8.2
GitLab 10.4 through 12.8.1 allows Directory Traversal. A particular endpoint was vulnerable to a directory traversal vulnerability, leading to arbitrary file read.
- CVE-2020-10087Mar 13, 2020affected < 12.8.2fixed 12.8.2
GitLab before 12.8.2 allows Information Disclosure. Badge images were not being proxied, causing mixed content warnings as well as leaking the IP address of the user.
- CVE-2020-10088Mar 13, 2020affected >= 12.5.0, < 12.8.2fixed 12.8.2
GitLab 12.5 through 12.8.1 has Insecure Permissions. Depending on particular group settings, it was possible for invited groups to be given the incorrect permission level.
- CVE-2020-10089Mar 13, 2020affected >= 8.11.0, < 12.8.2fixed 12.8.2
GitLab 8.11 through 12.8.1 allows a Denial of Service when using several features to recursively request eachother,
- CVE-2020-10090Mar 13, 2020affected >= 11.7.0, < 12.8.2fixed 12.8.2
GitLab 11.7 through 12.8.1 allows Information Disclosure. Under certain group conditions, group epic information was unintentionally being disclosed.
- CVE-2020-10091Mar 13, 2020affected >= 9.3.0, < 12.8.2fixed 12.8.2
GitLab 9.3 through 12.8.1 allows XSS. A cross-site scripting vulnerability was found when viewing particular file types.
- CVE-2020-10092Mar 13, 2020affected >= 12.1.0, < 12.8.2fixed 12.8.2
GitLab 12.1 through 12.8.1 allows XSS. A cross-site scripting vulnerability was present in a particular view relating to the Grafana integration.
- CVE-2020-10535Mar 12, 2020affected >= 12.8.0, < 12.8.6fixed 12.8.6
GitLab 12.8.x before 12.8.6, when sign-up is enabled, allows remote attackers to bypass email domain restrictions within the two-day grace period for an unconfirmed email address.
- CVE-2020-8113Mar 6, 2020affected >= 10.7.0, < 12.6.8fixed 12.6.8
GitLab 10.7 and later through 12.7.2 has Incorrect Access Control.
- CVE-2020-8795Feb 17, 2020affected >= 12.5.0, < 12.7.6fixed 12.7.6
In GitLab Enterprise Edition (EE) 12.5.0 through 12.7.5, sharing a group with a group could grant project access to unauthorized users.
- CVE-2020-6833Feb 5, 2020affected >= 11.3.0, < 12.5.9fixed 12.5.9
An issue was discovered in GitLab EE 11.3 and later. A GitLab Workhorse bypass could lead to package and file disclosure via request smuggling.
- CVE-2020-7966Feb 5, 2020affected >= 11.11.0, < 12.5.9fixed 12.5.9
GitLab EE 11.11 and later through 12.7.2 allows Directory Traversal.
Page 52 of 53