Vulnerabilities
Vulnerable Software
Gitlab:  >> Gitlab  >> 10.2.1  Security Vulnerabilities
An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows SSRF.
CVSS Score
10.0
EPSS Score
0.02
Published
2019-04-17
An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Information Exposure (issue 3 of 5).
CVSS Score
5.3
EPSS Score
0.015
Published
2019-04-17
An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows CSRF.
CVSS Score
6.5
EPSS Score
0.007
Published
2019-04-17
An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Information Exposure (issue 4 of 5).
CVSS Score
5.3
EPSS Score
0.016
Published
2019-04-17
An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Information Exposure (issue 5 of 5).
CVSS Score
3.7
EPSS Score
0.013
Published
2019-04-17
An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. A user retains their role within a project in a private group after being removed from the group, if their privileges within the project are different from the group.
CVSS Score
6.5
EPSS Score
0.01
Published
2019-04-16
An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows XSS (issue 2 of 2). The user status field contains a lack of input validation and output encoding that results in a persistent XSS.
CVSS Score
6.1
EPSS Score
0.012
Published
2019-04-11
GitLab Community and Enterprise Edition before 11.3.14, 11.4.x before 11.4.12, and 11.5.x before 11.5.5 allows Directory Traversal.
CVSS Score
7.5
EPSS Score
0.017
Published
2019-04-04
GitLab CE/EE before 11.3.12, 11.4.x before 11.4.10, and 11.5.x before 11.5.3 allows Directory Traversal in Templates API.
CVSS Score
7.5
EPSS Score
0.023
Published
2019-03-26
An issue was discovered in GitLab Community and Enterprise Edition before 11.4. It allows Directory Traversal.
CVSS Score
7.5
EPSS Score
0.022
Published
2019-03-25


Contact Us

Shodan ® - All rights reserved