VYPR

Bitnami package

gitlab

pkg:bitnami/gitlab

Vulnerabilities (1,120)

  • CVE-2020-13294MedAug 10, 2020
    affected >= 7.7.0, < 13.0.12fixed 13.0.12

    In GitLab before 13.0.12, 13.1.6 and 13.2.3, access grants were not revoked when a user revoked access to an application.

  • CVE-2020-13293MedAug 10, 2020
    affected >= 1.0.0, < 13.0.12fixed 13.0.12

    In GitLab before 13.0.12, 13.1.6 and 13.2.3 using a branch with a hexadecimal name could override an existing hash.

  • CVE-2020-13292CriAug 10, 2020
    affected >= 12.3.0, < 13.0.12fixed 13.0.12

    In GitLab before 13.0.12, 13.1.6 and 13.2.3, it is possible to bypass E-mail verification which is required for OAuth Flow.

  • CVE-2020-15525MedJul 7, 2020
    affected >= 11.3.0, < 13.1.3fixed 13.1.3

    GitLab EE 11.3 through 13.1.2 has Incorrect Access Control because of the Maven package upload endpoint.

  • CVE-2020-13264MedJun 19, 2020
    affected >= 10.3.0, < 12.9.8fixed 12.9.8

    Kubernetes cluster token disclosure in GitLab CE/EE 10.3 and later through 13.0.1 allows other group maintainers to view Kubernetes cluster token

  • CVE-2020-13263HigJun 19, 2020
    affected >= 9.5.0, < 12.9.8fixed 12.9.8

    An authorization issue relating to project maintainer impersonation was identified in GitLab EE 9.5 and later through 13.0.1 that could allow unauthorized users to impersonate as a maintainer to perform limited actions.

  • CVE-2020-13261MedJun 19, 2020
    affected >= 12.6.0, < 12.9.8fixed 12.9.8

    Amazon EKS credentials disclosure in GitLab CE/EE 12.6 and later through 13.0.1 allows other administrators to view Amazon EKS credentials via HTML source code

  • CVE-2020-13276HigJun 19, 2020
    affected < 12.9.8fixed 12.9.8

    User is allowed to set an email as a notification email even without verifying the new email in all previous GitLab CE/EE versions through 13.0.1

  • CVE-2020-13275HigJun 19, 2020
    affected >= 12.2.0, < 12.9.8fixed 12.9.8

    A user with an unverified email address could request an access to domain restricted groups in GitLab EE 12.2 and later through 13.0.1

  • CVE-2020-13274HigJun 19, 2020
    affected < 12.9.8fixed 12.9.8

    A security issue allowed achieving Denial of Service attacks through memory exhaustion by uploading malicious artifacts in all previous GitLab versions through 13.0.1

  • CVE-2020-13273HigJun 19, 2020
    affected >= 12.0.0, < 12.9.8fixed 12.9.8

    A Denial of Service vulnerability allowed exhausting the system resources in GitLab CE/EE 12.0 and later through 13.0.1

  • CVE-2020-13272HigJun 19, 2020
    affected >= 12.3.0, < 12.9.8fixed 12.9.8

    OAuth flow missing verification checks CE/EE 12.3 and later through 13.0.1 allows unverified user to use OAuth authorization code flow

  • CVE-2020-13265MedJun 19, 2020
    affected >= 12.5.0, < 12.9.8fixed 12.9.8

    User email verification bypass in GitLab CE/EE 12.5 and later through 13.0.1 allows user to bypass email verification

  • CVE-2020-13262MedJun 19, 2020
    affected >= 12.9.0, < 12.9.8fixed 12.9.8

    Client-Side code injection through Mermaid markup in GitLab CE/EE 12.9 and later through 13.0.1 allows a specially crafted Mermaid payload to PUT requests on behalf of other users via clicking on a link

  • CVE-2020-13277MedJun 19, 2020
    affected >= 10.6.0, < 12.9.10fixed 12.9.10

    An authorization issue in the mirroring logic allowed read access to private repositories in GitLab CE/EE 10.6 and later through 13.0.5

  • CVE-2020-14155MedJun 15, 2020
    affected < 12.10.13fixed 12.10.13

    libpcre in PCRE before 8.44 allows an integer overflow via a large number after a (?C substring.

  • CVE-2020-13271MedJun 10, 2020
    affected < 12.9.8fixed 12.9.8

    A Stored Cross-Site Scripting vulnerability allowed the execution of arbitrary Javascript code in the blobs API in all previous GitLab CE/EE versions through 13.0.1

  • CVE-2020-13270HigJun 10, 2020
    affected >= 11.3.0, < 12.9.8fixed 12.9.8

    Missing permission check on fork relation creation in GitLab CE/EE 11.3 and later through 13.0.1 allows guest users to create a fork relation on restricted public projects via API

  • CVE-2020-13269MedJun 10, 2020
    affected >= 12.10.0, < 12.10.7fixed 12.10.7

    A Reflected Cross-Site Scripting vulnerability allowed the execution of arbitrary Javascript code on the Static Site Editor in GitLab CE/EE 12.10 and later through 13.0.1

  • CVE-2020-13268MedJun 10, 2020
    affected >= 12.8.0, < 12.9.8fixed 12.9.8

    A specially crafted request could be used to confirm the existence of files hosted on object storage services, without disclosing their contents. This vulnerability affects GitLab CE/EE 12.10 and later through 13.0.1

Page 53 of 56