Bitnami package
gitlab
pkg:bitnami/gitlab
Vulnerabilities (1,120)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2020-13294 | Med | 4.2 | >= 7.7.0, < 13.0.12 | 13.0.12 | Aug 10, 2020 | In GitLab before 13.0.12, 13.1.6 and 13.2.3, access grants were not revoked when a user revoked access to an application. | |
| CVE-2020-13293 | Med | 6.3 | >= 1.0.0, < 13.0.12 | 13.0.12 | Aug 10, 2020 | In GitLab before 13.0.12, 13.1.6 and 13.2.3 using a branch with a hexadecimal name could override an existing hash. | |
| CVE-2020-13292 | Cri | 9.6 | >= 12.3.0, < 13.0.12 | 13.0.12 | Aug 10, 2020 | In GitLab before 13.0.12, 13.1.6 and 13.2.3, it is possible to bypass E-mail verification which is required for OAuth Flow. | |
| CVE-2020-15525 | Med | 5.3 | >= 11.3.0, < 13.1.3 | 13.1.3 | Jul 7, 2020 | GitLab EE 11.3 through 13.1.2 has Incorrect Access Control because of the Maven package upload endpoint. | |
| CVE-2020-13264 | Med | 5.3 | >= 10.3.0, < 12.9.8 | 12.9.8 | Jun 19, 2020 | Kubernetes cluster token disclosure in GitLab CE/EE 10.3 and later through 13.0.1 allows other group maintainers to view Kubernetes cluster token | |
| CVE-2020-13263 | Hig | 7.5 | >= 9.5.0, < 12.9.8 | 12.9.8 | Jun 19, 2020 | An authorization issue relating to project maintainer impersonation was identified in GitLab EE 9.5 and later through 13.0.1 that could allow unauthorized users to impersonate as a maintainer to perform limited actions. | |
| CVE-2020-13261 | Med | 5.3 | >= 12.6.0, < 12.9.8 | 12.9.8 | Jun 19, 2020 | Amazon EKS credentials disclosure in GitLab CE/EE 12.6 and later through 13.0.1 allows other administrators to view Amazon EKS credentials via HTML source code | |
| CVE-2020-13276 | Hig | 7.4 | < 12.9.8 | 12.9.8 | Jun 19, 2020 | User is allowed to set an email as a notification email even without verifying the new email in all previous GitLab CE/EE versions through 13.0.1 | |
| CVE-2020-13275 | Hig | 8.0 | >= 12.2.0, < 12.9.8 | 12.9.8 | Jun 19, 2020 | A user with an unverified email address could request an access to domain restricted groups in GitLab EE 12.2 and later through 13.0.1 | |
| CVE-2020-13274 | Hig | 7.5 | < 12.9.8 | 12.9.8 | Jun 19, 2020 | A security issue allowed achieving Denial of Service attacks through memory exhaustion by uploading malicious artifacts in all previous GitLab versions through 13.0.1 | |
| CVE-2020-13273 | Hig | 7.5 | >= 12.0.0, < 12.9.8 | 12.9.8 | Jun 19, 2020 | A Denial of Service vulnerability allowed exhausting the system resources in GitLab CE/EE 12.0 and later through 13.0.1 | |
| CVE-2020-13272 | Hig | 7.5 | >= 12.3.0, < 12.9.8 | 12.9.8 | Jun 19, 2020 | OAuth flow missing verification checks CE/EE 12.3 and later through 13.0.1 allows unverified user to use OAuth authorization code flow | |
| CVE-2020-13265 | Med | 4.3 | >= 12.5.0, < 12.9.8 | 12.9.8 | Jun 19, 2020 | User email verification bypass in GitLab CE/EE 12.5 and later through 13.0.1 allows user to bypass email verification | |
| CVE-2020-13262 | Med | 6.1 | >= 12.9.0, < 12.9.8 | 12.9.8 | Jun 19, 2020 | Client-Side code injection through Mermaid markup in GitLab CE/EE 12.9 and later through 13.0.1 allows a specially crafted Mermaid payload to PUT requests on behalf of other users via clicking on a link | |
| CVE-2020-13277 | Med | 6.3 | >= 10.6.0, < 12.9.10 | 12.9.10 | Jun 19, 2020 | An authorization issue in the mirroring logic allowed read access to private repositories in GitLab CE/EE 10.6 and later through 13.0.5 | |
| CVE-2020-14155 | Med | 5.3 | < 12.10.13 | 12.10.13 | Jun 15, 2020 | libpcre in PCRE before 8.44 allows an integer overflow via a large number after a (?C substring. | |
| CVE-2020-13271 | Med | 6.1 | < 12.9.8 | 12.9.8 | Jun 10, 2020 | A Stored Cross-Site Scripting vulnerability allowed the execution of arbitrary Javascript code in the blobs API in all previous GitLab CE/EE versions through 13.0.1 | |
| CVE-2020-13270 | Hig | 7.5 | >= 11.3.0, < 12.9.8 | 12.9.8 | Jun 10, 2020 | Missing permission check on fork relation creation in GitLab CE/EE 11.3 and later through 13.0.1 allows guest users to create a fork relation on restricted public projects via API | |
| CVE-2020-13269 | Med | 6.1 | >= 12.10.0, < 12.10.7 | 12.10.7 | Jun 10, 2020 | A Reflected Cross-Site Scripting vulnerability allowed the execution of arbitrary Javascript code on the Static Site Editor in GitLab CE/EE 12.10 and later through 13.0.1 | |
| CVE-2020-13268 | Med | 5.3 | >= 12.8.0, < 12.9.8 | 12.9.8 | Jun 10, 2020 | A specially crafted request could be used to confirm the existence of files hosted on object storage services, without disclosing their contents. This vulnerability affects GitLab CE/EE 12.10 and later through 13.0.1 |
- affected >= 7.7.0, < 13.0.12fixed 13.0.12
In GitLab before 13.0.12, 13.1.6 and 13.2.3, access grants were not revoked when a user revoked access to an application.
- affected >= 1.0.0, < 13.0.12fixed 13.0.12
In GitLab before 13.0.12, 13.1.6 and 13.2.3 using a branch with a hexadecimal name could override an existing hash.
- affected >= 12.3.0, < 13.0.12fixed 13.0.12
In GitLab before 13.0.12, 13.1.6 and 13.2.3, it is possible to bypass E-mail verification which is required for OAuth Flow.
- affected >= 11.3.0, < 13.1.3fixed 13.1.3
GitLab EE 11.3 through 13.1.2 has Incorrect Access Control because of the Maven package upload endpoint.
- affected >= 10.3.0, < 12.9.8fixed 12.9.8
Kubernetes cluster token disclosure in GitLab CE/EE 10.3 and later through 13.0.1 allows other group maintainers to view Kubernetes cluster token
- affected >= 9.5.0, < 12.9.8fixed 12.9.8
An authorization issue relating to project maintainer impersonation was identified in GitLab EE 9.5 and later through 13.0.1 that could allow unauthorized users to impersonate as a maintainer to perform limited actions.
- affected >= 12.6.0, < 12.9.8fixed 12.9.8
Amazon EKS credentials disclosure in GitLab CE/EE 12.6 and later through 13.0.1 allows other administrators to view Amazon EKS credentials via HTML source code
- affected < 12.9.8fixed 12.9.8
User is allowed to set an email as a notification email even without verifying the new email in all previous GitLab CE/EE versions through 13.0.1
- affected >= 12.2.0, < 12.9.8fixed 12.9.8
A user with an unverified email address could request an access to domain restricted groups in GitLab EE 12.2 and later through 13.0.1
- affected < 12.9.8fixed 12.9.8
A security issue allowed achieving Denial of Service attacks through memory exhaustion by uploading malicious artifacts in all previous GitLab versions through 13.0.1
- affected >= 12.0.0, < 12.9.8fixed 12.9.8
A Denial of Service vulnerability allowed exhausting the system resources in GitLab CE/EE 12.0 and later through 13.0.1
- affected >= 12.3.0, < 12.9.8fixed 12.9.8
OAuth flow missing verification checks CE/EE 12.3 and later through 13.0.1 allows unverified user to use OAuth authorization code flow
- affected >= 12.5.0, < 12.9.8fixed 12.9.8
User email verification bypass in GitLab CE/EE 12.5 and later through 13.0.1 allows user to bypass email verification
- affected >= 12.9.0, < 12.9.8fixed 12.9.8
Client-Side code injection through Mermaid markup in GitLab CE/EE 12.9 and later through 13.0.1 allows a specially crafted Mermaid payload to PUT requests on behalf of other users via clicking on a link
- affected >= 10.6.0, < 12.9.10fixed 12.9.10
An authorization issue in the mirroring logic allowed read access to private repositories in GitLab CE/EE 10.6 and later through 13.0.5
- affected < 12.10.13fixed 12.10.13
libpcre in PCRE before 8.44 allows an integer overflow via a large number after a (?C substring.
- affected < 12.9.8fixed 12.9.8
A Stored Cross-Site Scripting vulnerability allowed the execution of arbitrary Javascript code in the blobs API in all previous GitLab CE/EE versions through 13.0.1
- affected >= 11.3.0, < 12.9.8fixed 12.9.8
Missing permission check on fork relation creation in GitLab CE/EE 11.3 and later through 13.0.1 allows guest users to create a fork relation on restricted public projects via API
- affected >= 12.10.0, < 12.10.7fixed 12.10.7
A Reflected Cross-Site Scripting vulnerability allowed the execution of arbitrary Javascript code on the Static Site Editor in GitLab CE/EE 12.10 and later through 13.0.1
- affected >= 12.8.0, < 12.9.8fixed 12.9.8
A specially crafted request could be used to confirm the existence of files hosted on object storage services, without disclosing their contents. This vulnerability affects GitLab CE/EE 12.10 and later through 13.0.1
Page 53 of 56