CVE-2019-15590
https://notcve.org/view.php?id=CVE-2019-15590
An access control issue exists in < 12.3.5, < 12.2.8, and < 12.1.14 for GitLab Community Edition (CE) and Enterprise Edition (EE) where private merge requests and issues would be disclosed with the Group Search feature provided by Elasticsearch integration Se presenta un problema de control de acceso en versiones anteriores a 12.3.5, versiones anteriores a 12.2.8 y versiones anteriores a 12.1.14 para GitLab Community Edition (CE) y Enterprise Edition (EE), donde las peticiones y problemas de fusión privada serían divulgados con la funcionalidad Group Search proporcionada por la integración Elasticsearch. • https://about.gitlab.com/releases/2019/10/07/security-release-gitlab-12-dot-3-dot-5-released https://hackerone.com/reports/701144 • CWE-284: Improper Access Control •
CVE-2019-5474
https://notcve.org/view.php?id=CVE-2019-5474
An authorization issue was discovered in GitLab EE < 12.1.2, < 12.0.4, and < 11.11.6 allowing the merge request approval rules to be overridden without appropriate permissions. Se detectó un problema de autorización en GitLab EE versiones anteriores a 12.1.2, versiones anteriores a 12.0.4 y versiones anteriores a 11.11.6, permitiendo que las reglas de aprobación de petición de fusión sea anuladas sin los permisos apropiados. • https://about.gitlab.com/releases/2019/07/29/security-release-gitlab-12-dot-1-dot-2-released https://gitlab.com/gitlab-org/gitlab-ee/issues/11423 https://hackerone.com/reports/544756 • CWE-284: Improper Access Control CWE-863: Incorrect Authorization •
CVE-2019-15583
https://notcve.org/view.php?id=CVE-2019-15583
An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE). When an issue was moved to a public project from a private one, the associated private labels and the private project namespace would be disclosed through the GitLab API. Se presenta una divulgación de información en versiones anteriores a 12.3.2, versiones anteriores a 12.2.6 y versiones anteriores a 12.1.12 para GitLab Community Edition (CE) y Enterprise Edition (EE). Cuando un problema fue trasladado hacia un proyecto público desde uno privado, las etiquetas privadas asociadas y el espacio de nombres del proyecto privado serían divulgados por medio de la API de GitLab. • https://about.gitlab.com/blog/2019/09/30/security-release-gitlab-12-dot-3-dot-2-released https://hackerone.com/reports/643854 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2019-15585
https://notcve.org/view.php?id=CVE-2019-15585
Improper authentication exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) in the GitLab SAML integration had a validation issue that permitted an attacker to takeover another user's account. Se presenta una autenticación inapropiada en versiones anteriores a 12.3.2, versiones anteriores a 12.2.6 y versiones anteriores a 12.1.12 para GitLab Community Edition (CE) y Enterprise Edition (EE), en la integración GitLab SAML se presenta un problema de comprobación que permitió a un atacante tomar el control de la cuenta de otro usuario. • https://about.gitlab.com/blog/2019/09/30/security-release-gitlab-12-dot-3-dot-2-released https://hackerone.com/reports/471323 • CWE-287: Improper Authentication •
CVE-2019-15586
https://notcve.org/view.php?id=CVE-2019-15586
A XSS exists in Gitlab CE/EE < 12.1.10 in the Mermaid plugin. Se presenta una vulnerabilidad de tipo XSS en Gitlab CE/EE versiones anteriores a 12.1.10, en el complemento Mermaid. • https://about.gitlab.com/blog/2019/09/30/security-release-gitlab-12-dot-3-dot-2-released https://hackerone.com/reports/645043 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •