Bitnami package
gitlab
pkg:bitnami/gitlab
Vulnerabilities (1,120)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2020-10078 | Med | 6.1 | >= 12.1.0, < 12.8.2 | 12.8.2 | Mar 13, 2020 | GitLab 12.1 through 12.8.1 allows XSS. The merge request submission form was determined to have a stored cross-site scripting vulnerability. | |
| CVE-2020-10535 | Med | 5.3 | >= 12.8.0, < 12.8.6 | 12.8.6 | Mar 12, 2020 | GitLab 12.8.x before 12.8.6, when sign-up is enabled, allows remote attackers to bypass email domain restrictions within the two-day grace period for an unconfirmed email address. | |
| CVE-2020-8113 | Cri | 9.8 | >= 10.7.0, < 12.6.8 | 12.6.8 | Mar 6, 2020 | GitLab 10.7 and later through 12.7.2 has Incorrect Access Control. | |
| CVE-2020-8795 | Hig | 7.5 | >= 12.5.0, < 12.7.6 | 12.7.6 | Feb 17, 2020 | In GitLab Enterprise Edition (EE) 12.5.0 through 12.7.5, sharing a group with a group could grant project access to unauthorized users. | |
| CVE-2020-6833 | Hig | 7.5 | >= 11.3.0, < 12.5.9 | 12.5.9 | Feb 5, 2020 | An issue was discovered in GitLab EE 11.3 and later. A GitLab Workhorse bypass could lead to package and file disclosure via request smuggling. | |
| CVE-2020-7978 | Hig | 7.5 | >= 12.6.0, < 12.6.6 | 12.6.6 | Feb 5, 2020 | GitLab EE 12.6 and later through 12.7.2 allows Denial of Service. | |
| CVE-2020-7977 | Med | 5.3 | >= 8.8.0, < 12.5.9 | 12.5.9 | Feb 5, 2020 | GitLab EE 8.8 and later through 12.7.2 has Insecure Permissions. | |
| CVE-2020-7976 | Med | 5.3 | >= 12.4.0, < 12.5.9 | 12.5.9 | Feb 5, 2020 | GitLab EE 12.4 and later through 12.7.2 has Incorrect Access Control. | |
| CVE-2020-7974 | Med | 5.3 | >= 10.1.0, < 12.5.9 | 12.5.9 | Feb 5, 2020 | GitLab EE 10.1 through 12.7.2 allows Information Disclosure. | |
| CVE-2020-7973 | Med | 6.1 | < 12.5.9 | 12.5.9 | Feb 5, 2020 | GitLab through 12.7.2 allows XSS. | |
| CVE-2020-7972 | Hig | 7.5 | >= 12.0.0, < 12.5.9 | 12.5.9 | Feb 5, 2020 | GitLab EE 12.2 has Insecure Permissions (issue 2 of 2). | |
| CVE-2020-7971 | Med | 6.1 | >= 11.0.0, < 12.5.9 | 12.5.9 | Feb 5, 2020 | GitLab EE 11.0 and later through 12.7.2 allows XSS. | |
| CVE-2020-7969 | Hig | 7.5 | >= 8.0.0, < 12.5.9 | 12.5.9 | Feb 5, 2020 | GitLab EE 8.0 and later through 12.7.2 allows Information Disclosure. | |
| CVE-2020-7968 | Hig | 7.5 | < 12.5.9 | 12.5.9 | Feb 5, 2020 | GitLab EE 8.0 through 12.7.2 has Incorrect Access Control. | |
| CVE-2020-7967 | Med | 4.3 | >= 12.0.0, < 12.7.3 | 12.7.3 | Feb 5, 2020 | GitLab EE 8.0 through 12.7.2 has Insecure Permissions (issue 1 of 2). | |
| CVE-2020-7966 | Hig | 7.5 | >= 11.11.0, < 12.5.9 | 12.5.9 | Feb 5, 2020 | GitLab EE 11.11 and later through 12.7.2 allows Directory Traversal. | |
| CVE-2020-8114 | Cri | 9.8 | >= 8.9.0, < 12.5.9 | 12.5.9 | Feb 5, 2020 | GitLab EE 8.9 and later through 12.7.2 has Insecure Permission | |
| CVE-2020-7979 | Med | 5.3 | >= 8.9.0, < 12.5.9 | 12.5.9 | Feb 5, 2020 | GitLab EE 8.9 and later through 12.7.2 has Insecure Permission | |
| CVE-2020-6832 | Med | 5.3 | >= 8.9.0, < 12.6.2 | 12.6.2 | Jan 13, 2020 | An issue was discovered in GitLab Enterprise Edition (EE) 8.9.0 through 12.6.1. Using the project import feature, it was possible for someone to obtain issues from private projects. | |
| CVE-2020-5197 | Med | 4.3 | >= 5.1.0, < 12.6.2 | 12.6.2 | Jan 13, 2020 | An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 5.1 through 12.6.1. It has Incorrect Access Control. |
- affected >= 12.1.0, < 12.8.2fixed 12.8.2
GitLab 12.1 through 12.8.1 allows XSS. The merge request submission form was determined to have a stored cross-site scripting vulnerability.
- affected >= 12.8.0, < 12.8.6fixed 12.8.6
GitLab 12.8.x before 12.8.6, when sign-up is enabled, allows remote attackers to bypass email domain restrictions within the two-day grace period for an unconfirmed email address.
- affected >= 10.7.0, < 12.6.8fixed 12.6.8
GitLab 10.7 and later through 12.7.2 has Incorrect Access Control.
- affected >= 12.5.0, < 12.7.6fixed 12.7.6
In GitLab Enterprise Edition (EE) 12.5.0 through 12.7.5, sharing a group with a group could grant project access to unauthorized users.
- affected >= 11.3.0, < 12.5.9fixed 12.5.9
An issue was discovered in GitLab EE 11.3 and later. A GitLab Workhorse bypass could lead to package and file disclosure via request smuggling.
- affected >= 12.6.0, < 12.6.6fixed 12.6.6
GitLab EE 12.6 and later through 12.7.2 allows Denial of Service.
- affected >= 8.8.0, < 12.5.9fixed 12.5.9
GitLab EE 8.8 and later through 12.7.2 has Insecure Permissions.
- affected >= 12.4.0, < 12.5.9fixed 12.5.9
GitLab EE 12.4 and later through 12.7.2 has Incorrect Access Control.
- affected >= 10.1.0, < 12.5.9fixed 12.5.9
GitLab EE 10.1 through 12.7.2 allows Information Disclosure.
- affected < 12.5.9fixed 12.5.9
GitLab through 12.7.2 allows XSS.
- affected >= 12.0.0, < 12.5.9fixed 12.5.9
GitLab EE 12.2 has Insecure Permissions (issue 2 of 2).
- affected >= 11.0.0, < 12.5.9fixed 12.5.9
GitLab EE 11.0 and later through 12.7.2 allows XSS.
- affected >= 8.0.0, < 12.5.9fixed 12.5.9
GitLab EE 8.0 and later through 12.7.2 allows Information Disclosure.
- affected < 12.5.9fixed 12.5.9
GitLab EE 8.0 through 12.7.2 has Incorrect Access Control.
- affected >= 12.0.0, < 12.7.3fixed 12.7.3
GitLab EE 8.0 through 12.7.2 has Insecure Permissions (issue 1 of 2).
- affected >= 11.11.0, < 12.5.9fixed 12.5.9
GitLab EE 11.11 and later through 12.7.2 allows Directory Traversal.
- affected >= 8.9.0, < 12.5.9fixed 12.5.9
GitLab EE 8.9 and later through 12.7.2 has Insecure Permission
- affected >= 8.9.0, < 12.5.9fixed 12.5.9
GitLab EE 8.9 and later through 12.7.2 has Insecure Permission
- affected >= 8.9.0, < 12.6.2fixed 12.6.2
An issue was discovered in GitLab Enterprise Edition (EE) 8.9.0 through 12.6.1. Using the project import feature, it was possible for someone to obtain issues from private projects.
- affected >= 5.1.0, < 12.6.2fixed 12.6.2
An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 5.1 through 12.6.1. It has Incorrect Access Control.
Page 56 of 56